{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T23:42:45Z","timestamp":1784590965040,"version":"3.55.0"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSFC Program","award":["62076146"],"award-info":[{"award-number":["62076146"]}]},{"name":"NSFC Program","award":["62021002"],"award-info":[{"award-number":["62021002"]}]},{"name":"NSFC Program","award":["U20A6003"],"award-info":[{"award-number":["U20A6003"]}]},{"name":"NSFC Program","award":["6212780016"],"award-info":[{"award-number":["6212780016"]}]},{"DOI":"10.13039\/501100001809","name":"Industrial Technology Infrastructure Public Service Platform Project \u201cPublic Service Platform for Urban Rail Transit Equipment Signal System Testing and Safety Evaluation\u201d","doi-asserted-by":"publisher","award":["2022-233-225"],"award-info":[{"award-number":["2022-233-225"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Ministry of Industry and Information Technology of China"},{"name":"National Key Research and Development Program of China","award":["2022YFB4301202"],"award-info":[{"award-number":["2022YFB4301202"]}]},{"name":"National Key Research and Development Program of China","award":["2023YFB3307500"],"award-info":[{"award-number":["2023YFB3307500"]}]},{"name":"Science and Technology Innovation Project of Hunan Province","award":["2023RC4014"],"award-info":[{"award-number":["2023RC4014"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3459616","type":"journal-article","created":{"date-parts":[[2024,9,26]],"date-time":"2024-09-26T17:44:43Z","timestamp":1727372683000},"page":"9566-9581","source":"Crossref","is-referenced-by-count":6,"title":["The Last Mile of Attack Investigation: Audit Log Analysis Toward Software Vulnerability Location"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-0038-7806","authenticated-orcid":false,"given":"Changhua","family":"Chen","sequence":"first","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4731-3390","authenticated-orcid":false,"given":"Tingzhen","family":"Yan","sequence":"additional","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chenxuan","family":"Shi","sequence":"additional","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-5071-5306","authenticated-orcid":false,"given":"Hao","family":"Xi","sequence":"additional","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhirui","family":"Fan","sequence":"additional","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9608-5808","authenticated-orcid":false,"given":"Hai","family":"Wan","sequence":"additional","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6168-7016","authenticated-orcid":false,"given":"Xibin","family":"Zhao","sequence":"additional","affiliation":[{"name":"Beijing National Research Center for Information Science and Technology (BNRist), Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Apache HTTP Benchmarking Tool","year":"2024"},{"key":"ref2","volume-title":"2023 Annual Threat Intelligence Report","year":"2023"},{"key":"ref3","volume-title":"Apache HTTP Test Project","year":"1997"},{"key":"ref4","volume-title":"Tool Interface Standard (TIS) Executable and Linking Format (ELF) Specification","year":"1995"},{"key":"ref5","volume-title":"OWASP Top Ten","year":"2024"},{"key":"ref6","volume-title":"[AMQ-6013] Restrict Classes That Can Be Serialized in ObjectMessages","year":"2015"},{"key":"ref7","volume-title":"GitHub AMQ-6013 Activemq@a7e2a44","year":"2015"},{"key":"ref8","volume-title":"CVE-2015-5254 Unsafe Deserialization","year":"2015"},{"key":"ref9","volume-title":"GitHub PHP-SRC@046827a","year":"2021"},{"key":"ref10","volume-title":"PHP Changes to Git Commit Workflow","year":"2021"},{"key":"ref11","volume-title":"GitHub Patch 8.1.1365: Vim@5357552","year":"2019"},{"key":"ref12","volume-title":"Vim <8.1.1365\u2014Code Execution","year":"2019"},{"key":"ref13","volume-title":"Apache HTTP Server 2.4 Vulnerabilities","year":"2021"},{"key":"ref14","volume-title":"Mod_Proxy. Httpd@bac6dd2","year":"2021"},{"key":"ref15","volume-title":"Hex Rays IDA Pro","year":"2024"},{"key":"ref16","volume-title":"The Linux Audit Daemon","year":"2021"},{"key":"ref17","volume-title":"CodeChecker","year":"2024"},{"key":"ref18","volume-title":"CodeQL for Research","year":"2021"},{"key":"ref19","volume-title":"American Fuzzy Lop","year":"2017"},{"key":"ref20","volume-title":"NVD\u2014Cve-2014-6271","year":"2014"},{"key":"ref21","volume-title":"Bash.git\u2014Bash","year":"2014"},{"key":"ref22","volume-title":"Bash-4.3-Patched","year":"2014"},{"key":"ref23","volume-title":"Vulhub\u2014Docker-Compose File for Vulnerability Environment","year":"2021"},{"key":"ref24","volume-title":"DARPA. Transparent Computing, Defense Advanced Research Projects Agency","year":"2014"},{"key":"ref25","volume-title":"Transparent Computing Engagement 5 Data Release","year":"2020"},{"key":"ref26","volume-title":"StreamSpot: Detecting Network Anomalies in Edge Streams","year":"2016"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICAISC56366.2023.10085474"},{"key":"ref28","first-page":"319","article-title":"Trustworthy whole-system provenance for the Linux kernel","volume-title":"Proc. USENIX Secur. Symp.","author":"Bates"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/11890850_18"},{"key":"ref30","first-page":"3989","article-title":"CLARION: Sound and clear provenance tracking for microservice deployments","volume-title":"Proc. USENIX Secur. Symp.","author":"Chen"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35170-9_6"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24270"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00064"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/2151024.2151042"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23306"},{"key":"ref37","first-page":"1","article-title":"High accuracy attack provenance via binary-based execution partition","volume-title":"Proc. Annu. Netw. Distrib. Syst. Secur. Symp. (NDSS)","author":"Lee"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516731"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818039"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"key":"ref41","first-page":"1111","article-title":"MPI: Multiple perspective attack investigation with semantic aware execution partitioning","volume-title":"Proc. USENIX Secur. Symp.","author":"Ma"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.08.007"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315260"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2019.00056"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2907"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3338503.3357725"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274751"},{"key":"ref48","first-page":"1","article-title":"Compressing provenance graphs","volume-title":"Proc. USENIX Workshop Theory Pract. Provenance (TaPP)","author":"Xie"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484551"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24329"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24445"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2019.00055"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560570"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534380"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2946563"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24046"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420989"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3093336.3037716"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243797"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30215-3_17"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10319981\/10695108.pdf?arnumber=10695108","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T04:55:40Z","timestamp":1729054540000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10695108\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3459616","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}