308 citations · 517 across the 12 of their papers we have counts for
5 papers · 1 filter
Xanthus: Push-button Orchestration of Host Provenance Data Collection
Xueyuan Han, James Mickens, Ashish Gehani +2
Host-based anomaly detectors generate alarms by inspecting audit logs for suspicious behavior. Unfortunately, evaluating these anomaly detectors is hard. There are few high-quality…
UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
Xueyuan Han, Thomas Pasquier, Adam Bates +2
Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based A…
ProvMark: A Provenance Expressiveness Benchmarking System
Sheung Chi Chan, James Cheney, Pramod Bhatotia +5
System level provenance is of widespread interest for applications such as security enforcement and information protection. However, testing the correctness or completeness of prov…
Runtime Analysis of Whole-System Provenance
Thomas Pasquier, Xueyuan Han, Thomas Moyer +5
Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of inf…
Practical Whole-System Provenance Capture
Thomas Pasquier, Xueyuan Han, Mark Goldstein +4
Data provenance describes how data came to be in its present form. It includes data sources and the transformations that have been applied to them. Data provenance has many uses, f…