activity
20092022
most citedUNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

308 citations · 517 across the 12 of their papers we have counts for

collaborators
Showing cs.CRShow all

5 papers · 1 filter

cs.CR20204 cited

Xanthus: Push-button Orchestration of Host Provenance Data Collection

Xueyuan Han, James Mickens, Ashish Gehani +2

Host-based anomaly detectors generate alarms by inspecting audit logs for suspicious behavior. Unfortunately, evaluating these anomaly detectors is hard. There are few high-quality…

cs.CR2020308 cited

UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

Xueyuan Han, Thomas Pasquier, Adam Bates +2

Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based A…

cs.CR20195 cited

ProvMark: A Provenance Expressiveness Benchmarking System

Sheung Chi Chan, James Cheney, Pramod Bhatotia +5

System level provenance is of widespread interest for applications such as security enforcement and information protection. However, testing the correctness or completeness of prov…

cs.CR2018

Runtime Analysis of Whole-System Provenance

Thomas Pasquier, Xueyuan Han, Thomas Moyer +5

Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of inf…

cs.CR2017156 cited

Practical Whole-System Provenance Capture

Thomas Pasquier, Xueyuan Han, Mark Goldstein +4

Data provenance describes how data came to be in its present form. It includes data sources and the transformations that have been applied to them. Data provenance has many uses, f…