Retroactive auditing
Name
Kaashoek_Retroactive auditing.pdf
Size
150.96 KB
Format
Adobe PDF
Checksum (MD5)
6be95eeefd9b8b557007efc1469fca38
Author(s) • •
Wang, Xi
Zeldovich, Nickolai
Kaashoek, M. Frans
Date Issued
January 2011
Journal
Proceedings of the Second Asia-Pacific Workshop on Systems (APSys '11)
Publisher
Association for Computing Machinery (ACM)
Citation
Xi Wang, Nickolai Zeldovich, and M. Frans Kaashoek. 2011. Retroactive auditing. In Proceedings of the Second Asia-Pacific Workshop on Systems (APSys '11). ACM, New York, NY, USA, , Article 9 , 5 pages.
Version
Author's final manuscript
Abstract
Retroactive auditing is a new approach for detecting past intrusions and vulnerability exploits based on security patches. It works by spawning two copies of the code that was patched, one with and one without the patch, and running both of them on the same inputs observed during the system's original execution. If the resulting outputs differ, an alarm is raised, since the input may have triggered the patched vulnerability. Unlike prior tools, retroactive auditing does not require developers to write predicates for each vulnerability.
MIT Department
Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike 3.0
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/2103799.2103810