论文标题

Xanthus:主机出处数据收集的按钮编排

Xanthus: Push-button Orchestration of Host Provenance Data Collection

论文作者

Han, Xueyuan, Mickens, James, Gehani, Ashish, Seltzer, Margo, Pasquier, Thomas

论文摘要

基于主机的异常检测器通过检查审核日志是否可疑行为来产生警报。不幸的是,评估这些异常检测器很难。很少有高质量的公开审核日志,并且没有现有的框架可以实现按钮创建现实的系统痕迹。为了使跟踪生成更容易,我们创建了Xanthus,这是一种自动化工具,该工具策划了虚拟机以生成现实的审核日志。使用Xanthus的简单管理接口,管理员选择一个基本VM图像,配置一个特定的跟踪框架以在该VM中使用,并定义收集和保存跟踪数据的发布后脚本。一旦数据收集完成,Xanthus就会创建一个自我描述的存档,其中包含VM,其配置参数和收集的跟踪数据。我们证明,Xanthus隐藏了人类经常犯错的许多乏味(但微妙的)编排任务。 Xanthus避免了导致不可杀伤实验的错误。

Host-based anomaly detectors generate alarms by inspecting audit logs for suspicious behavior. Unfortunately, evaluating these anomaly detectors is hard. There are few high-quality, publicly-available audit logs, and there are no pre-existing frameworks that enable push-button creation of realistic system traces. To make trace generation easier, we created Xanthus, an automated tool that orchestrates virtual machines to generate realistic audit logs. Using Xanthus' simple management interface, administrators select a base VM image, configure a particular tracing framework to use within that VM, and define post-launch scripts that collect and save trace data. Once data collection is finished, Xanthus creates a self-describing archive, which contains the VM, its configuration parameters, and the collected trace data. We demonstrate that Xanthus hides many of the tedious (yet subtle) orchestration tasks that humans often get wrong; Xanthus avoids mistakes that lead to non-replicable experiments.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源