仪表(计算机编程)
审计
计算机科学
登录中
操作系统
会计
业务
林业
地理
作者
Shiqing Ma,Kyu Eun Lee,Chung Yong Kim,Junghwan Rhee,Xiangyu Zhang,Dongyan Xu
出处
期刊:Annual Computer Security Applications Conference
日期:2015-12-07
被引量:46
标识
DOI:10.1145/2818000.2818039
摘要
Audit logging is an important approach to cyber attack investigation. However, traditional audit logging either lacks accuracy or requires expensive and complex binary instrumentation. In this paper, we propose a Windows based audit logging technique that features accuracy and low cost. More importantly, it does not require instrumenting the applications, which is critical for commercial software with IP protection. The technique is build on Event Tracing for Windows (ETW). By analyzing ETW log and critical parts of application executables, a model can be constructed to parse ETW log to units representing independent sub-executions in a process. Causality inferred at the unit level renders much higher accuracy, allowing us to perform accurate attack investigation and highly effective log reduction.
科研通智能强力驱动
Strongly Powered by AbleSci AI