Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security · 2022 · 11 citations · 36 references
System auditing is the foundation of attack provenance to investigate root causes and ramifications of cyber-attacks. However, provenance tracking on coarse-grained audit logs suffers from false causalities caused by dependency explosion. Recent approaches address this problem by increasing provenance granularity using execution partitioning or record-and-replay techniques. Unfortunately, they require program instrumentation and/or impose an unaffordable overhead, which is not practical in deployment.
36
Patrick Cousot, Radhia Cousot · 1977 · 6.1K citations
Programming Language Theory, Actual Computations, Declarative Programming +10
SOK: (State of) The Art of War: Offensive Techniques in Binary Analysis
Yan Shoshitaishvili, Ruoyu Wang, Christopher Salls et al. · 2016 · 883 citations · Full text
Angora: Efficient Fuzzing by Principled Search
Unicorn: Runtime Provenance-Based Detector for Advanced Persistent Threats
2020 · 246 citations · Full text