C^2SR: Cybercrime Scene Reconstruction for Post-mortem Forensic Analysis
Yonghwi Kwon, Weihang Wang, Jinho Jung, Kyu Hyung Lee, Roberto Perdisci
Abstract
Cybercrime scene reconstruction that aims to reconstruct a previous execution of the cyber attack delivery process is an important capability for cyber forensics (e.g., post mortem analysis of the cyber attack executions). Unfortunately, existing techniques such as log-based forensics or record-and-replay techniques are not suitable to handle complex and long-running modern applications for cybercrime scene reconstruction and post mortem forensic analysis. Specifically, log-based cyber forensics techniques often suffer from a lack of inspection capability and do not provide details of how the attack unfolded. Record-and-replay techniques impose significant runtime overhead, often require significant modifications on end-user systems, and demand to replay the entire recorded execution from the beginning. In this paper, we propose C^2SR, a novel technique that can reconstruct an attack delivery chain (i.e., cybercrime scene) for post-mortem forensic analysis. It provides a highly desired capability: interactable partial execution reconstruction. In particular, it reproduces a partial execution of interest from a large execution trace of a long-running program. The reconstructed execution is also interactable, allowing forensic analysts to leverage debugging and analysis tools that did not exist on the recorded machine. The key intuition behind C^2SR is partitioning an execution trace by resources and reproducing resource accesses that are consistent with the original execution. It tolerates user interactions required for inspections that do not cause inconsistent resource accesses. Our evaluation results on 26 real-world programs show that C^2SR has low runtime overhead (less than 5.47%) and acceptable space overhead. We also demonstrate with four realistic attack scenarios that C^2SR successfully reconstructs partial executions of long-running applications such as web browsers, and it can remarkably reduce the user's efforts to understand the incident.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ef09e532-2b78-42e9-972b-f0e935e3601eCited by top-tier papers3
- Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningMati Ur Rehman, Hadi Ahmadi, Wajih Ul HassanS&P 2024 · 104 citations
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 14 citations
- WEBRR: A Forensic System for Replaying and Investigating Web-Based Attacks in The Modern WebJoey Allen, Zheng Yang, Feng Xiao, Matthew Landen et al.USENIX Security 2024 · 2 citations
Builds on14
- High Fidelity Data Reduction for Big Data Security Dependency AnalysesZhang Xu, Zhenyu Wu, Zhichun Li, Kangkook Jee et al.CCS 2016 · 197 citations
- Towards Scalable Cluster Auditing through Grammatical Inference over Provenance GraphsWajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates et al.NDSS 2018 · 157 citations
- MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution PartitioningShiqing Ma, Juan Zhai, Fei Wang, Kyu Hyung Lee et al.USENIX Security 2017 · 136 citations
- Dependence-Preserving Data Compaction for Scalable Forensic AnalysisMd Nahid Hossain, Junao Wang, R. Sekar, Scott D. StollerUSENIX Security 2018 · 133 citations
- RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow TrackingYang Ji, Sangho Lee, Evan Downing, Weiren Wang et al.CCS 2017 · 119 citations
Related papers
- JSgraph: Enabling Reconstruction of Web Attacks via Efficient Tracking of Live In-Browser JavaScript ExecutionsBo Li, Phani Vadrevu, Kyu Hyung Lee, Roberto PerdisciNDSS 2018 · 61 citations
- Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation SystemJoey Allen, Zheng Yang, Matthew Landen, Raghav Bhat et al.CCS 2020 · 14 citations
- Enabling Reconstruction of Attacks on Users via Efficient Browsing SnapshotsPhani Vadrevu, Jienan Liu, Bo Li, Babak Rahbarinia et al.NDSS 2017 · 22 citations
- Forecasting Malware Capabilities From Cyber Attack Memory ImagesOmar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi et al.USENIX Security 2021 · 32 citations
- ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without InstrumentationLe Yu, Shiqing Ma, Zhuo Zhang, Guanhong Tao et al.NDSS 2021
