Hi-Fi: collecting high-fidelity whole-system provenance

@inproceedings{Pohly2012HiFiCH,
  title={Hi-Fi: collecting high-fidelity whole-system provenance},
  author={Devin J. Pohly and Stephen E. McLaughlin and P. McDaniel and Kevin R. B. Butler},
  booktitle={ACSAC '12},
  year={2012}
}
Data provenance---a record of the origin and evolution of data in a system---is a useful tool for forensic analysis. However, existing provenance collection mechanisms fail to achieve sufficient breadth or fidelity to provide a holistic view of a system's operation over time. We present Hi-Fi, a kernel-level provenance system which leverages the Linux Security Modules framework to collect high-fidelity whole-system provenance. We demonstrate that Hi-Fi is able to record a variety of malicious… Expand
109 Citations

Figures, Tables, and Topics from this paper

Practical whole-system provenance capture
  • 50
  • Highly Influenced
  • PDF
Trustworthy Whole-System Provenance for the Linux Kernel
  • 145
  • PDF
High-throughput ingest of data provenance records into Accumulo
  • T. Moyer, V. Gadepally
  • Computer Science
  • 2016 IEEE High Performance Extreme Computing Conference (HPEC)
  • 2016
  • 11
  • PDF
Expressiveness Benchmarking for System-Level Provenance
  • 11
  • Highly Influenced
  • PDF
Linux Provenance Modules : Secure Provenance Collection for the Linux Kernel
  • 1
  • PDF
Taming the Costs of Trustworthy Provenance through Policy Reduction
  • 7
  • PDF
PR EP RI NT Runtime Analysis of Whole-System Provenance
  • Highly Influenced
  • PDF
Runtime Analysis of Whole-System Provenance
  • 28
  • Highly Influenced
  • PDF
RecProv: Towards Provenance-Aware User Space Record and Replay
  • 9
  • PDF
...
1
2
3
4
5
...

References

SHOWING 1-3 OF 3 REFERENCES
Policy auditing over incomplete logs: theory, implementation and applications
  • 98
  • Highly Influential
  • PDF
I and J
  • 128,990
  • Highly Influential
Forensix: a robust
  • high-performance reconstruction system. In Distributed Computing Systems Workshops
  • 2005