Electronic Thesis/Dissertation
 

ProcAID: Process Anomaly-based Intrusion Detection

Open Access

Advanced Persistent Threats (APTs) prey on government entities and corporationsvia previously unknown attack vectors and complex techniques with overwhelming success. Though industry has attempted to engineer effective solutions to combat APTs, the solutions consistently lack the ability to quickly respond and react to novel threats. This research presents an effective, two-stage unsupervised graph anomaly-based detection algorithm called ProcAID that fills the gap of industry’s current detection and response capabilities. In general, ProcAID concentrates on anomalous process creation, inverse graph leadership, and inverse graph density to discover malicious processes on a single host. In the first stage, the solution detects anomalous host process creation events via unsupervised link prediction. In the second stage, ProcAID evaluates and assigns scores to a process based on its observed behavior. ProcAID was tested on a real-world enterprise dataset with known APT activity. This research proved proficient in distinguishing between malicious and benign host processes with options to expand to an enterprise implementation. ProcAID also out-performed other graph and machine learning anomaly detection algorithms in the detection of malicious activity. With already existing assets like Windows Security Event Logs, the implementation costs for ProcAID are minimal while the benefits are vast.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Read_gwu_0075M_15756.pdf Read_gwu_0075M_15756.pdf 2022-03-06 Open Access