RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow Tracking
Yang Ji, Sangho Lee, Evan Downing, Weiren Wang, Mattia Fazzini, Taesoo Kim, Alessandro Orso, Wenke Lee
摘要
As modern attacks become more stealthy and persistent, detecting or preventing them at their early stages becomes virtually impossible. Instead, an attack investigation or provenance system aims to continuously monitor and log interesting system events with minimal overhead. Later, if the system observes any anomalous behavior, it analyzes the log to identify who initiated the attack and which resources were affected by the attack and then assess and recover from any damage incurred. However, because of a fundamental tradeoff between log granularity and system performance, existing systems typically record system-call events without detailed program-level activities (e.g., memory operation) required for accurately reconstructing attack causality or demand that every monitored program be instrumented to provide program-level information. To address this issue, we propose Rain, a Refinable Attack Investigation system based on a record-replay technology that records system-call events during runtime and performs instruction-level dynamic information flow tracking (DIFT) during on-demand process replay. Instead of replaying every process with DIFT, Rain conducts system-call-level reachability analysis to filter out unrelated processes and to minimize the number of processes to be replayed, making inter-process DIFT feasible. Evaluation results show that Rain effectively prunes out unrelated processes and determines attack causality with negligible false positive rates. In addition, the runtime overhead of Rain is similar to existing system-call level provenance systems and its analysis overhead is much smaller than full-system DIFT.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper39
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingSadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. VenkatakrishnanCCS 2019 · 被引用 313 次
- SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit RecordsJun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen 等S&P 2022 · 被引用 187 次
- Dependence-Preserving Data Compaction for Scalable Forensic AnalysisMd Nahid Hossain, Junao Wang, R. Sekar, Scott D. StollerUSENIX Security 2018 · 被引用 133 次
- DEPCOMM: Graph Summarization on System Audit Logs for Attack InvestigationZhiqiang Xu, Pengcheng Fang, Changlin Liu, Xusheng Xiao 等S&P 2022 · 被引用 88 次
它引用的顶会 Paper3
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato 等USENIX Security 2016 · 被引用 296 次
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 被引用 253 次
- High Fidelity Data Reduction for Big Data Security Dependency AnalysesZhang Xu, Zhenyu Wu, Zhichun Li, Kangkook Jee 等CCS 2016 · 被引用 197 次
相关 Paper
- Enabling Refinable Cross-Host Attack Investigation with Efficient Data Flow Tagging and TrackingYang Ji, Sangho Lee, Mattia Fazzini, Joey Allen 等USENIX Security 2018 · 被引用 70 次
- PalanTír: Optimizing Attack Provenance with Hardware-enhanced System ObservabilityJun Zeng, Chuqi Zhang, Zhenkai LiangCCS 2022 · 被引用 11 次
- MCI : Modeling-based Causality Inference in Audit Logging for Attack InvestigationYonghwi Kwon, Fei Wang, Weihang Wang, Kyu Hyung Lee 等NDSS 2018 · 被引用 116 次
- Forensic Analysis of Configuration-based AttacksMuhammad Adil Inam, Wajih Ul Hassan, Ali Ahad, Adam Bates 等NDSS 2022
- UIScope: Accurate, Instrumentation-free, and Visible Attack Investigation for GUI ApplicationsRunqing Yang, Shiqing Ma, Haitao Xu, Xiangyu Zhang 等NDSS 2020
