ProPatrol: Attack Investigation via Extracted High-Level Tasks

ProPatrol: Attack Investigation via Extracted High-Level Tasks
复制标题

ProPatrol:通过提取的高级任务进行攻击调查

DOI:
10.1007/978-3-030-05171-6_6
复制
发表时间:
2018
期刊:
ArXiv
影响因子:
--
通讯作者:
V. Venkatakrishnan
V. Venkatakrishnan
中科院分区:
--
文献类型:
--
作者:
Sadegh M. Milajerdi;Birhanu Eshete;Rigel Gjomemo;V. Venkatakrishnan

文献摘要

参考文献

被引文献

相似文献

内核审计日志是对网络攻击进行取证调查的宝贵信息来源。然而,审计日志中依赖信息的粗粒度导致构建包含虚假或不准确依赖的巨大攻击图。为了克服这个问题,我们提出了一个名为ProPatrol的系统,它利用了在安全敏感环境中使用的企业应用程序系列中的开放分区设计(例如,浏览器、聊天客户端、电子邮件客户端)。为了实现其目标,ProPatrol纯粹使用应用程序生成的审计日志事件,将应用程序的高级任务模型推断为输入处理隔间。这种方法的主要好处是它不依赖于源代码或二进制插装,而只依赖于应用程序架构的初步和一般知识来引导分析。我们对企业级攻击的实验表明,ProPatrol大大减少了取证调查工作,并迅速查明了攻击的根本原因。ProPatrol在商用操作系统上的运行时开销不到2%。
Kernel audit logs are an invaluable source of information in the forensic investigation of a cyber-attack. However, the coarse granularity of dependency information in audit logs leads to the construction of huge attack graphs which contain false or inaccurate dependencies. To overcome this problem, we propose a system, called ProPatrol, which leverages the open compartmentalized design in families of enterprise applications used in security-sensitive contexts (e.g., browser, chat client, email client). To achieve its goal, ProPatrol infers a model for an application’s high-level tasks as input-processing compartments using purely the audit log events generated by that application. The main benefit of this approach is that it does not rely on source code or binary instrumentation, but only on a preliminary and general knowledge of an application’s architecture to bootstrap the analysis. Our experiments with enterprise-level attacks demonstrate that ProPatrol significantly cuts down the forensic investigation effort and quickly pinpoints the root-cause of attacks. ProPatrol incurs less than 2% runtime overhead on a commodity operating system.
DOI: 10.14722/ndss.2018.23141
发表时间: 2018
期刊: --
影响因子: --
作者:
Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer
通讯作者: Wajih Ul Hassan;Mark Lemay;Nuraini Aguse;Adam Bates;Thomas Moyer