TARDIS: Rolling Back The Clock On CMS-Targeting Cyber Attacks
Ranjita Pai Kasturi, Yiting Sun, Ruian Duan, Omar Alrawi, Ehsan Asdar, Victor Zhu, Yonghwi Kwon, Brendan Saltaformaggio
Abstract
Over 55% of the world’s websites run on Content Management Systems (CMS). Unfortunately, this huge user population has made CMS-based websites a high-profile target for hackers. Worse still, the vast majority of the website hosting industry has shifted to a "backup and restore" model of security, which relies on error-prone AV scanners to prompt users to roll back to a pre-infection nightly snapshot. This research had the opportunity to study these nightly backups for over 300,000 unique production websites. In doing so, we measured the attack landscape of CMS-based websites and assessed the effectiveness of the backup and restore protection scheme. To our surprise, we found that the evolution of tens of thousands of attacks exhibited clear long-lived multi-stage attack patterns. We now propose TARDIS, an automated provenance inference technique, which enables the investigation and remediation of CMS-targeting attacks based on only the nightly backups already being collected by website hosting companies. With the help of our industry collaborator, we applied TARDIS to the nightly backups of those 300K websites and found 20,591 attacks which lasted from 6 to 1,694 days, some of which were still yet to be detected.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 26d2d1e5-27e5-40a8-be11-14886a60afd9Cited by top-tier papers9
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi et al.USENIX Security 2021 · 32 citations
- Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation SystemJoey Allen, Zheng Yang, Matthew Landen, Raghav Bhat et al.CCS 2020 · 14 citations
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud et al.USENIX Security 2024 · 10 citations
- ROCAS: Root Cause Analysis of Autonomous Driving Accidents via Cyber-Physical Co-mutationShiwei Feng, Yapeng Ye, Qingkai Shi, Zhiyuan Cheng et al.ASE 2024 · 4 citations
- Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment ReuseRunze Zhang, Mingxuan Yao, Haichuan Xu, Omar Alrawi et al.NDSS 2025
Builds on10
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete et al.USENIX Security 2017 · 291 citations
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
- Towards a Timely Causality Analysis for Enterprise SecurityYushan Liu, Mu Zhang, Ding Li, Kangkook Jee et al.NDSS 2018 · 177 citations
Related papers
- Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress MarketplacesRanjita Pai Kasturi, Jonathan Fuller, Yiting Sun, Omar Chabklo et al.USENIX Security 2022
- Breaking and Fixing Content-Defined ChunkingKien Tuong Truong, Simon-Philipp Merz, Matteo Scarlata, Felix Günther et al.CCS 2025
- Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain VerificationRuixuan Li, Xingyu Zhao, Yunyi Zhang, Baojun Liu et al.USENIX Security 2026
- From Payload to Plugin: Web-Scale Ecosystem Attribution of JavaScript Injection CampaignsRavindu De Silva, Nicholas Shao, Yigitcan Kaya, Mingxuan Yao et al.CCS 2026
- Do You Really Know What I Am Doing? Backdoor Attacks on Provenance-Based Intrusion Detection SystemsShaodi Xie, Wei Yuan, Haoyu Jiang, Zhu Gong et al.WWW 2026
