2018
DOI: 10.1007/s11416-018-0318-x
|View full text |Cite
|
Sign up to set email alerts
|

SEQUIN: a grammar inference framework for analyzing malicious system behavior

Abstract: Targeted attacks on IT systems are a rising threat to the confidentiality of sensitive data and the availability of critical systems. The emergence of Advanced Persistent Threats (APTs) made it paramount to fully understand the particulars of such attacks in order to improve or devise effective defense mechanisms. Grammar inference paired with visual analytics (VA) techniques offers a powerful foundation for the automated extraction of behavioral patterns from sequential event traces. To facilitate the interpr… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
15
0

Year Published

2019
2019
2022
2022

Publication Types

Select...
4
1

Relationship

2
3

Authors

Journals

citations
Cited by 7 publications
(15 citation statements)
references
References 49 publications
(68 reference statements)
0
15
0
Order By: Relevance
“…Figure 5 shows a summary. Note that "SE-QUIN" is an optional component discussed in [27]. For both binary and CAPEC multi-class classification, the core classification system utilizing SVM with hyperplane optimization offers the highest accuracy with 99.82% and 95.73%, respectively.…”
Section: Results Summarymentioning
confidence: 99%
“…Figure 5 shows a summary. Note that "SE-QUIN" is an optional component discussed in [27]. For both binary and CAPEC multi-class classification, the core classification system utilizing SVM with hyperplane optimization offers the highest accuracy with 99.82% and 95.73%, respectively.…”
Section: Results Summarymentioning
confidence: 99%
“…For the purpose of compression we utilize prior work, SEQUIN [42], a grammar inference system based on the Sequitur algorithm, which constructs a context-free grammar (CFG) from string-based input data. Specifically, Sequitur is a greedy compression algorithm that creates a hierarchical structure 575 from a sequence of discrete symbols by recursively replacing repeated phrases with a grammatical rule [53].…”
Section: Grammar Inferencementioning
confidence: 99%
“…The full rule extraction and evaluation process is detailed in [42]. The article describes the application of our adapted Sequitur system on smart traces of kernel events associated with arbitrary processes and other security-relevant data, proving a full example grammar.…”
Section: Grammar Inferencementioning
confidence: 99%
See 2 more Smart Citations