• KSII Transactions on Internet and Information Systems
    Monthly Online Journal (eISSN: 1976-7277)

Semi-supervised based Unknown Attack Detection in EDR Environment

Vol. 14, No. 12, December 31, 2020
10.3837/tiis.2020.12.016, Download Paper (Free):

Abstract

Cyberattacks penetrate the server and perform various malicious acts such as stealing confidential information, destroying systems, and exposing personal information. To achieve this, attackers perform various malicious actions by infecting endpoints and accessing the internal network. However, the current countermeasures are only anti-viruses that operate in a signature or pattern manner, allowing initial unknown attacks. Endpoint Detection and Response (EDR) technology is focused on providing visibility, and strong countermeasures are lacking. If you fail to respond to the initial attack, it is difficult to respond additionally because malicious behavior like Advanced Persistent Threat (APT) attack does not occur immediately, but occurs over a long period of time. In this paper, we propose a technique that detects an unknown attack using an event log without prior knowledge, although the initial response failed with anti-virus. The proposed technology uses a combination of AutoEncoder and 1D CNN (1-Dimention Convolutional Neural Network) based on semi-supervised learning. The experiment trained a dataset collected over a month in a real-world commercial endpoint environment, and tested the data collected over the next month. As a result of the experiment, 37 unknown attacks were detected in the event log collected for one month in the actual commercial endpoint environment, and 26 of them were verified as malicious through VirusTotal (VT). In the future, it is expected that the proposed model will be applied to EDR technology to form a secure endpoint environment and reduce time and labor costs to effectively detect unknown attacks.


Statistics

Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2015)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article

[IEEE Style]
C. Hwang, D. Kim, T. Lee, "Semi-supervised based Unknown Attack Detection in EDR Environment," KSII Transactions on Internet and Information Systems, vol. 14, no. 12, pp. 4909-4926, 2020. DOI: 10.3837/tiis.2020.12.016.

[ACM Style]
Chanwoong Hwang, Doyeon Kim, and Taejin Lee. 2020. Semi-supervised based Unknown Attack Detection in EDR Environment. KSII Transactions on Internet and Information Systems, 14, 12, (2020), 4909-4926. DOI: 10.3837/tiis.2020.12.016.

[BibTeX Style]
@article{tiis:24150, title="Semi-supervised based Unknown Attack Detection in EDR Environment", author="Chanwoong Hwang and Doyeon Kim and Taejin Lee and ", journal="KSII Transactions on Internet and Information Systems", DOI={10.3837/tiis.2020.12.016}, volume={14}, number={12}, year="2020", month={December}, pages={4909-4926}}