Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective Tracing
Chuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto, Zhenkai Liang, Adil Ahmad
Abstract
Audit logs are widely used for attack investigation in enterprises, but their granularity (system calls and related events) is too coarse-grained to be useful for attack forensics when adversaries launch advanced kernel exploits. Such exploits manipulate kernel memory to hijack kernel controlflow, and these aspects (i.e., the executed anomaly control flows and their capabilities) are not visible in today's audit logs. Appare is an auditing framework designed to comprehensively and efficiently capture sophisticated in-memory kernel exploit behaviors. Appare implements anomalous control-flow logging, where it leverages an augmented hybrid approach to (a) dynamically profile representative system call workloads, and (b) generalize the profiles by using LLM-assisted code semantics reasoning to differentiate reference (benign) and anomalous function executions within the kernel. Appare uses efficient hardware tracing techniques to record anomaly control flow behaviors, as well as the historical contexts to reveal where control flow divergences (hijacking) happen. Appare leverages virtualization extensions and features available in modern architectures to achieve end-to-end tamper-proof logging, persistence, and management. Our analysis and evaluation show that appare effectively captures attack behaviors in the exploits we analyzed, while incurring a geometric mean slowdown of only 2.0% across diverse programs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cb7a58e6-da61-4435-b5b4-15b233f74e9fRelated papers
- RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow TrackingYang Ji, Sangho Lee, Evan Downing, Weiren Wang et al.CCS 2017 · 119 citations
- HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud PlatformsRenpeng Zhang, Kai Shen, Peng Jiang, Ding Li et al.USENIX Security 2026
- ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without InstrumentationLe Yu, Shiqing Ma, Zhuo Zhang, Guanhong Tao et al.NDSS 2021
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 31 citations
- A Novel Dynamic Analysis Infrastructure to Instrument Untrusted Execution Flow Across User-Kernel SpacesJiaqi Hong, Xuhua DingS&P 2021 · 10 citations
