Provenance-based Intrusion Detection: Opportunities and Challenges

June 04, 2018 Β· Declared Dead Β· πŸ› Workshop on the Theory and Practice of Provenance

πŸ‘» CAUSE OF DEATH: Ghosted
No code link whatsoever

"No code URL or promise found in abstract"

Evidence collected by the PWNC Scanner

Authors Xueyuan Han, Thomas Pasquier, Margo Seltzer arXiv ID 1806.00934 Category cs.CR: Cryptography & Security Cross-listed eess.SY Citations 51 Venue Workshop on the Theory and Practice of Provenance Last Checked 5 months ago
Abstract
Intrusion detection is an arms race; attackers evade intrusion detection systems by developing new attack vectors to sidestep known defense mechanisms. Provenance provides a detailed, structured history of the interactions of digital objects within a system. It is ideal for intrusion detection, because it offers a holistic, attack-vector-agnostic view of system execution. As such, provenance graph analysis fundamentally strengthens detection robustness. We discuss the opportunities and challenges associated with provenance-based intrusion detection and provide insights based on our experience building such systems.
Community shame:
Not yet rated
Community Contributions

Found the code? Know the venue? Think something is wrong? Let us know!

πŸ“œ Similar Papers

In the same crypt β€” Cryptography & Security

Died the same way β€” πŸ‘» Ghosted