Annual Computer Security Applications Conference (ACSAC) 2020

Full Program »

This is Why We Can’t Cache Nice Things: Lightning-Fast Threat Hunting using Suspicion-Based Hierarchical Storage

Recent advances in the causality analysis can accelerate incident response time but only after a causal graph of the attack has been constructed. Unfortunately, existing causal graph generation techniques are mainly offline and may take hours or days to respond to investigator queries, creating greater opportunity for attackers to hide their attack footprint, gain persistency, and propagate to other machines. To address that limitation, we present Swift, a threat investigation system that provides high-throughput causality tracking and real-time causal graph generation capabilities. We design an in-memory graph database that enables space-efficient graph storage and online causality tracking with minimal disk operations. We propose a hierarchical storage system that keeps forensically-relevant part of the causal graph in main memory while evicting rest to disk. To identify causal graph that is likely to be relevant during forensic investigations, we design an asynchronous cache eviction policy that calculates the most suspicious part of the causal graph and caches only that part in the main memory. We evaluated Swift on a real-world enterprise to demonstrate how our system scales to process typical event loads as well as how it responds to forensic queries when security alerts occur. Results show that Swift is scalable, modular, and answers forensic queries in real-time even when analyzing audit logs containing tens of millions of events.

Wajih Ul Hassan
University Of Illinois Urbana-Champaign

Ding Li
NEC Laboratories America, Inc.

Kangkook Jee
University of Texas at Dallas

Xiao Yu
NEC Laboratories America, Inc.

Kexuan (Klaus) Zou
University Of Illinois Urbana-Champaign

Daiwei Wang
University Of Illinois Urbana-Champaign

Zhengzhang Chen
NEC Laboratories America, Inc.

Zhichun Li
NEC Laboratories America, Inc.

Junghwan Rhee
NEC Laboratories America, Inc.

Jiaping Gui
NEC Laboratories America, Inc.

Adam Bates
University Of Illinois Urbana-Champaign

Paper (ACM DL)

Slides

Video

 



Powered by OpenConf®
Copyright©2002-2021 Zakon Group LLC