{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:18:54Z","timestamp":1785543534475,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":78,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["CNS-1918542"],"award-info":[{"award-number":["CNS-1918542"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["DGE-1069311"],"award-info":[{"award-number":["DGE-1069311"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["CNS-1514472"],"award-info":[{"award-number":["CNS-1514472"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"AFOSR","award":["FA8650-15-C-7561"],"award-info":[{"award-number":["FA8650-15-C-7561"]}]},{"name":"SPAWAR","award":["N6600118C4035"],"award-info":[{"award-number":["N6600118C4035"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3363217","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"1795-1812","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":264,"title":["POIROT"],"prefix":"10.1145","author":[{"given":"Sadegh M.","family":"Milajerdi","sequence":"first","affiliation":[{"name":"University of Illinois at Chicago, Chicago, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Birhanu","family":"Eshete","sequence":"additional","affiliation":[{"name":"University of Michigan-Dearborn, Dearborn, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rigel","family":"Gjomemo","sequence":"additional","affiliation":[{"name":"University of Illinois at Chicago, Chicago, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"V.N.","family":"Venkatakrishnan","sequence":"additional","affiliation":[{"name":"University of Illinois at Chicago, Chicago, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"USENIX security symposium","author":"Antonakakis Manos"},{"key":"e_1_3_2_1_2_1","volume-title":"USENIX security symposium","author":"Antonakakis Manos"},{"key":"e_1_3_2_1_3_1","unstructured":"Apache. 2019. ab - Apache HTTP server benchmarking tool. https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html. Accessed: 2019-08--27.  Apache. 2019. ab - Apache HTTP server benchmarking tool. https:\/\/httpd.apache.org\/docs\/2.4\/programs\/ab.html. Accessed: 2019-08--27."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420969"},{"key":"e_1_3_2_1_5_1","unstructured":"G Data Blog. 2013. The Uroburos case: new sophisticated RAT identified. https:\/\/www.gdatasoftware.com\/blog\/2014\/11\/23937-the-uroburos-case-new-sophisticated-rat-identified. Accessed: 2019-04--19.  G Data Blog. 2013. The Uroburos case: new sophisticated RAT identified. https:\/\/www.gdatasoftware.com\/blog\/2014\/11\/23937-the-uroburos-case-new-sophisticated-rat-identified. Accessed: 2019-04--19."},{"key":"e_1_3_2_1_6_1","unstructured":"WeLiveSecurity by ESET. 2018. OceanLotus: Old techniques new backdoor. https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2018\/03\/ESET_OceanLotus.pdf. Accessed: 2019-08--12.  WeLiveSecurity by ESET. 2018. OceanLotus: Old techniques new backdoor. https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2018\/03\/ESET_OceanLotus.pdf. Accessed: 2019-08--12."},{"key":"e_1_3_2_1_7_1","unstructured":"Threat Analysis by FortiGuard Labs. 2019. Analysis of a New HawkEye Variant. https:\/\/www.fortinet.com\/blog\/threat-research\/hawkeye-malware-analysis.html. Accessed: 2019-08--12.  Threat Analysis by FortiGuard Labs. 2019. Analysis of a New HawkEye Variant. https:\/\/www.fortinet.com\/blog\/threat-research\/hawkeye-malware-analysis.html. Accessed: 2019-08--12."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2008.4497500"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1287624.1287628"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2008.205"},{"key":"e_1_3_2_1_11_1","unstructured":"EFD. 2019. HD Tune. https:\/\/www.hdtune.com. Accessed: 2019-08--27.  EFD. 2019. HD Tune. https:\/\/www.hdtune.com. Accessed: 2019-08--27."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.14778\/1920841.1920878"},{"key":"e_1_3_2_1_13_1","unstructured":"FireEye. 2013. OpenIOC Series: Investigating with Indicators of Compromise (IOCs) - Part I. https:\/\/www.fireeye.com\/blog\/threat-research\/2013\/12\/openioc-series-investigating-indicators-compromise-iocs.html.  