Ransomware-oriented incidents often leave suspicious traces across both endpoint and network domains, yet these observations are still commonly examined in isolation. This makes incident interpretation difficult, since host-level and communication-level evidence may remain fragmented even when they originate from the same attack sequences. To address this problem, this paper presents a hybrid endpoint-network correlation framework built around three analytical stages: endpoint-side suspicious activity analysis, network-side suspicious activity analysis, and multi-log correlation. The framework combines rule-based indicators with machine-learning-based suspiciousness support to preserve relevant evidence and then links the resulting candidates through temporal proximity, entity consistency, and behavioral relevance. Experiments on public attack scenarios show that the framework retained 16 endpoint candidates and 3 network candidates in a successful Drupal exploitation case, 11 endpoint candidates and 3 network candidates in a Samba known-creds scenario, and preserved a network-only context in a reconnaissance-dominant case. These retained candidates then serve as the basis for identifying cross-log relations, allowing suspicious observations from different sources to be interpreted within the same incident context. These results suggest that the framework can construct incident-oriented context without forcing unsupported cross-source relations.
Copyrights © 2026