Enabling Efficient Attack Investigation via Human-in-the-Loop Security Analysis
Saimon Amanuel Tsegai, Xinyu Yang, Haoyuan Liu, Peng Gao
Abstract
System auditing is a vital technique for collecting system call events as system provenance and investigating complex multi-step attacks such as Advanced Persistent Threats. However, existing attack investigation methods struggle to uncover long attack sequences due to the massive volume of system provenance data and their inability to focus on attack-relevant parts. In this paper, we present Provexa, a defense system that enables human analysts to effectively analyze large-scale system provenance to reveal multi-step attack sequences. Provexa introduces an expressive domain-specific language, ProvQL, that offers essential primitives for various types of attack analyses (e.g., attack pattern search, attack dependency tracking) with user-defined constraints, enabling analysts to focus on attack-relevant parts and iteratively sift through the large provenance data. Moreover, Provexa provides an optimized execution engine for efficient language execution. Our extensive evaluations on a wide range of attack scenarios demonstrate the practical effectiveness of Provexa in facilitating timely attack investigation. The source code, data, and other artifacts have been made available at https://github.com/peng-gao-lab/Provexa .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1654522d-4238-4da7-bc06-8a397f9a4620Builds on12
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 313 citations
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
- High Fidelity Data Reduction for Big Data Security Dependency AnalysesZhang Xu, Zhenyu Wu, Zhichun Li, Kangkook Jee et al.CCS 2016 · 197 citations
Related papers
- ProGQL: A Provenance Graph Query System for Cyber Attack InvestigationFei Shao, Jia Zou, Zhichao Cao, Xusheng XiaoICDE 2026
- PROGRAPHER: An Anomaly Detection System based on Provenance Graph EmbeddingFan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li et al.USENIX Security 2023
- SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsMuhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu et al.S&P 2023
- Cutting the Fuse: Actionable APT Attack Blocking in Provenance-based IDSWeiheng Wu, Wei Qiao, Teng Li, Yebo Feng et al.USENIX Security 2026
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 2 citations
