Time-Series Analysis
Analyzing temporal relationships between security events is critical for identifying stealthy attack behaviors that evade traditional detection methods. Attackers often employ time-based tactics, such as delayed exfiltration, multi-stage compromises, or periodic reconnaissance, which require defenders to examine event sequences across extended timeframes. Time-series analysis in Microsoft Sentinel leverages KQL (Kusto Query Language) to uncover these patterns by correlating events based on their timing, frequency, and sequence.
Key Concepts in Time-Series Analysis¶
- Temporal Context: Events that occur within specific time windows (e.g., hours, days, or weeks) may indicate coordinated attacks. For example, a phishing click followed by lateral movement after several days could signal a multi-stage breach.
- Anomaly Detection: Unusual gaps or bursts in event timing (e.g., sudden spikes in failed logins or irregular process creation) may reveal reconnaissance or exfiltration activities.
- Sequence Correlation: Attackers often follow predictable but subtle patterns (e.g., credential theft followed by privilege escalation). Time-series analysis helps identify these sequences by aligning events across systems.
Common Attack Patterns to Detect¶
- Delayed Exfiltration: Data is transferred over extended periods to avoid detection (e.g., small, frequent data transfers).
- Lateral Movement: Attackers move between systems with irregular intervals, mimicking legitimate traffic.
- Reconnaissance: Passive scanning or enumeration activities spaced over hours or days.
- Scheduled Tasks: Malicious scripts or processes executed at specific times (e.g., during off-peak hours).
KQL Techniques for Time-Series Analysis¶
Use KQL functions to analyze temporal relationships:
- datetime: Convert string timestamps to datetime objects.
- ago: Filter events within a relative time window (e.g., datetime() - 7d).
- between: Define a time range for event correlation.
- bin: Aggregate events into time intervals (e.g., bin(TimeGenerated, 1h)).
- summarize: Calculate metrics like count, average interval, or duration between events.
Example 1: Detecting Delayed Exfiltration
SecurityEvent
| where EventID == 4663 // Logon attempt
| where Account == "domain\\compromised_user"
| where TimeGenerated between (datetime() - 7d .. datetime())
| summarize count() by bin(TimeGenerated, 1h)
| where count_ > 5 // Filter for unusual activity
Example 2: Identifying Irregular Process Creation
Process
| where ProcessName == "cmd.exe" and InitiatingProcess != "explorer.exe"
| where TimeGenerated between (datetime() - 30d .. datetime())
| summarize avg(DurationInSeconds) by bin(TimeGenerated, 1h)
| where avg_DurationInSeconds < 10 // Flag short, frequent executions
Challenges and Mitigations¶
- Noise in Data: Legitimate activities (e.g., scheduled jobs) may mimic attack patterns. Use contextual filters (e.g., IP ranges, user roles) to reduce false positives.
- Time Zone Variability: Ensure timestamps are normalized to a consistent time zone.
- Event Granularity: High-frequency events (e.g., registry changes) may require aggregation to avoid overwhelming results.
Key takeaways¶
- Time-series analysis reveals attack patterns that evade signature-based detection.
- Use KQL to correlate events across time windows and identify anomalies.
- Focus on irregular intervals, sequence timing, and contextual filters to reduce noise.
- Combine temporal analysis with other correlation techniques (e.g., user behavior analytics) for comprehensive threat detection.