Rethinking System Audit Architectures for High Event Coverage and Synchronous Log Availability
Varun Gandhi, Sarbartha Banerjee, Aniket Agrawal, Adil Ahmad, Sangho Lee, Marcus Peinado
摘要
Once an attacker compromises the operating system, the integrity and availability of unprotected system audit logs still kept on the computer becomes uncertain. In this paper, we ask the question: can recently proposed audit systems aimed at tackling such an attacker provide enough information for forensic analysis? Our findings suggest that the answer is no, because the inefficient logging pipelines of existing audit systems prohibit generating log entries for a vast majority of attack events and protecting logs as soon as they are created (i.e., synchronously). This leads to a low attack event coverage within generated logs, while allowing attackers to tamper with unprotected logs after a compromise. To counter these limitations, we present OMNILOG, a system audit architecture that composes an end-to-end efficient logging pipeline where logs are rapidly generated and protected using a set of platform-agnostic security abstractions. This allows OMNILOG to enable high attack event coverage and synchronous log availability, while even outperforming the state-of-the-art audit systems that achieve neither property.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Veil: A Protected Services Framework for Confidential Virtual MachinesAdil Ahmad, Botong Ou, Congyu Liu, Xiaokuan Zhang 等ASPLOS 2023 · 被引用 12 次
- The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission SwitchesChuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad 等CCS 2024 · 被引用 4 次
- Entente: Cross-silo Intrusion Detection on Network Log Graphs with Federated LearningJiacen Xu, Chenang Li, Yu Zheng, Zhou LiNDSS 2026 · 被引用 3 次
- Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing SystemRui Zhao, Muhammad Shoaib, Viet Tung Hoang, Wajih Ul HassanCCS 2025 · 被引用 1 次
- HyperAudit: Towards User Transparent and Highly Efficient System Auditing for Cloud PlatformsRenpeng Zhang, Kai Shen, Peng Jiang, Ding Li 等USENIX Security 2026
它引用的顶会 Paper18
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and TaintingShiqing Ma, Xiangyu Zhang, Dongyan XuNDSS 2016 · 被引用 253 次
- High Fidelity Data Reduction for Big Data Security Dependency AnalysesZhang Xu, Zhenyu Wu, Zhichun Li, Kangkook Jee 等CCS 2016 · 被引用 197 次
- vTZ: Virtualizing ARM TrustZoneZhichao Hua, Jinyu Gu, Yubin Xia, Haibo Chen 等USENIX Security 2017 · 被引用 136 次
- Dependence-Preserving Data Compaction for Scalable Forensic AnalysisMd Nahid Hossain, Junao Wang, R. Sekar, Scott D. StollerUSENIX Security 2018 · 被引用 133 次
相关 Paper
- Logging to the Danger Zone: Race Condition Attacks and Defenses on System Audit FrameworksRiccardo Paccagnella, Kevin Liao, Dave Tian, Adam BatesCCS 2020 · 被引用 43 次
- eAudit: A Fast, Scalable and Deployable Audit Data Collection SystemR. Sekar, Hanke Kimm, Rohit AichS&P 2024 · 被引用 31 次
- OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log AnalysisWajih Ul Hassan, Mohammad A. Noureddine, Pubali Datta, Adam BatesNDSS 2020
- Faster Yet Safer: Logging System Via Fixed-Key BlockcipherViet Tung Hoang, Cong Wu, Xin YuanUSENIX Security 2022
- Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted ExecutionRiccardo Paccagnella, Pubali Datta, Wajih Ul Hassan, Adam Bates 等NDSS 2020
