308 citations · 468 across the 4 of their papers we have counts for
6 papers
Secure Namespaced Kernel Audit for Containers
Soo Yee Lim, Bogdan Stelea, Xueyuan Han +1
Despite the wide usage of container-based cloud computing, container auditing for security analysis relies mostly on built-in host audit systems, which often lack the ability to ca…
Xanthus: Push-button Orchestration of Host Provenance Data Collection
Xueyuan Han, James Mickens, Ashish Gehani +2
Host-based anomaly detectors generate alarms by inspecting audit logs for suspicious behavior. Unfortunately, evaluating these anomaly detectors is hard. There are few high-quality…
UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
Xueyuan Han, Thomas Pasquier, Adam Bates +2
Advanced Persistent Threats (APTs) are difficult to detect due to their "low-and-slow" attack patterns and frequent use of zero-day exploits. We present UNICORN, an anomaly-based A…
Runtime Analysis of Whole-System Provenance
Thomas Pasquier, Xueyuan Han, Thomas Moyer +5
Identifying the root cause and impact of a system intrusion remains a foundational challenge in computer security. Digital provenance provides a detailed history of the flow of inf…
Sharing and Preserving Computational Analyses for Posterity with encapsulator
Thomas Pasquier, Matthew K. Lau, Xueyuan Han +6
Open data and open-source software may be part of the solution to science's "reproducibility crisis", but they are insufficient to guarantee reproducibility. Requiring minimal end-…
Practical Whole-System Provenance Capture
Thomas Pasquier, Xueyuan Han, Mark Goldstein +4
Data provenance describes how data came to be in its present form. It includes data sources and the transformations that have been applied to them. Data provenance has many uses, f…