Search papers, labs, and topics across Lattice.
DUPIN is a novel attack forensics learner that utilizes unsupervised pre-training on extensive audit event data represented as provenance graphs, followed by a few-shot learning phase to enhance detection capabilities. The model was pretrained on 7.3TB of audit logs spanning 38 to 52 days and evaluated against 25 advanced persistent threat (APT) campaigns across multiple data sources. Key results show that DUPIN effectively improves attack detection accuracy while requiring significantly fewer labeled examples compared to traditional methods, underscoring its efficiency in real-world scenarios.
Few-shot learning can dramatically enhance attack forensics, with DUPIN achieving superior detection accuracy using minimal labeled data.
We propose a novel approach to learning-based attack forensics called DUPIN. DUPIN performs unsupervised pre-training on an enormous amount of audit events in the form of provenance graphs. It then proceeds to a few-shot learning stage, leveraging a small number of labeled attack examples to fine-tune its detection capabilities. We pretrain DUPIN on up to 38 - 52 days of audit logs (7.3TB total) and evaluate it against various baselines on 25 APT campaigns across four different data sources, facilitating the scalable evaluation.