面向安全的溯源技术的内核遥测选项研究
A Study of Kernel Telemetry Options for Security-Oriented Provenance
浏览论文内容
中文总结 AI 辅助
本文分析内核遥测捕获方法确定eBPF最具前景,对8个溯源系统和5个捕获代理分类后发现,多数工具的捕获层无法保证事件完整性与可用性,不满足安全用例要求。
中文摘要 AI 辅助
溯源旨在为安全和取证应用捕获系统对象的起源、转换及交互过程。现有溯源捕获方法仍面临重大挑战,尚未适用于生产环境。本文首先分析主要的内核遥测捕获方法,确定eBPF是最具前景的方案,并通过微基准测试评估其性能开销及用于实现捕获粒度的过滤机制,例如将捕获范围限制在单个容器内。在此基础上,本文根据研究的捕获方法和过滤方式,对8个溯源系统和5个可作为其捕获层的捕获代理(统称为工具)进行分类。研究发现,这些工具构建于高度异构的捕获层之上,其中大多数无法保证所捕获事件的完整性和可用性,完全无法满足面向安全的用例的要求。
英文摘要
Provenance aims to capture the origins, transformations, and interactions of system objects for security and forensic applications. Existing provenance capture approaches still face major challenges and are not yet ready for production environments. In this paper, we first analyze the main kernel telemetry capture approaches, identifying eBPF as the most promising, and complement this analysis with micro benchmarks to assess its performance overhead and the filtering mechanisms used to achieve capture granularity, such as restricting capture to individual containers. Building on this foundation, we then classify, according to the studied capture approaches and filtering methods, eight provenance systems and five capture agents that could serve as their capture layers, collectively referred to as tools. Our study reveals that these tools are built on highly heterogeneous capture layers, most of which cannot guarantee the integrity and availability of the captured events, completely failing to meet the requirements of security-oriented use cases.
发表机构
- Orange Research(橙研实验室)
- Samovar, Télécom SudParis, Institut Polytechnique de Paris(萨摩瓦尔实验室,巴黎高等电信学院,巴黎理工学院)
机构由 AI 辅助整理,请以论文原文为准。