activity
20172021
most citedUNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

308 citations · 468 across the 4 of their papers we have counts for

collaborators

6 papers

cs.CR2021

Secure Namespaced Kernel Audit for Containers

Soo Yee Lim, Bogdan Stelea, Xueyuan Han +1

Despite the wide usage of container-based cloud computing, container auditing for security analysis relies mostly on built-in host audit systems, which often lack the ability to ca…

cs.CR20204 cited

Xanthus: Push-button Orchestration of Host Provenance Data Collection

Xueyuan Han, James Mickens, Ashish Gehani +2

Host-based anomaly detectors generate alarms by inspecting audit logs for suspicious behavior. Unfortunately, evaluating these anomaly detectors is hard. There are few high-quality…

cs.CR2020308 cited

UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

Xueyuan Han, Thomas Pasquier, Adam Bates +2

Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based A…

cs.CR2018

Runtime Analysis of Whole-System Provenance

Thomas Pasquier, Xueyuan Han, Thomas Moyer +5

Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of inf…

cs.DL2018

Sharing and Preserving Computational Analyses for Posterity with encapsulator

Thomas Pasquier, Matthew K. Lau, Xueyuan Han +6

Open data and open-source software may be part of the solution to science's "reproducibility crisis", but they are insufficient to guarantee reproducibility. Requiring minimal end-…

cs.CR2017156 cited

Practical Whole-System Provenance Capture

Thomas Pasquier, Xueyuan Han, Mark Goldstein +4

Data provenance describes how data came to be in its present form. It includes data sources and the transformations that have been applied to them. Data provenance has many uses, f…