USENIX Security2022Top-tier venue
Back-Propagating System Dependency Impact for Attack Investigation
Pengcheng Fang, Peng Gao, Changlin Liu, Erman Ayday, Kangkook Jee, Ting Wang, Yanfang (Fanny) Ye, Zhuotao Liu, Xusheng Xiao
Abstract
Causality analysis on system auditing data has emerged as an important solution for attack investigation. Given a POI (Point-Of-Interest) event (e.g., an alert fired on a suspicious file creation), causality analysis constructs a dependency graph, in which nodes represent system entities (e.g., processes and files) and edges represent dependencies among entities, to reveal the attack sequence. However, causality analysis often produces a huge graph (> 100, 000 edges) that is hard for security analysts to inspect. From the dependency graphs of various attacks, we observe that (1) dependencies that are highly related to the POI event often exhibit a different set of properties (e.g., data flow and time) from the lessrelevant dependencies; (2) the POI event is often related to a few attack entries (e.g., downloading a file). Based on these insights, we propose DEPIMPACT, a framework that identifies the critical component of a dependency graph (i.e., a subgraph) by (1) assigning discriminative dependency weights to edges to distinguish critical edges that represent the attack sequence from less-important dependencies, (2) propagating dependency impacts backward from the POI event to entry points, and (3) performing forward causality analysis from the top-ranked entry nodes based on their dependency impacts to filter out edges that are not found in the forward causality analysis. Our evaluations on the 150 million real system auditing events of real attacks and the DARPA TC dataset show that DEPIMPACT can significantly reduce the large dependency graphs (∼ 1, 000, 000 edges) to a small graph (∼ 234 edges), which is 4611× smaller. The comparison with the other state-of-the-art causality analysis techniques shows that DEPIMPACT is 106× more effective in reducing the dependency graphs while preserving the attack sequences. Key Insight. By carefully inspecting the dependency graphs of various attacks [31, 45, 55, 57] , we have two key observations. First, on a large dependency graph constructed from a POI event, a small number of critical edges (e.g., events
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext da5da8db-a129-4472-8140-4642c8f6bfaaCited by top-tier papers22
- Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningMati Ur Rehman, Hadi Ahmadi, Wajih Ul HassanS&P 2024 · 104 citations
- R-CAID: Embedding Root Cause Analysis within Provenance-based Intrusion DetectionAkul Goyal, Gang Wang, Adam BatesS&P 2024 · 40 citations
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 31 citations
- Are we there yet? An Industrial Viewpoint on Provenance-based Endpoint Detection and Response ToolsFeng Dong, Shaofei Li, Peng Jiang, Ding Li et al.CCS 2023 · 24 citations
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 14 citations
Builds on19
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar et al.S&P 2019 · 550 citations
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen et al.NDSS 2019 · 411 citations
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 313 citations
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete et al.USENIX Security 2017 · 291 citations
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 253 citations
Related papers
- DEPCOMM: Graph Summarization on System Audit Logs for Attack InvestigationZhiqiang Xu, Pengcheng Fang, Changlin Liu, Xusheng Xiao et al.S&P 2022 · 88 citations
- ProGQL: A Provenance Graph Query System for Cyber Attack InvestigationFei Shao, Jia Zou, Zhichao Cao, Xusheng XiaoICDE 2026
- Dependence-Preserving Data Compaction for Scalable Forensic AnalysisMd Nahid Hossain, Junao Wang, R. Sekar, Scott D. StollerUSENIX Security 2018 · 133 citations
- SEAL: Storage-efficient Causality Analysis on Enterprise Logs with Query-friendly CompressionPeng Fei, Zhou Li, Zhiying Wang, Xiao Yu et al.USENIX Security 2021 · 45 citations
- Towards a Timely Causality Analysis for Enterprise SecurityYushan Liu, Mu Zhang, Ding Li, Kangkook Jee et al.NDSS 2018 · 177 citations
