A copy of this work was available on the public web and has been preserved in the Wayback Machine. The capture dates from 2018; you can also visit the original URL.
The file type is application/pdf
.
ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and Tainting
2016
Proceedings 2016 Network and Distributed System Security Symposium
unpublished
Provenance tracing is a very important approach to Advanced Persistent Threat (APT) attack detection and investigation. Existing techniques either suffer from the dependence explosion problem or have non-trivial space and runtime overhead, which hinder their application in practice. We propose ProTracer, a lightweight provenance tracing system that alternates between system event logging and unit level taint propagation. The technique is built on an on-the-fly system event processing
doi:10.14722/ndss.2016.23350
fatcat:mjvgl3gigrg4tfwpcju3ika4ru