• DocumentCode
    2178581
  • Title

    FloTracker: Log-Free and Instantaneous Host-Based Intrusion Root-Cause Analysis

  • Author

    Zonouz, Saman ; Seyfi, Ahmad ; Mesa, Alejandro ; Salles-Loustau, Gabriel

  • Author_Institution
    Electr. & Comput. Eng, Univ. of Miami, Miami, FL, USA
  • fYear
    2013
  • fDate
    2-4 Dec. 2013
  • Firstpage
    246
  • Lastpage
    255
  • Abstract
    Preserving the availability and integrity of security-critical computer systems in a fast-spreading sophisticated intrusions environment, requires advance algorithms, accurate and efficient intrusion diagnosis, along side with root-cause analysis techniques. In this paper we introduce FloTracker that is an online log-free host-based root-cause analysis detection engine, with instantaneous forensics capabilities. FloTracker presents security administrators as well as automated response systems, with immediate forensics information. For instance, it will identify a system´s entry point of intrusion as soon as a critical security incident occurs, e.g., a sensitive system file modification is detected within the target system. To this end, FloTracker automatically defines an access control policy set (possibly with no access restriction) for the target system that facilitates real-time backtracking of an intrusion, given a detection point. Our experimental results on a real-world SE-Linux test-bed showed that the FloTracker could efficiently update the system´s configuration thus modifications will not affect the functionalities of the system, yet providing a log-free and instantaneous root-cause analysis capability.
  • Keywords
    authorisation; safety-critical software; FloTracker; access control policy set; automated response systems; forensics information; instantaneous forensics capabilities; intrusion diagnosis; log-free instantaneous host-based intrusion root-cause analysis; root-cause analysis detection engine; root-cause analysis techniques; security administrators; security incident; security-critical computer systems; system availability; system integrity; Access control; Algorithm design and analysis; Databases; Generators; Intrusion detection; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Computing (PRDC), 2013 IEEE 19th Pacific Rim International Symposium on
  • Conference_Location
    Vancouver, BC
  • Type

    conf

  • DOI
    10.1109/PRDC.2013.46
  • Filename
    6820872