pith. sign in

arxiv: 1806.00934 · v1 · pith:3GMU6RS7new · submitted 2018-06-04 · 💻 cs.CR · cs.SY

Provenance-based Intrusion Detection: Opportunities and Challenges

classification 💻 cs.CR cs.SY
keywords detectionintrusionchallengesopportunitiesprovenanceprovenance-basedsystemsystems
0
0 comments X
read the original abstract

Intrusion detection is an arms race; attackers evade intrusion detection systems by developing new attack vectors to sidestep known defense mechanisms. Provenance provides a detailed, structured history of the interactions of digital objects within a system. It is ideal for intrusion detection, because it offers a holistic, attack-vector-agnostic view of system execution. As such, provenance graph analysis fundamentally strengthens detection robustness. We discuss the opportunities and challenges associated with provenance-based intrusion detection and provide insights based on our experience building such systems.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.