FireEye. 2013. OpenIOC Series: Investigating with Indicators of Compromise (IOCs) - Part I. https:\/\/www.fireeye.com\/blog\/threat-research\/2013\/12\/openioc-series-investigating-indicators-compromise-iocs.html."},{"key":"e_1_3_2_1_14_1","unstructured":"FireEye. 2018a. Open IOC. https:\/\/openioc.org.  FireEye. 2018a. Open IOC. https:\/\/openioc.org."},{"key":"e_1_3_2_1_15_1","unstructured":"FireEye. 2018b. Redline. https:\/\/www.fireeye.com\/services\/freeware\/redline.html. Accessed: 2019-04--23.  FireEye. 2018b. Redline. https:\/\/www.fireeye.com\/services\/freeware\/redline.html. Accessed: 2019-04--23."},{"key":"e_1_3_2_1_16_1","first-page":"45","article-title":"Matching structure and semantics: A survey on graph-based pattern matching","volume":"6","author":"Gallagher Brian","year":"2006","journal-title":"AAAI FS"},{"key":"e_1_3_2_1_17_1","volume-title":"SAQL: A Stream-based Query System for Real-Time Abnormal System Behavior Detection. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Gao Peng","year":"2018"},{"key":"e_1_3_2_1_18_1","volume-title":"2018 USENIX Annual Technical Conference (USENIX ATC 18)","author":"Gao Peng","year":"2018"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2002.1048250"},{"key":"e_1_3_2_1_20_1","volume-title":"25th IEEE International Conference on Distributed Computing Systems Workshops.","author":"Goel A."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Ashvin Goel Kenneth Po Kamran Farhadi Zheng Li and Eyal de Lara. 2005 b. The Taser Intrusion Recovery System. SIGOPS Oper. Syst. Rev. (2005).  Ashvin Goel Kenneth Po Kamran Farhadi Zheng Li and Eyal de Lara. 2005 b. The Taser Intrusion Recovery System. SIGOPS Oper. Syst. Rev. (2005).","DOI":"10.1145\/1095810.1095826"},{"key":"e_1_3_2_1_22_1","volume-title":"Global Research & Analysis Team (GReAT)","author":"Lab Kaspersky","year":"2015"},{"key":"e_1_3_2_1_23_1","unstructured":"hasherezade. 2018. PE-Sieve: Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced\/injected PEs shellcodes hooks in-memory patches). https:\/\/github.com\/hasherezade\/pe-sieve.  hasherezade. 2018. PE-Sieve: Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced\/injected PEs shellcodes hooks in-memory patches). https:\/\/github.com\/hasherezade\/pe-sieve."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Wajih Ul Hassan Shengjian Guo Ding Li Zhengzhang Chen Kangkook Jee Zhichun Li and Adam Bates. 2019. NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage.. In NDSS.  Wajih Ul Hassan Shengjian Guo Ding Li Zhengzhang Chen Kangkook Jee Zhichun Li and Adam Bates. 2019. NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage.. In NDSS.","DOI":"10.14722\/ndss.2019.23349"},{"key":"e_1_3_2_1_25_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Hossain Md Nahid"},{"key":"e_1_3_2_1_26_1","volume-title":"Dependence Preserving Data Compaction for Scalable Forensic Analysis. In USENIX Security Symposium. USENIX Association.","author":"Hossain Md Nahid","year":"2018"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134646"},{"key":"e_1_3_2_1_28_1","volume-title":"Andras Iklody","author":"MISP","year":"2019"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134045"},{"key":"e_1_3_2_1_30_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Ji Yang","year":"2018"},{"key":"e_1_3_2_1_31_1","unstructured":"Angelos D. Keromytis. 2018. Transparent Computing Engagement 3 Data Release. https:\/\/github.com\/darpa-i2o\/Transparent-Computing.  Angelos D. Keromytis. 2018. Transparent Computing Engagement 3 Data Release. https:\/\/github.com\/darpa-i2o\/Transparent-Computing."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.14778\/2535569.2448952"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Samuel T King and Peter M Chen. 2003. Backtracking intrusions. In SOSP. ACM.  