ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without Instrumentation
Le Yu, Shiqing Ma, Zhuo Zhang, Guanhong Tao, Xiangyu Zhang, Dongyan Xu, Vincent E. Urias, Han Wei Lin, Gabriela F. Ciocarlie, Vinod Yegneswaran, Ashish Gehani
摘要
—Cyber-attacks are becoming more persistent and complex. Most state-of-the-art attack forensics techniques either require annotating and instrumenting software applications or rely on high quality execution profiling to serve as the basis for anomaly detection. We propose a novel attack forensics technique ALchemist . It is based on the observations that built-in application logs provide critical high-level semantics and audit logs provide low-level fine-grained information; and the two share a lot of common elements. ALchemist is hence a log fusion technique that couples application logs and audit logs to derive critical attack information invisible in either log. It is based on a relational reasoning engine Datalog and features the capabilities of inferring new relations such as the task structure of execution (e.g., tabs in firefox ), especially in the presence of complex asynchronous execution models, and high-level dependencies between log events. Our evaluation on 15 popular applications including firefox , Chromium , and OpenOffice , and 14 APT attacks from the literature demonstrates that although ALchemist does not require instrumentation, it is highly effective in partitioning execution to autonomous tasks (in order to avoid bogus dependencies) and deriving precise attack provenance graphs, with very small overhead. It also outperforms NoDoze and OmegaLog, two state-of-the-art techniques that do not require instrumentation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper21
- SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit RecordsJun Zeng, Xiang Wang, Jiahao Liu, Yinfang Chen 等S&P 2022 · 被引用 187 次
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 被引用 31 次
- You Cannot Escape Me: Detecting Evasions of SIEM Rules in Enterprise NetworksRafael Uetz, Marco Herzog, Louis Hackländer, Simon Schwarz 等USENIX Security 2024 · 被引用 23 次
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 被引用 14 次
- PalanTír: Optimizing Attack Provenance with Hardware-enhanced System ObservabilityJun Zeng, Chuqi Zhang, Zhenkai LiangCCS 2022 · 被引用 11 次
它引用的顶会 Paper14
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 被引用 1,823 次
- HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsSadegh Momeni Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 等S&P 2019 · 被引用 550 次
- NoDoze: Combatting Threat Alert Fatigue with Automated Provenance TriageWajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen 等NDSS 2019 · 被引用 411 次
- Log2vec: A Heterogeneous Graph Embedding Based Approach for Detecting Cyber Threats within EnterpriseFucheng Liu, Yu Wen, Dongxue Zhang, Xihe Jiang 等CCS 2019 · 被引用 314 次
- SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit DataMd Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete 等USENIX Security 2017 · 被引用 291 次
相关 Paper
- OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log AnalysisWajih Ul Hassan, Mohammad A. Noureddine, Pubali Datta, Adam BatesNDSS 2020
- AutoLabel: Automated Fine-Grained Log Labeling for Cyber Attack Dataset GenerationYihao Peng, Tongxin Zhang, Jieshao Lai, Yuxuan Zhang 等USENIX Security 2025
- Fine-Grained Kernel Auditing Using Augmented Syscall Reference Behavior Analysis and Virtualized Selective TracingChuqi Zhang, Spencer Faith, Feras Al-Qassas, Theodorus Februanto 等S&P 2026
- Clearing the Clutter: Real-Time Program-Specific Log Consolidation for APT DetectionXiao Han, Jiahao Xue, Zhuo Lu, Yao LiuINFOCOM 2026
- MCI : Modeling-based Causality Inference in Audit Logging for Attack InvestigationYonghwi Kwon, Fei Wang, Weihang Wang, Kyu Hyung Lee 等NDSS 2018 · 被引用 116 次
