遇见数据集

DUPIN: Attack Learning Is Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner

收藏
Zenodo2026-06-08 更新2026-06-12 收录
官方服务:

资源简介:

Audit Toolkit - The tool was introduced by our paper "DUPIN: Attack Learning Still Needed! Demonstrating Few-Shot after Unsupervised Pretraining Is A Nimble Forensics Learner", Usenix Security 2026. - This tool aims to integrate many different types of audit logs and help users generate provenance graphs, hiding the complexity from different log parsings. - The tool supports 1. Darpa TRACE dataset (example trace: [DARPA TRACE repo]) 2. Window ETW (example trace: [ATLAS repo]) 3. Linux Auditbeat (example trace: [PalanTir repo]) How to set up - Requirements1. python32. requirements -> `pip3 install igraph pyparsing alive_progress` - Configure the tool on `conf.py`1. Verbose level - `PRINT_TRACE`: if set, every line of log will print when parsing (recommended off) - `DEBUG`: used for development (recommended off) - `VERBOSE`: information that is needed for users (recommended on) 2. Path to the project folder - `HOME_PATH`: Be sure to use "\\" for Windows. use "/" for linux or Mac. - Run the program1. Write a conf file(s) to sepicify log files, scenario information - read our example `.conf` files - `name`: unique name as an identifier - `type`: `cdm-18`, `cdm-20` (Darpa E3/E5), `auditbeat` (Linux logs), `windows` (Windows ETW) - `file_names`: log files to parse (can be multiple files) - dapra: `.json` files (after decompression) - windows: `.txt` files - auditbeat: `auditbeat` (unless changed) - `time_from`, `time_to`: time windows to extract - `gt_names`: if specified, nodes will be marked red when plotting the graph figures. 2. Run the tool - please refer to [`tool-demonstration.md`](Tool%20Demonstration.md) DUPIN - Please go to \dupin directory for source code of DUPIN.

提供机构:
Zenodo
创建时间:
2026-06-08
二维码
社区交流群
二维码
科研交流群
商业服务