Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response Tools
Feng Dong, Shaofei Li, Peng Jiang, Ding Li, Haoyu Wang, Liangyi Huang, Xusheng Xiao, Jiedong Chen, Xiapu Luo, Yao Guo, Xiangqun Chen
Abstract
Provenance-Based Endpoint Detection and Response (P-EDR) systems are deemed crucial for future Advanced Persistent Threats (APT) defenses. Despite the fact that numerous new techniques to improve P-EDR systems have been proposed in academia, it is still unclear whether the industry will adopt P-EDR systems and what improvements the industry desires for P-EDR systems. To this end, we conduct the first set of systematic studies on the effectiveness and the limitations of P-EDR systems. Our study consists of four components: a one-to-one interview, an online questionnaire study, a survey of the relevant literature, and a systematic measurement study. Our research indicates that all industry experts consider P-EDR systems to be more effective than conventional Endpoint Detection and Response (EDR) systems. However, industry experts are concerned about the operating cost of P-EDR systems. In addition, our research reveals three significant gaps between academia and industry (1) overlooking client-side overhead; (2) imbalancedalarm triage cost and interpretation cost; and (3) excessive server side memory consumption. This paper's findings provide objective data on the effectiveness of P-EDR systems and how much improvements are needed to adopt P-EDR systems in industry.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ce1f90ab-4b53-4eaf-a47a-6479e3b45714Cited by top-tier papers12
- How does Endpoint Detection use the MITRE ATT&CK Framework?Apurva Virkud, Muhammad Adil Inam, Andy Riddle, Jason Liu et al.USENIX Security 2024 · 9 citations
- KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance AnalysisYuhan Meng, Shaofei Li, Jiaping Gui, Peng Jiang et al.NDSS 2026 · 8 citations
- Cost-effective Attack Forensics by Recording and Correlating File System ChangesLe Yu, Yapeng Ye, Zhuo Zhang, Xiangyu ZhangUSENIX Security 2024 · 5 citations
- Credible Threat Detection? Measuring Contribution Dynamics and Quality Control in a Crowdsourced Threat Detection EcosystemApurva Virkud, Gang Wang, Adam BatesUSENIX Security 2026 · 1 citation
- HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud PlatformsRenpeng Zhang, Kai Shen, Peng Jiang, Ding Li et al.USENIX Security 2026
Builds on25
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 317 citations
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 313 citations
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete et al.USENIX Security 2017 · 291 citations
Related papers
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
- DISTDET: A Cost-Effective Distributed Cyber Threat Detection SystemFeng Dong, Liu Wang, Xu Nie, Fei Shao et al.USENIX Security 2023
- EvilEDR: Repurposing EDR as an Offensive ToolKotaiba Alachkar, Dirk Gaastra, Eduardo Barbaro, Michel van Eeten et al.USENIX Security 2025
- Cutting the Fuse: Actionable APT Attack Blocking in Provenance-based IDSWeiheng Wu, Wei Qiao, Teng Li, Yebo Feng et al.USENIX Security 2026
- TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph LearningMingqi Lv, Hongzhe Gao, Xuebo Qiu, Tieming Chen et al.CCS 2024 · 18 citations
