ALchemist: Fusing Application and Audit Logs for Precise Attack Provenance without Instrumentation

作者: Vinod Yegneswaran , Gabriela Ciocarlie , Dongyan Xu , Xiangyu Zhang , Vincent E. Urias

DOI: 10.14722/NDSS.2021.24445

关键词:

摘要:

参考文章(40)
Dominic G. Lucchetti, Peter M. Chen, Zhuoqing Morley Mao, Samuel T. King, Enriching Intrusion Alerts Through Multi-Host Causality. network and distributed system security symposium. ,(2005)
Tudor Dumitras, Iulian Neamtiu, Experimental challenges in cyber security: a story of provenance and lineage for malware usenix security symposium. pp. 9- 9 ,(2011)
Adam Bates, Dave Tian, Kevin R. B. Butler, Thomas Moyer, Trustworthy whole-system provenance for the Linux kernel usenix security symposium. pp. 319- 334 ,(2015)
Kiran-Kumar Muniswamy-Reddy, David A. Holland, Uri Braun, Margo Seltzer, Provenance-aware storage systems usenix annual technical conference. pp. 4- 4 ,(2006)
Karthik Nagaraj, Charles Killian, Jennifer Neville, Structured comparative analysis of systems logs to diagnose performance problems networked systems design and implementation. pp. 26- 26 ,(2012)
Radu Sion, Marianne Winslett, Ragib Hasan, The case of the fake Picasso: preventing history forgery with secure provenance file and storage technologies. pp. 1- 14 ,(2009)
Zhenyu Guo, Mao Yang, Fan Long, Haoxiang Lin, Lidong Zhou, Chaoqiang Deng, Dong Zhou, Changshu Liu, G 2 : a graph processing system for diagnosing distributed systems usenix annual technical conference. pp. 27- 27 ,(2011)
Alina Oprea, Zhou Li, Ting-Fang Yen, Sang H. Chin, Sumayah Alrwais, Detection of Early-Stage Enterprise Infection by Mining Large-Scale Log Data dependable systems and networks. pp. 45- 56 ,(2015) , 10.1109/DSN.2015.14
Michael Backes, Sven Bugiel, Sebastian Gerling, Scippa: system-centric IPC provenance on Android annual computer security applications conference. pp. 36- 45 ,(2014) , 10.1145/2664243.2664264
Di Ma, Practical forward secure sequential aggregate signatures computer and communications security. pp. 341- 352 ,(2008) , 10.1145/1368310.1368361