The University of New Brunswick

$20,000.00 CAD

≈ 3 months of average Canadian pay
Department
National Research Council Canada
Program
Collaborative Science, Technology and Innovation Program – Ideation Fund
Recipient country
Canada
Fiscal year
2019-2020
Agreement period
March 20, 2020 – March 31, 2021
Reference
nrc-cnrc:172-2019-2020-Q4-945265

Published purpose

Detecting and identifying malicious activity occurring on a network of host machines can be extremely difficult in attack scenarios such as Advanced Persistent Threats (APT) where attackers move laterally from host to host. Sequential pattern analysis methods can be used to detect the presence of potentially malicious behaviour on a network. With multi-host detection, however, the challenge lies in recognizing patterns of host activity that may not be of particular interest on their own, but when considered with the presence or absence of activities occurring on other host machine, may be part of a more concerning sequence of events. The focus of this project is the creation of conditional high-utility sequential pattern mining methods to compute the criticality of identified patterns given the existence of particular patterns on different hosts. Making this challenge particularly difficult is the fact that the complexity of APT attacks, coupled with the general lack of success in identifying APT attacks and, in particular, the lateral movement of attackers, means that publicly available labeled real-world datasets containing this type of behaviour are virtually nonexistent. As a result, many studies validate proposed methods on real operational data that has been injected with artificial attack traces. The difficulty is that these artificial infiltrations tend to be unrealistic, and as a result are easily recognizable amongst the true operational data. In the absence of true APT data that can be used to successfully train effective ML models for the detection of lateral movement, further research will be conducted into the generation of realistic synthetic datasets for APT attacks, with a focus on the advancement of the current state of the art in synthetic data for malicious lateral movement.

Community tags

Tags are applied by readers, not by this site. One tag per person per record.

Good value Local impact Needs context Questionable Success story Wasteful
View official source record Imported July 30, 2026 from open.canada.ca Grants & Contributions