Forensic Analysis of Configuration-based Attacks
Forensic Analysis of Configuration-based Attacks
复制标题
DOI:
10.14722/ndss.2022.23057
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
M. A. Inam;Wajih Ul Hassan;A. Ahad;Adam Bates;Rashid Tahir;Tianyi Xu;Fareed Zaffar
中科院分区:
文献类型:
--
作者:
M. A. Inam;Wajih Ul Hassan;A. Ahad;Adam Bates;Rashid Tahir;Tianyi Xu;Fareed Zaffar
—Causality analysis is an effective technique for investigating and detecting cyber attacks. However, by focusing on auditing at the Operating System level, existing causal analysis techniques lack visibility into important application-level semantics, such as configuration changes that control application runtime behavior. This leads to incorrect attack attribution and half-baked tracebacks. In this work, we propose Dossier, a specialized provenance tracker that enhances the visibility of the Linux auditing infrastructure. By providing additional hooks into the system, Dossier can generate a holistic view of the target application’s event history and causal chains, particularly those pertaining to configuration changes that are among the most common attack vectors observed in the real world. The extra vantage points in Dossier enable forensic investigators to bridge the semantic gap and correctly piece together attack fragments. Dossier leverages the versatility of information flow tracking and system call introspection to track all configuration changes, including both dynamic modifications that directly update configuration-related program variables and revisions to configuration files on disk with negligible runtime overhead (less than 7%). Evaluation on realistic workloads and real-world attack scenarios shows that Dossier can effectively reason about configuration-based attacks and accurately reconstruct the whole attack stories.