Practical automatic determination of causal relationships in software execution traces
Practical automatic determination of causal relationships in software execution traces(2011)
摘要
From the system investigator who needs to analyze an intrusion (“how did the intruder break in?”), to the forensic expert who needs to investigate digital crimes (“did the suspect commit the crime?”), security experts have to frequently answer questions about the cause-effect relationships between the various events that occur in a computer system. The implications of using causality determination techniques with a low accuracy vary from slowing down incident response to undermining the evidence unearthed by forensic experts. This dissertation presents research done along two areas: (1) We present an empirical study evaluating the accuracy and performance overhead of existing causality determination techniques. Our study shows that existing causality determination techniques are either accurate or efficient, but seldom both. (2) We propose a novel approach to causality determination based on coarse-grained observation of control-flow of program execution. Our evaluation shows that our approach is both practical in terms of low runtime overhead and accurate in terms of low false positives and false negatives.
更多查看译文
关键词
causality determination technique,software execution trace,causal relationship,low accuracy,forensic expert,low runtime overhead,empirical study,novel approach,low false positive,computer system,practical automatic determination,false negative,performance overhead
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络