USENIX Security2024Top-tier venue
WEBRR: A Forensic System for Replaying and Investigating Web-Based Attacks in The Modern Web
Joey Allen, Zheng Yang, Feng Xiao, Matthew Landen, Roberto Perdisci, Wenke Lee
Abstract
After a sophisticated attack or data breach occurs at an organization, a postmortem forensic analysis must be conducted to reconstruct and understand the root causes of the attack. Unfortunately, the majority of proposed forensic analysis systems rely on system-level auditing, making it difficult to reconstruct and investigate web-based attacks, due to the semantic-gap between system-and web-level semantics. This limited visibility into web-based attacks has recently become increasingly concerning because web-based attacks are commonly employed by nation-state adversaries to penetrate and achieve the initial compromise of an enterprise network. To enable forensic analysts to replay and investigate web-based attacks, we propose WEBRR, a novel OS-and device-independent record-andreplay (RR) forensic auditing system for Chromium-based web browsers. While there exist prior works that focus on webbased auditing, current systems are either record-only or suffer from critical limitations that prevent them from deterministically replaying attacks. WEBRR addresses these limitation by introducing a novel design that allows it to record and deterministically replay modern web applications by leveraging JavaScript Execution Unit Partitioning. Our evaluation demonstrates that WEBRR is capable of replaying web-based attacks that fail to replay on prior state-ofthe-art systems. Furthermore, we demonstrate that WEBRR can replay highly-dynamic modern websites in a deterministic fashion with an average runtime overhead of only 3.44%.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 25716c90-3b97-400c-a53f-e9db1c0ac08fCited by top-tier papers1
Ask how each one uses itBuilds on26
- Big Self-Supervised Models are Strong Semi-Supervised LearnersTing Chen, Simon Kornblith, Kevin Swersky, Mohammad Norouzi et al.NeurIPS 2020 · 2,611 citations
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
Related papers
- JSgraph: Enabling Reconstruction of Web Attacks via Efficient Tracking of Live In-Browser JavaScript ExecutionsBo Li, Phani Vadrevu, Kyu Hyung Lee, Roberto PerdisciNDSS 2018 · 61 citations
- C^2SR: Cybercrime Scene Reconstruction for Post-mortem Forensic AnalysisYonghwi Kwon, Weihang Wang, Jinho Jung, Kyu Hyung Lee et al.NDSS 2021
- Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation SystemJoey Allen, Zheng Yang, Matthew Landen, Raghav Bhat et al.CCS 2020 · 14 citations
- RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow TrackingYang Ji, Sangho Lee, Evan Downing, Weiren Wang et al.CCS 2017 · 119 citations
- Enabling Reconstruction of Attacks on Users via Efficient Browsing SnapshotsPhani Vadrevu, Jienan Liu, Bo Li, Babak Rahbarinia et al.NDSS 2017 · 22 citations
