arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CUSTOS:实现捕获-遏制边界处具备取证就绪能力的零信任

CUSTOS: Toward Forensic-Ready Zero Trust at the Capture-Containment Boundary

Avinash Srinivasan, John Paramadilok

arXiv 2608.17068首次发表:更新:

发表机构

U.S. Space Command(美国太空司令部)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出以取证管理点为核心的CUSTOS架构,解决零信任下易失性证据获取难的问题,实验验证其能恢复容器植入秘密,明确了取证就绪零信任的关键要求与证据恢复局限。

AI 中文摘要

零信任(ZT)用持续验证替代隐式信任,但双向TLS、临时工作负载、以身份为中心的控制及自动修复会降低有效载荷可见性、削弱基于IP的归因并缩小获取易失性证据的窗口。我们提出CUSTOS,这是一种以取证管理点(FMP)为核心的具备取证就绪能力的零信任参考架构,该架构协调分层捕获、与身份和策略关联的重构、遥测编排以及零信任控制的调查访问。我们使用实时执行网关加上单独的运行时和编排器实验评估了一个组合的组件级原型。在规定的信任假设下,始终在线的决策记录被捕获并在网关处进行哈希链处理,进程内策略引擎的吞吐量成本为1.9%-3.0%,在受监控工作负载之外保留了决策来源。反应式检查点(约65毫秒)先于防御者路由的秒级驱逐,但不及未排序的直接SIGKILL(约9毫秒)、内核内执行及对抗性自毁,产生取证粉碎机效应。在真实容器上,并发捕获和SIGKILL在1000次试验中均未恢复植入的秘密;将SIGKILL排序在FMP屏障后,1000次试验均成功恢复。主要的集成单节点Kubernetes对FMP控制的进程进行竞态检查点;容器内存捕获单独评估,在托管Kubernetes配置中不可用。在五个公共基准数据集和一个合成模式参考中,面向身份的遥测填充了决策记录模式的64%-75%,而面向网络的遥测仅填充18%-30%,同时速率限制限制了全内存准入上限。这些结果表明,具备取证就绪能力的零信任既需要始终在线的证据基础,也需要有界的反应式捕获,同时确定了易失性证据仍无法恢复的场景。

英文摘要

Zero Trust (ZT) replaces implicit trust with continuous verification, but automated containment can destroy volatile evidence before preservation. We propose CUSTOS, a forensic-ready ZT reference architecture whose Forensic Management Point (FMP) links identity and policy context to tiered, rate-limited capture and orders volatile-state acquisition ahead of defender-routed destructive containment. In a controlled real-container experiment, the planted artifact was lost in all 1000 trials when capture and SIGKILL began concurrently, showing that the direct kill outran the evaluated acquisition path. The sequencing barrier completed capture before releasing that same kill in all 1000 trials. In a matched four-condition comparison, only sequencing recovered the transient artifact (200/200); a periodic snapshot-chain baseline recovered long-lived evidence (200/200) but missed the transient artifact at both cadences. Sequencing added 0.140 s of containment delay and 9.99 MB per event. At a 2 s cadence, the chain added no containment delay but suspended the workload for 4.9% of wall-clock and accrued 59.2 KB/s after its root snapshot. The always-on decision record reduced in-process request-path throughput by 1.9-3.0%. In-kernel enforcement and adversarial self-destruction bypass the sequencing barrier; CUSTOS preserves volatile state otherwise lost to defender-routed containment at measured cost.

Comments20 pages. v3: revised manuscript and supplement; added a matched comparison of reactive, periodic, and sequenced preservation; expanded the evaluation and revised the related work; clarified the reference architecture and scope. Includes the IEEE preprint notice

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