Advanced persistent threats (APTs) have novel features such as multi-stage penetration, highly-tailored intention, and evasive tactics. APTs defense requires fusing multi-dimensional Cyber threat intelligence data to identify attack intentions and conducts efficient knowledge discovery strategies by data-driven machine learning to recognize entity relationships. However, data-driven machine learning lacks generalization ability on fresh or unknown samples, reducing the accuracy and practicality of the defense model. Besides, the private deployment of these APT defense models on heterogeneous environments and various network devices requires significant investment in context awareness (such as known attack entities, continuous network states, and current security strategies). In this paper, we propose a few-shot multi-domain knowledge rearming (FMKR) scheme for context-aware defense against APTs. By completing multiple small tasks that are generated from different network domains with meta-learning, the FMKR firstly trains a model with good discrimination and generalization ability for fresh and unknown APT attacks. In each FMKR task, both threat intelligence and local entities are fused into the support/query sets in meta-learning to identify possible attack stages. Secondly, to rearm current security strategies, an finetuning-based deployment mechanism is proposed to transfer learned knowledge into the student model, while minimizing the defense cost. Compared to multiple model replacement strategies, the FMKR provides a faster response to attack behaviors while consuming less scheduling cost. Based on the feedback from multiple real users of the Industrial Internet of Things (IIoT) over 2 months, we demonstrate that the proposed scheme can improve the defense satisfaction rate.
翻译:高级持续性威胁(APT)具有多阶段渗透、高度定制化意图和规避策略等新型特征。APT防御需要融合多维网络威胁情报数据来识别攻击意图,并通过数据驱动的机器学习执行高效的知识发现策略以识别实体关系。然而,数据驱动机器学习对新鲜或未知样本缺乏泛化能力,降低了防御模型的准确性和实用性。此外,在异构环境和不同网络设备上私有部署这些APT防御模型,需要投入大量资源进行情境感知(例如已知攻击实体、持续网络状态和当前安全策略)。本文提出了一种用于APT情境感知防御的少样本多域知识重组(FMKR)方案。通过元学习完成从不同网络域生成的多个小任务,FMKR首先训练了一个对新鲜和未知APT攻击具有良好判别和泛化能力的模型。在每个FMKR任务中,威胁情报和本地实体被融合到元学习的支持/查询集中,以识别可能的攻击阶段。其次,为重组当前安全策略,提出了一种基于微调的部署机制,将学到的知识迁移到学生模型中,同时最小化防御成本。与多种模型替换策略相比,FMKR在消耗更少调度成本的同时,能更快地响应攻击行为。基于工业物联网(IIoT)多位真实用户超过两个月的反馈,我们证明了所提方案能够提高防御满意度。