308 citations · 489 across the 8 of their papers we have counts for
7 papers · 1 filter
Kairos: Practical Intrusion Detection and Investigation using Whole-system Provenance
Zijun Cheng, Qiujian Lv, Jinyuan Liang +4
Provenance graphs are structured audit logs that describe the history of a system's execution. Recent studies have explored a variety of techniques to analyze provenance graphs for…
Secure Namespaced Kernel Audit for Containers
Soo Yee Lim, Bogdan Stelea, Xueyuan Han +1
Despite the wide usage of container-based cloud computing, container auditing for security analysis relies mostly on built-in host audit systems, which often lack the ability to ca…
Xanthus: Push-button Orchestration of Host Provenance Data Collection
Xueyuan Han, James Mickens, Ashish Gehani +2
Host-based anomaly detectors generate alarms by inspecting audit logs for suspicious behavior. Unfortunately, evaluating these anomaly detectors is hard. There are few high-quality…
UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
Xueyuan Han, Thomas Pasquier, Adam Bates +2
Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based A…
ProvMark: A Provenance Expressiveness Benchmarking System
Sheung Chi Chan, James Cheney, Pramod Bhatotia +5
System level provenance is of widespread interest for applications such as security enforcement and information protection. However, testing the correctness or completeness of prov…
Runtime Analysis of Whole-System Provenance
Thomas Pasquier, Xueyuan Han, Thomas Moyer +5
Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of inf…