Threat detection and investigation with system-level provenance graphs: a survey Z Li, QA Chen, R Yang, Y Chen, W Ruan Computers & Security 106, 102282, 2021 | 60 | 2021 |
AttacKG: Constructing technique knowledge graph from cyber threat intelligence reports Z Li, J Zeng, Y Chen, Z Liang European Symposium on Research in Computer Security, 589-609, 2022 | 58 | 2022 |
Effective and light-weight deobfuscation and semantic-aware attack detection for powershell scripts Z Li, QA Chen, C Xiong, Y Chen, T Zhu, H Yang Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications …, 2019 | 38 | 2019 |
RATScope: Recording and Reconstructing Missing RAT Semantic Behaviors for Forensic Analysis on Windows R Yang, X Chen, H Xu, Y Cheng, C Xiong, L Ruan, M Kavousi, Z Li, L Xu, ... IEEE Transactions on Dependable and Secure Computing 19 (3), 1621-1638, 2020 | 14 | 2020 |
Generic, efficient, and effective deobfuscation and semantic-aware attack detection for PowerShell scripts C Xiong, Z Li, Y Chen, T Zhu, J Wang, H Yang, W Ruan Frontiers of Information Technology & Electronic Engineering 23 (3), 361-381, 2022 | 5 | 2022 |
Poster: Towards automated and large-scale cyber attack reconstruction with apt reports Z Li, A Soltani, A Yusof, AC Risdianto, K Huang, J Zeng, Z Liang, Y Chen NDSS, 0 | 1 | |
Incorporating Gradients to Rules: Towards Lightweight, Adaptive Provenance-based Intrusion Detection L Wang, X Shen, W Li, Z Li, R Sekar, H Liu, Y Chen arXiv preprint arXiv:2404.14720, 2024 | | 2024 |
TAGS: Real-time Intrusion Detection with Tag-Propagation-based Provenance Graph Alignment on Streaming Events Z Li, Y Wei, X Shen, L Wang, Y Chen, H Xu, S Ji, F Zhang arXiv preprint arXiv:2403.12541, 2024 | | 2024 |
Decoding the MITRE Engenuity ATT&CK Enterprise Evaluation: An Analysis of EDR Performance in Real-World Environments X Shen, Z Li, G Burleigh, L Wang, Y Chen arXiv preprint arXiv:2401.15878, 2024 | | 2024 |
A First Look at Evasion against Provenance Graph-based Threat Detection Z Li, R Yang, QA Chen, Y Chen | | |