Sealing the Window: Efficient Tamper Protection for Provenance Logs
Sagar Mishra, R. Sekar
Abstract
Today's advanced cyber attacks routinely circumvent existing protection measures. Analysts must rely on after-the-fact detection, based on provenance logs, to understand and recover from these intrusions. Since attackers prize the ability to stay hidden, they take every measure to remove all signs of attacks from these logs. In this research, we begin with a study of previous work on protecting provenance logs from such tampering. Through a motivating experimental study, we show that audit logging systems deployed today are highly susceptible to tampering. Moreover, existing tamper detection measures either require specialized hardware and custom OS modifications, or they incur excessive performance costs. To overcome these challenges, we first analyze previous research to identify their key bottlenecks. We then present new techniques and algorithms that avoid these bottlenecks, while also providing several additional benefits. Our techniques have been implemented into a system WinSeal that achieves well over a reduction in overhead as compared to previous tamper detection techniques. On the protection front as well, WinSeal improves a key metric, namely, tamper window duration, by an order of magnitude as compared to previous techniques compatible with stock hardware and software. Our software is being open-sourced along with this paper.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5785a319-47c0-42a8-9ea0-0d2e3de33e37Related papers
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 31 citations
- Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted ExecutionRiccardo Paccagnella, Pubali Datta, Wajih Ul Hassan, Adam Bates et al.NDSS 2020
- SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsMuhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu et al.S&P 2023
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 43 citations
- Towards Scalable Cluster Auditing through Grammatical Inference over Provenance GraphsWajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates et al.NDSS 2018 · 157 citations
