Runtime Analysis of Whole-System Provenance
Thomas F. J.-M. Pasquier, Xueyuan Han, Thomas Moyer, Adam Bates, Olivier Hermant, David M. Eyers, Jean Bacon, Margo I. Seltzer
摘要
Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of information within a computing system, connecting suspicious events to their root causes. Although existing provenance-based auditing techniques provide value in forensic analysis, they assume that such analysis takes place only retrospectively. Such post-hoc analysis is insufficient for realtime security applications; moreover, even for forensic tasks, prior provenance collection systems exhibited poor performance and scalability, jeopardizing the timeliness of query responses. We present CamQuery, which provides inline, realtime provenance analysis, making it suitable for implementing security applications. CamQuery is a Linux Security Module that offers support for both userspace and in-kernel execution of analysis applications. We demonstrate the applicability of CamQuery to a variety of runtime security applications including data loss prevention, intrusion detection, and regulatory compliance. In evaluation, we demonstrate that CamQuery reduces the latency of realtime query mechanisms, while imposing minimal overheads on system execution. CamQuery thus enables the further deployment of provenance-based technologies to address central challenges in computer security.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper31
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- Tactical Provenance Analysis for Endpoint Detection and Response SystemsWajih Ul Hassan, Adam Bates, Daniel MarinoS&P 2020 · 被引用 317 次
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 被引用 313 次
- SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit RecordsJun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen 等S&P 2022 · 被引用 187 次
- Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceZijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang 等S&P 2024 · 被引用 125 次
它引用的顶会 Paper6
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 被引用 253 次
- Towards a Timely Causality Analysis for Enterprise SecurityYushan Liu, Mu Zhang, Ding Li, Kangkook Jee 等NDSS 2018 · 被引用 177 次
- Towards Scalable Cluster Auditing through Grammatical Inference over Provenance GraphsWajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates 等NDSS 2018 · 被引用 157 次
- MPI: Multiple Perspective Attack Investigation with Semantic Aware Execution PartitioningShiqing Ma, Juan Zhai, Fei Wang, Kyu Hyung Lee 等USENIX Security 2017 · 被引用 136 次
- SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior DetectionPeng Gao, Xusheng Xiao, Ding Li, Zhichun Li 等USENIX Security 2018 · 被引用 122 次
相关 Paper
- SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsMuhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu 等S&P 2023
- Forensic Analysis of Configuration-based AttacksMuhammad Adil Inam, Wajih Ul Hassan, Ali Ahad, Adam Bates 等NDSS 2022
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani 等USENIX Security 2021 · 被引用 38 次
- RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow TrackingYang Ji, Sangho Lee, Evan Downing, Weiren Wang 等CCS 2017 · 被引用 119 次
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 被引用 31 次
