中文

ProPatrol:基于提取高层任务的攻击调查

密码学与安全 2018-10-16 v1

摘要

内核审计日志是网络攻击取证调查中极具价值的信息来源。然而,审计日志中依赖信息的粗粒度导致构建出包含错误或不准确依赖关系的大型攻击图。为克服该问题,我们提出一个名为 ProPatrol 的系统,其利用安全敏感场景(如浏览器、聊天客户端、邮件客户端)中企业级应用族所采用的开放分舱式设计。为实现目标,ProPatrol 仅使用该应用生成的审计日志事件,将其高层任务推断为输入处理分舱的模型。该方法的主要优势在于不依赖源代码或二进制插桩,仅需对应用架构的初步一般性了解即可引导分析。我们在企业级攻击上的实验表明,ProPatrol 显著减少了取证调查工作量,并快速定位攻击根因。ProPatrol 在商用操作系统上产生的运行时开销低于 2%。

关键词

引用

@article{arxiv.1810.05711,
  title  = {ProPatrol: Attack Investigation via Extracted High-Level Tasks},
  author = {Sadegh M. Milajerdi and Birhanu Eshete and Rigel Gjomemo and V. N. Venkatakrishnan},
  journal= {arXiv preprint arXiv:1810.05711},
  year   = {2018}
}

备注

The published version of this article will appear in proceedings of the 14th International Conference on Information Systems Security in Dec 2018