{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T14:50:42Z","timestamp":1784904642435,"version":"3.55.0"},"reference-count":30,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2005,2,2]],"date-time":"2005-02-02T00:00:00Z","timestamp":1107302400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Comput. Syst."],"published-print":{"date-parts":[[2005,2,2]]},"abstract":"<jats:p>Analyzing intrusions today is an arduous, largely manual task because system administrators lack the information and tools needed to understand easily the sequence of steps that occurred in an attack. The goal of BackTracker is to identify automatically potential sequences of steps that occurred in an intrusion. Starting with a single detection point (e.g., a suspicious file), BackTracker identifies files and processes that could have affected that detection point and displays chains of events in a dependency graph. We use BackTracker to analyze several real attacks against computers that we set up as honeypots. In each case, BackTracker is able to highlight effectively the entry point used to gain access to the system and the sequence of steps from that entry point to the point at which we noticed the intrusion. The logging required to support BackTracker added 9% overhead in running time and generated 1.2 GB per day of log data for an operating-system intensive workload.<\/jats:p>","DOI":"10.1145\/1047915.1047918","type":"journal-article","created":{"date-parts":[[2005,8,3]],"date-time":"2005-08-03T08:30:55Z","timestamp":1123057855000},"page":"51-76","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":75,"title":["Backtracking intrusions"],"prefix":"10.1145","volume":"23","author":[{"given":"Samuel T.","family":"King","sequence":"first","affiliation":[{"name":"University of Michigan, Ann Arbor, MI"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peter M.","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Michigan, Ann Arbor, MI"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2005,2,2]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2002.1033782"},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the 2002 IEEE Symposium on Security and Privacy. 131--147","author":"Ashcraft K."},{"key":"e_1_2_1_3_1","volume-title":"Proceedings of the 2001 IEEE Symposium on High Assurance System Engineering (HASE). 95--105","author":"Buchacker K."},{"key":"e_1_2_1_4_1","volume-title":"Steps for recovering from a UNIX or NT system compromise. Tech. rep"},{"key":"e_1_2_1_5_1","volume-title":"Detecting signs of intrusion. Tech. rep. CMU\/SEI-SIM-009"},{"key":"e_1_2_1_6_1","unstructured":"CERT. 2002a. CERT\/CC overview incident and vulnerability trends. Tech. rep. CERT Coordination Center. Available online at http:\/\/www.cert.org\/present\/cert-overview-trends\/.  CERT. 2002a. CERT\/CC overview incident and vulnerability trends. Tech. rep. CERT Coordination Center. Available online at http:\/\/www.cert.org\/present\/cert-overview-trends\/."},{"key":"e_1_2_1_7_1","volume-title":"Multiple vulnerabilities In OpenSSL. Tech. rep. CERT Advisory CA-2002-23"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the","author":"Cheswick B.","year":"1992"},{"key":"e_1_2_1_9_1","volume-title":"The Incident Detection, Analysis, and Response (IDAR) Project. Tech. rep","author":"Christie A. M."},{"key":"e_1_2_1_10_1","unstructured":"CIAC. 2001. L-133: Sendmail debugger arbitrary code execution vulnerability. Tech. rep. Computer Incident Advisory Capability. Available online at http:\/\/www.ciac.org\/ciac\/bulletins\/l-133.shtml.  CIAC. 2001. L-133: Sendmail debugger arbitrary code execution vulnerability. Tech. rep. Computer Incident Advisory Capability. Available online at http:\/\/www.ciac.org\/ciac\/bulletins\/l-133.shtml."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/360051.360056"},{"key":"e_1_2_1_12_1","volume-title":"Proceedings of the 2002 Symposium on Operating Systems Design and Implementation. 211--224","author":"Dunlap G. W."},{"key":"e_1_2_1_13_1","first-page":"10","article-title":"What are MACtimes","volume":"25","author":"Farmer D.","year":"2000","journal-title":"Dr. Dobb's J."},{"key":"e_1_2_1_14_1","first-page":"1","article-title":"Bring out your dead","volume":"26","author":"Farmer D.","year":"2001","journal-title":"Dr. Dobb's J."},{"key":"e_1_2_1_15_1","first-page":"9","article-title":"Forensic computer analysis: an introduction","volume":"25","author":"Farmer D.","year":"2000","journal-title":"Dr. Dobb's J."},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of 1996 IEEE Symposium on Computer Security and Privacy. 120--128","author":"Forrest S."},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 2003 Network and Distributed System Security Symposium (NDSS).","author":"Garfinkel T."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCSW.2005.62"},{"key":"e_1_2_1_19_1","volume-title":"Proceedings of the 1996 USENIX Security Symposium. 1--13","author":"Goldberg I."},{"key":"e_1_2_1_20_1","unstructured":"Huagang X. 2000. Build a secure system with LIDS. Available online at http:\/\/www.lids.org\/document\/build_lids-0.2.html.  Huagang X. 2000. Build a secure system with LIDS. Available online at http:\/\/www.lids.org\/document\/build_lids-0.2.html."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of 1994 ACM Conference on Computer and Communications Security (CCS). 18--29","author":"Kim G. H.","year":"1911"},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 2003 USENIX Technical Conference. 71--84","author":"King S. T."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the 2002 USENIX Security Symposium.","author":"Kiriansky V."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/359545.359563"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/362375.362389"},{"key":"e_1_2_1_26_1","volume-title":"Know Your Enemy: Revealing the Security Tools, Tactics, and Motives of the Blackhat Community","author":"The Honeynet Project"},{"key":"e_1_2_1_27_1","first-page":"3","article-title":"A survey of program slicing techniques","volume":"3","author":"Tip F.","year":"1995","journal-title":"J. Programm. Lang."},{"key":"e_1_2_1_28_1","volume-title":"DERBI: Diagnosis, explanation and recovery from computer break-ins. Tech. rep. DARPA Project F30602-96-C-0295 Final Report. SRI International","author":"Tyson W. M.","year":"2001"},{"key":"e_1_2_1_29_1","unstructured":"Wall L. Christiansen T. and Orwant J. 2000. Programming Perl 3rd ed. O'Reilly & Associates Sebastopol; CA.   Wall L. Christiansen T. and Orwant J. 2000. Programming Perl 3rd ed. O'Reilly & Associates Sebastopol; CA."},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the 2003 International Conference on Dependable Systems and Networks (DSN). 217--226","author":"Zhu N."}],"container-title":["ACM Transactions on Computer Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1047915.1047918","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1047915.1047918","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:07:58Z","timestamp":1750262878000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1047915.1047918"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,2,2]]},"references-count":30,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2005,2,2]]}},"alternative-id":["10.1145\/1047915.1047918"],"URL":"https:\/\/doi.org\/10.1145\/1047915.1047918","relation":{},"ISSN":["0734-2071","1557-7333"],"issn-type":[{"value":"0734-2071","type":"print"},{"value":"1557-7333","type":"electronic"}],"subject":[],"published":{"date-parts":[[2005,2,2]]},"assertion":[{"value":"2005-02-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}