eAudit: A Fast, Scalable and Deployable Audit Data Collection System
R. Sekar, Hanke Kimm, Rohit Aich
Abstract
Today’s advanced cyber attack campaigns can often bypass all existing protections. The primary defense against them is after-the-fact detection, followed by a forensic analysis to understand their impact. Such an analysis requires audit logs (also called provenance logs) that faithfully capture all activities and data flows on each host. While the Linux auditing daemon (auditd) and sysdig are the most popular tools for audit data collection, a number of other systems, authored by researchers and practitioners, are also available. Through a motivating experimental study, we show that these systems impose high overheads, slowing workloads by 2× to 8×; lose a majority of events under sustained workloads; and are vulnerable to log tampering that erases log entries before they are committed to persistent storage. We present a new approach that overcomes these challenges. By relying on the extended Berkeley Packet Filter (eBPF) framework built into recent Linux versions, we avoid changes to the kernel code, and hence our data collector works out of the box on most Linux distributions. We present new design, tuning and optimization techniques that enables our system to sustain workloads that are an order of magnitude more intense than those causing major data loss with existing systems. Moreover, our system incurs only a fraction of the overhead of previous systems, while considerably reducing data volumes, and shrinking the log tampering window by 100×.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 58009c23-e125-4cbe-900c-cf9120872448Cited by top-tier papers12
- Merlin: Multi-tier Optimization of eBPF Code for Performance and CompactnessJinsong Mao, Hailun Ding, Juan Zhai, Shiqing MaASPLOS 2024 · 15 citations
- Cost-effective Attack Forensics by Recording and Correlating File System ChangesLe Yu, Yapeng Ye, Zhuo Zhang, Xiangyu ZhangUSENIX Security 2024 · 5 citations
- The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission SwitchesChuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad et al.CCS 2024 · 4 citations
- NetCap: Data-Plane Capability-Based Defense Against Token Theft in Network AccessOsama Bajaber, Bo Ji, Peng GaoNDSS 2026 · 2 citations
- Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing SystemRui Zhao, Muhammad Shoaib, Viet Tung Hoang, Wajih Ul HassanCCS 2025 · 1 citation
Builds on28
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete et al.USENIX Security 2017 · 291 citations
- ATLAS: A Sequence-based Learning Approach for Attack InvestigationAbdulellah Alsaheel, Yuhong Nan, Shiqing Ma, Le Yu et al.USENIX Security 2021 · 256 citations
Related papers
- Sealing the Window: Efficient Tamper Protection for Provenance LogsSagar Mishra, R. SekarS&P 2026
- HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud PlatformsRenpeng Zhang, Kai Shen, Peng Jiang, Ding Li et al.USENIX Security 2026
- Rethinking System Audit Architectures for High Event Coverage and Synchronous Log AvailabilityVarun Gandhi, Sarbartha Banerjee, Aniket Agrawal, Adil Ahmad et al.USENIX Security 2023
- Auditing Frameworks Need Resource Isolation: A Systematic Study on the Super Producer Threat to System Auditing and Its MitigationPeng Jiang, Ruizhe Huang, Ding Li, Yao Guo et al.USENIX Security 2023
- Runtime Analysis of Whole-System ProvenanceThomas F. J.-M. Pasquier, Xueyuan Han, Thomas Moyer, Adam Bates et al.CCS 2018 · 112 citations
