ProvTalk: Towards Interpretable Multi-level Provenance Analysis in Networking Functions Virtualization (NFV)
Azadeh Tabiban, Heyang Zhao, Yosr Jarraya, Makan Pourzandi, Mengyuan Zhang, Lingyu Wang
Abstract
—Network functions virtualization (NFV) enables agile deployment of network services on top of clouds. However, as NFV involves multiple levels of abstraction representing the same components, pinpointing the root cause of security incidents can become challenging. For instance, a security incident may be detected at a different level from where its root cause operations were conducted with no obvious link between the two. Moreover, existing provenance analysis techniques may produce results that are impractically large for human analysts to interpret due to the inherent complexity of NFV. In this paper, we propose ProvTalk, a provenance analysis system that handles the unique multi-level nature of NFV and assists the analyst to identify the root cause of security incidents. Specifically, we first define a multi-level provenance model to capture the dependencies between NFV levels. Next, we improve the interpretability through three novel techniques, i.e., multi-level pruning, mining-based aggregation, and rule-based natural language translation. We implement ProvTalk on a Tacker-OpenStack NFV platform and validate its effectiveness based on real-world security incidents. We demonstrate that ProvTalk captures management API calls issued to all NFV services, and produces more interpretable results by significantly reducing the size of the provenance graphs (about 3.6 times reduction via the multi-level pruning scheme and two times reduction via the aggregation scheme). Our user studies show that ProvTalk facilitates the analysis task of real-world users by generating more interpretable results.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 48b79740-2d7f-4649-a227-c9cc51b29a5cCited by top-tier papers6
- KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance AnalysisYuhan Meng, Shaofei Li, Jiaping Gui, Peng Jiang et al.NDSS 2026 · 8 citations
- FaDE: More Than a Million What-ifs Per SecondHaneen Mohammed, Eugene Wu, Alexander Yao, Charlie Summers et al.VLDB 2025 · 6 citations
- Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall SequencesHugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang, Suryadipta Majumdar et al.NDSS 2024
- Sometimes Simpler is Better: A Comprehensive Analysis of State-of-the-Art Provenance-Based Intrusion Detection SystemsTristan Bilot, Baoxiang Jiang, Zefeng Li, Nour El Madhoun et al.USENIX Security 2025
- PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management PoliciesRui Li, Shuang CaoUSENIX Security 2026
Builds on13
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Fear and Logging in the Internet of ThingsQi Wang, Wajih Ul Hassan, Adam Bates, Carl A. GunterNDSS 2018 · 205 citations
- Towards Scalable Cluster Auditing through Grammatical Inference over Provenance GraphsWajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates et al.NDSS 2018 · 157 citations
- MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution PartitioningShiqing Ma, Juan Zhai, Fei Wang, Kyu Hyung Lee et al.USENIX Security 2017 · 136 citations
Related papers
- Enabling Efficient Attack Investigation via Human-in-the-Loop Security AnalysisSaimon Amanuel Tsegai, Xinyu Yang, Haoyuan Liu, Peng GaoVLDB 2025 · 2 citations
- Connecting the Extra Dots (Contexts): Correlating External Information about Point of Interest for Attack InvestigationSareh Mohammadi, Hugo Kermabon-Bobinnec, Azadeh Tabiban, Lingyu Wang et al.S&P 2025
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani et al.USENIX Security 2021 · 38 citations
- Forensic Analysis of Configuration-based AttacksMuhammad Adil Inam, Wajih Ul Hassan, Ali Ahad, Adam Bates et al.NDSS 2022
- Alert Summarization for Online Service Systems by Validating Propagation Paths of FaultsJia Chen, Yuang He, Peng Wang, Xiaolei Chen et al.FSE 2025
