ProcAID: Process Anomaly-based Intrusion Detection

Presented at ShmooCon 2022 Rescheduled, March 24, 2022, 5:30 p.m. (30 minutes)

Advanced Persistent Threats (APTs) prey on government entities and corporations via previously unknown attack vectors and complex techniques with overwhelming success. Though industry has attempted to engineer effective solutions to combat APTs, the solutions consistently lack the ability to respond and react to novel threats. This presentation covers an effective, two-stage unsupervised graph anomaly-based detection algorithm called “ProcAID” that fills the gap of industry’s current detection and response capabilities. In general, ProcAID concentrates on anomalous process creation, inverse graph leadership, and inverse graph density to discover malicious processes on a single host. In the first stage, the solution detects anomalous host process creation events via unsupervised graph link prediction. In the second stage, ProcAID evaluates and assigns scores to a process based on its observed behavior. ProcAID was tested on a real-world enterprise dataset with known APT activity. This research proved proficient in distinguishing between malicious and benign host processes with options to expand to an enterprise implementation. ProcAID also out-performed other graph and machine learning anomaly detection algorithms in the detection of malicious activity. With already existing assets like Windows Security Event Logs, the implementation costs for ProcAID are minimal while the benefits are vast.


Presenters:

  • Austin Read
    Austin Read (@ajread3) is an active-duty Coast Guard (CG) officer, currently completing his Masters degree at The George Washington University (GW) where he also works as a research assistant within the Graph Computing Lab (GraphLab). Prior to graduate school, he completed his undergraduate education at the US Coast Guard Academy in 2018. His first assignment was to CG Cyber Command (CGCYBER) as the Deputy Director of the Cybersecurity Operations Center (CSOC). This winter, he will be returning to CGCYBER within the Cyber Protection Team (CPT). His certifications include CISSP, GCIH, GCFA, GREM, and ITIL Foundations. His hobbies include soccer, CrossFit, playing with his dog, and CTFs.

Similar Presentations: