SCAHunter: Scalable Threat Hunting Through Decentralized Hierarchical Monitoring Agent Architecture

Mohiuddin Ahmed*, Jinpeng Wei, Ehab Al-Shaer

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

This paper presents a scalable, dynamic, flexible, and non-intrusive monitoring architecture for threat hunting. The agent architecture detects attack techniques at the agent level, classifies composite and primitive events, and disseminates seen attack techniques or subscribed event information to the upper-level agent or manager. The proposed solution offers improvement over existing approaches for threat hunting by supporting hierarchical event filtering-based monitoring, which improves monitoring scalability. It reduces memory requirement and communication overhead while maintaining the same accuracy of threat hunting in state-of-the-art centralized approaches. We provide a distributed hierarchical agent architecture and an approximation algorithm for near-optimal agent hierarchy generation. We also evaluated the proposed system across three simulated attack use cases built using the MITRE ATT &CK framework and DARPA OpTC attack dataset. The evaluation shows that our proposed approach reduces communication overhead by 43% to 64% and memory usage by 45% to 60% compared with centralized threat hunting approaches.

Original languageEnglish
Title of host publicationIntelligent Computing - Proceedings of the 2023 Computing Conference
EditorsKohei Arai
PublisherSpringer Science and Business Media Deutschland GmbH
Pages1282-1307
Number of pages26
ISBN (Print)9783031379628
DOIs
StatePublished - 2023
Externally publishedYes
EventProceedings of the Computing Conference 2023 - London, United Kingdom
Duration: 22 Jun 202323 Jun 2023

Publication series

NameLecture Notes in Networks and Systems
Volume739 LNNS
ISSN (Print)2367-3370
ISSN (Electronic)2367-3389

Conference

ConferenceProceedings of the Computing Conference 2023
Country/TerritoryUnited Kingdom
CityLondon
Period22/06/2323/06/23

Bibliographical note

Publisher Copyright:
© 2023, The Author(s), under exclusive license to Springer Nature Switzerland AG.

Keywords

  • Hierarchical Event Monitoring
  • Intrusion Detection
  • Threat Hunting

ASJC Scopus subject areas

  • Control and Systems Engineering
  • Signal Processing
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'SCAHunter: Scalable Threat Hunting Through Decentralized Hierarchical Monitoring Agent Architecture'. Together they form a unique fingerprint.

Cite this