Forensic Analysis of Configuration-based Attacks

Forensic Analysis of Configuration-based Attacks
复制标题

DOI:
10.14722/ndss.2022.23057
复制
发表时间:
2022
期刊:
Proceedings 2022 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
M. A. Inam;Wajih Ul Hassan;A. Ahad;Adam Bates;Rashid Tahir;Tianyi Xu;Fareed Zaffar
M. A. Inam;Wajih Ul Hassan;A. Ahad;Adam Bates;Rashid Tahir;Tianyi Xu;Fareed Zaffar
中科院分区:
其他
文献类型:
--
作者:
M. A. Inam;Wajih Ul Hassan;A. Ahad;Adam Bates;Rashid Tahir;Tianyi Xu;Fareed Zaffar

文献摘要

相似文献

- 由于在操作系统级别的审核,现有的灾难性分析技术缺乏对重要的应用程序级语义的可见性,例如控制应用程序行为导致攻击属性不正确,在这项工作中,我们提出了专业的出处追踪器档案这可以通过向系统提供其他钩子来增强Linux审计基础架构的可见性,档案可以对目标应用程序的事件历史和因果关系产生整体视图,尤其是与配置变化有关的链条。真实的世界利用信息流跟踪和系统呼叫内省的多功能性来跟踪所有配置变化,包括直接更新与配置相关的程序变量的动态修改和修订,以配置在磁盘上使用磁盘上的配置,并使用可忽略的运行时间开销(少于7%)工作负载和现实世界攻击方案表明,档案可以有效地理由基于配置的攻击,并准确地重建整个攻击故事。
—Causality analysis is an effective technique for investigating and detecting cyber attacks. However, by focusing on auditing at the Operating System level, existing causal analysis techniques lack visibility into important application-level semantics, such as configuration changes that control application runtime behavior. This leads to incorrect attack attribution and half-baked tracebacks. In this work, we propose Dossier, a specialized provenance tracker that enhances the visibility of the Linux auditing infrastructure. By providing additional hooks into the system, Dossier can generate a holistic view of the target application’s event history and causal chains, particularly those pertaining to configuration changes that are among the most common attack vectors observed in the real world. The extra vantage points in Dossier enable forensic investigators to bridge the semantic gap and correctly piece together attack fragments. Dossier leverages the versatility of information flow tracking and system call introspection to track all configuration changes, including both dynamic modifications that directly update configuration-related program variables and revisions to configuration files on disk with negligible runtime overhead (less than 7%). Evaluation on realistic workloads and real-world attack scenarios shows that Dossier can effectively reason about configuration-based attacks and accurately reconstruct the whole attack stories.