OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log Analysis

OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log Analysis
复制标题

DOI:
10.14722/ndss.2020.24270
复制
发表时间:
2020
期刊:
Proceedings 2020 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Wajih Ul Hassan;Mohammad A. Noureddine;Pubali Datta;Adam Bates
Wajih Ul Hassan;Mohammad A. Noureddine;Pubali Datta;Adam Bates
中科院分区:
其他
文献类型:
--
作者:
Wajih Ul Hassan;Mohammad A. Noureddine;Pubali Datta;Adam Bates

文献摘要

被引文献

相似文献

因果关系分析的最新进展使调查人员能够使用起源图跟踪多阶段攻击。基于系统层审计日志(例如,系统调用),这些方法忽略了应用程序上下文的重要源(例如,电子邮件地址、HTTP响应代码),这些信息可以在系统的更高层中找到。虽然这些信息对于理解攻击行为通常是必不可少的,但由于系统层之间存在语义差距,因此很难将这些证据纳入因果分析引擎。为了解决这一不足,我们提出了通用出处的概念,它编码所有法医相关的因果依赖关系,而不管它们的起源层。为了在商品系统上透明地实现这一愿景,我们提出了OmegaLog,这是一个出处跟踪器,可以弥合系统和应用程序日志上下文之间的语义差距。OmegaLog分析程序二进制文件以识别和建模应用层日志记录行为,从而实现应用程序事件与系统层访问的准确协调。OmegaLog然后拦截应用程序的运行时日志记录活动,并将这些事件移植到系统层起源图上,使调查人员能够更精确地推断攻击的性质。我们证明,我们的系统是广泛适用于现有的软件项目,可以透明地促进执行分区的起源图没有任何培训或开发人员的干预。对真实攻击场景的评估表明,我们的技术生成了简洁的起源图,相对于最先进的技术具有丰富的语义信息,平均运行时开销为4%。
—Recent advances in causality analysis have en- abled investigators to trace multi-stage attacks using provenance graphs. Based on system-layer audit logs (e.g., syscalls), these approaches omit vital sources of application context (e.g., email addresses, HTTP response codes) that can be found in higher layers of the system. Although such information is often essential to understanding attack behaviors, it is difficult to incorporate this evidence into causal analysis engines because of the semantic gap that exists between system layers. To address that short- coming, we propose the notion of universal provenance , which encodes all forensically relevant causal dependencies regardless of their layer of origin. To transparently realize that vision on commodity systems, we present OmegaLog, a provenance tracker that bridges the semantic gap between system and application logging contexts. OmegaLog analyzes program binaries to identify and model application-layer logging behaviors, enabling accurate reconciliation of application events with system-layer accesses. OmegaLog then intercepts applications’ runtime logging activities and grafts those events onto the system-layer provenance graph, allowing investigators to reason more precisely about the nature of attacks. We demonstrate that our system is widely applicable to existing software projects and can transparently facilitate execution partitioning of provenance graphs without any training or developer intervention. Evaluation on real-world attack scenarios shows that our technique generates concise provenance graphs with rich semantic information relative to the state-of-the-art, with an average runtime overhead of 4%.