Show simple item record

dc.contributor.authorGjerstad, Julieen_GB
dc.contributor.authorKadiric, Fikreten_GB
dc.contributor.authorGrov, Gudmunden_GB
dc.contributor.authorKjellstadli, Espen Hammeren_GB
dc.contributor.authorAsprusten, Markus Leiraen_GB
dc.date.accessioned2023-03-30T06:46:24Z
dc.date.accessioned2023-05-19T10:02:07Z
dc.date.available2023-03-30T06:46:24Z
dc.date.available2023-05-19T10:02:07Z
dc.date.issued2023-01-26
dc.identifier.citationGjerstad, Kadiric, Grov, Kjellstadli, Asprusten: LADEMU: a modular & continuous approach for generating labelled APT datasets from emulations. In: Tsumoto S, Ohsawa, Chen L, Van den Poel, Hu X, Motomura, Takagi, Wu, Xie Y, Abe, Raghavan. 2022 IEEE International Conference on Big Data, 2023. IEEE (Institute of Electrical and Electronics Engineers)en_GB
dc.identifier.urihttp://hdl.handle.net/20.500.12242/3187
dc.description2022 IEEE International Conference on Big Data. IEEE (Institute of Electrical and Electronics Engineers) 2023 ISBN 978-1-6654-8045-1.en_GB
dc.description.abstractDevelopment and evaluation of data-driven capabilities for both threat hunting and intrusion detection require high-quality and up-to-date datasets. The generation of such datasets poses multiple challenges, which has led to a general lack of suitable datasets for this domain.One such difficulty is the ability to correctly label each datapoint at a suitable level of granularity. In this paper, we argue that the challenges faced when labelling datasets can to some degree be decoupled from realistic emulations of up-to-date attacks and benign behaviours. We propose a modular labelling approach that can be combined with existing emulation platforms that provide the necessary details used for labelling. A proof-of-concept implementation is provided with our LADEMU (Labelled Apt Datasets from EMUlations) tool, which is integrated with the Mitre CALDERA emulation platform and uses the GHOSTS framework for benign behaviour. LADEMU captures both host and network logs and labels them at a sufficient level of detail to separate the various attack steps. This provides dataset support for the development of data-driven APT, multi-step and kill-chain capabilities. As a case, LADEMU is used to generate a labelled dataset from an intelligence-driven emulation plan of an advanced persistent threat (APT) group.en_GB
dc.language.isoenen_GB
dc.subjectPakkebehandlingssystemeren_GB
dc.subjectStordataen_GB
dc.subjectDatasikkerheten_GB
dc.titleLADEMU: a modular & continuous approach for generating labelled APT datasets from emulationsen_GB
dc.typeArticleen_GB
dc.date.updated2023-03-30T06:46:24Z
dc.identifier.cristinID2137404
dc.identifier.doihttp://dx.doi.org/10.1109/BigData55660.2022.10020549
dc.source.isbn978-1-6654-8045-1
dc.type.documentChapter


Files in this item

This item appears in the following Collection(s)

Show simple item record