Forensic Analysis of Configuration-based Attacks
Muhammad Adil Inam, Wajih Ul Hassan, Ali Ahad, Adam Bates, Rashid Tahir, Tianyin Xu, Fareed Zaffar
摘要
—Causality analysis is an effective technique for investigating and detecting cyber attacks. However, by focusing on auditing at the Operating System level, existing causal analysis techniques lack visibility into important application-level semantics, such as configuration changes that control application runtime behavior. This leads to incorrect attack attribution and half-baked tracebacks. In this work, we propose Dossier, a specialized provenance tracker that enhances the visibility of the Linux auditing infrastructure. By providing additional hooks into the system, Dossier can generate a holistic view of the target application’s event history and causal chains, particularly those pertaining to configuration changes that are among the most common attack vectors observed in the real world. The extra vantage points in Dossier enable forensic investigators to bridge the semantic gap and correctly piece together attack fragments. Dossier leverages the versatility of information flow tracking and system call introspection to track all configuration changes, including both dynamic modifications that directly update configuration-related program variables and revisions to configuration files on disk with negligible runtime overhead (less than 7%). Evaluation on realistic workloads and real-world attack scenarios shows that Dossier can effectively reason about configuration-based attacks and accurately reconstruct the whole attack stories.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningMati Ur Rehman, Hadi Ahmadi, Wajih Ul HassanS&P 2024 · 被引用 104 次
- Large Language Models as Configuration ValidatorsXinyu Lian, Yinfang Chen, Runxiang Cheng, Jie Huang 等ICSE 2025 · 被引用 7 次
- SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsMuhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu 等S&P 2023
- Principled and Automated Approach for Investigating AR/VR AttacksMuhammad Shoaib, Alex Suh, Wajih Ul HassanUSENIX Security 2025
它引用的顶会 Paper13
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 被引用 253 次
- Towards Scalable Cluster Auditing through Grammatical Inference over Provenance GraphsWajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates 等NDSS 2018 · 被引用 157 次
- RAIN: Refinable Attack Investigation with On-demand Inter-Process Information Flow TrackingYang Ji, Sangho Lee, Evan Downing, Weiren Wang 等CCS 2017 · 被引用 119 次
- MCI : Modeling-based Causality Inference in Audit Logging for Attack InvestigationYonghwi Kwon, Fei Wang, Weihang Wang, Kyu Hyung Lee 等NDSS 2018 · 被引用 116 次
- UniSan: Proactive Kernel Memory Initialization to Eliminate Data LeakagesKangjie Lu, Chengyu Song, Taesoo Kim, Wenke LeeCCS 2016 · 被引用 81 次
相关 Paper
- OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log AnalysisWajih Ul Hassan, Mohammad A. Noureddine, Pubali Datta, Adam BatesNDSS 2020
- Runtime Analysis of Whole-System ProvenanceThomas F. J.-M. Pasquier, Xueyuan Han, Thomas Moyer, Adam Bates 等CCS 2018 · 被引用 112 次
- PalanTír: Optimizing Attack Provenance with Hardware-enhanced System ObservabilityJun Zeng, Chuqi Zhang, Zhenkai LiangCCS 2022 · 被引用 11 次
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani 等USENIX Security 2021 · 被引用 38 次
- Towards a Timely Causality Analysis for Enterprise SecurityYushan Liu, Mu Zhang, Ding Li, Kangkook Jee 等NDSS 2018 · 被引用 177 次
