Pith. sign in

REVIEW 3 cited by

UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2001.01525 v2 pith:YUYGS2BL submitted 2020-01-06 cs.CR

classification cs.CR
keywords unicorndetectionsystemadvancedanalysisaptsattackdetector
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based APT detector that effectively leverages data provenance analysis. From modeling to detection, UNICORN tailors its design specifically for the unique characteristics of APTs. Through extensive yet time-efficient graph analysis, UNICORN explores provenance graphs that provide rich contextual and historical information to identify stealthy anomalous activities without pre-defined attack signatures. Using a graph sketching technique, it summarizes long-running system execution with space efficiency to combat slow-acting attacks that take place over a long time span. UNICORN further improves its detection capability using a novel modeling approach to understand long-term behavior as the system evolves. Our evaluation shows that UNICORN outperforms an existing state-of-the-art APT detection system and detects real-life APT scenarios with high accuracy.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. TGCM: Topic-Guided Consistency Modeling for One-Step Disentanglement of Interleaved APT Technique Sequences

    cs.CR 2026-06 unverdicted novelty 6.0 of 10

    TGCM is a one-step neural demixer that maps an interleaved MITRE ATT&CK technique sequence to per-campaign assignments and a campaign-count estimate, trained on synthetic mixtures and tested on benchmarks and real traces.

  2. An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models

    cs.CR 2025-09 reject novelty 6.0 of 10

    ANANKE reports 97.1% TPR and 0.2% FPR for LLM-based attack investigation, but its central evaluation is compromised by knowledge-base overlap with test scenarios.

  3. From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection

    cs.CR 2025-07 conditional novelty 6.0 of 10

    SHIELD, an LLM-aided pipeline combining a masked autoencoder, deterministic data augmentation, and multi-level prompting, detects host-based attacks with high precision on three public datasets.

Pith tools