Samuel T King and Peter M Chen. 2003. Backtracking intrusions. In SOSP. ACM.","DOI":"10.1145\/945445.945467"},{"key":"e_1_3_2_1_34_1","volume-title":"Chen","author":"King Samuel T.","year":"2005"},{"key":"e_1_3_2_1_35_1","volume-title":"Dominic G Lucchetti, and Peter M Chen.","author":"King Samuel T","year":"2005"},{"key":"e_1_3_2_1_36_1","volume-title":"Christopher Kruegel, Engin Kirda, Xiao-yong Zhou, and XiaoFeng Wang.","author":"Kolbitsch Clemens","year":"2009"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2954680.2872395"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23306"},{"key":"e_1_3_2_1_39_1","unstructured":"Kyu Hyung Lee Xiangyu Zhang and Dongyan Xu. 2013a. High Accuracy Attack Provenance via Binary-based Execution Partition.. In NDSS.  Kyu Hyung Lee Xiangyu Zhang and Dongyan Xu. 2013a. High Accuracy Attack Provenance via Binary-based Execution Partition.. In NDSS."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516731"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978315"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23254"},{"key":"e_1_3_2_1_43_1","volume-title":"International Conference on Information Systems Security. Springer.","author":"Milajerdi Sadegh M."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818039"},{"key":"e_1_3_2_1_45_1","volume-title":"MPI: Multiple Perspective Attack Investigation with Semantics Aware Execution Partitioning. In 26th USENIX Security Symposium (USENIX Security 17)","author":"Ma Shiqing","year":"2017"},{"key":"e_1_3_2_1_46_1","unstructured":"Shiqing Ma Xiangyu Zhang and Dongyan Xu. 2016. ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and Tainting. In NDSS.  Shiqing Ma Xiangyu Zhang and Dongyan Xu. 2016. ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and Tainting. In NDSS."},{"key":"e_1_3_2_1_47_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy. IEEE.","author":"Milajerdi Sadegh M."},{"key":"e_1_3_2_1_48_1","unstructured":"MISP. 2019. MISP - Open Source Threat Intelligence Platform & Open Standards For Threat Information Sharing. https:\/\/www.misp-project.org\/. Accessed: 2019-04--23.  MISP. 2019. MISP - Open Source Threat Intelligence Platform & Open Standards For Threat Information Sharing. https:\/\/www.misp-project.org\/. Accessed: 2019-04--23."},{"key":"e_1_3_2_1_49_1","unstructured":"Mitre. 2018. Structured Threat Information eXpression (STIX). https:\/\/stixproject.github.io.  Mitre. 2018. Structured Threat Information eXpression (STIX). https:\/\/stixproject.github.io."},{"key":"e_1_3_2_1_50_1","volume-title":"Ned Moran and Nart Villeneuve","year":"2013"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2015.14"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Chetan Parampalli R Sekar and Rob Johnson. 2008. A practical mimicry attack against powerful system-call monitors. In Information computer and communications security. ACM.  Chetan Parampalli R Sekar and Rob Johnson. 2008. A practical mimicry attack against powerful system-call monitors. In Information computer and communications security. ACM.","DOI":"10.1145\/1368310.1368334"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243776"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991122"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2014.7004278"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Devin J Pohly Stephen McLaughlin Patrick McDaniel and Kevin Butler. 2012. Hi-Fi: collecting high-fidelity whole-system provenance. In ACSAC. ACM.  Devin J Pohly Stephen McLaughlin Patrick McDaniel and Kevin Butler. 2012. Hi-Fi: collecting high-fidelity whole-system provenance. In ACSAC. ACM.","DOI":"10.1145\/2420950.2420989"},{"key":"e_1_3_2_1_57_1","volume-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS '18)","author":"Shu Xiaokui","year":"1883"},{"key":"e_1_3_2_1_58_1","unstructured":"General Dynamics Fidelis Cybersecurity Solutions. 2013. njRAT Uncovered. https:\/\/app.box.com\/s\/vdg51zbfvap52w60zj0is3l1dmyya0n4. Accessed: 2019-04--19.  General Dynamics Fidelis Cybersecurity Solutions. 2013. njRAT Uncovered. https:\/\/app.box.com\/s\/vdg51zbfvap52w60zj0is3l1dmyya0n4. Accessed: 2019-04--19."},{"key":"e_1_3_2_1_59_1","unstructured":"Splunk. 2019. SIEM AIOps Application Management Log Management Machine Learning and Compliance. https:\/\/www.splunk.com\/.  Splunk. 2019. SIEM AIOps Application Management Log Management Machine Learning and Compliance. https:\/\/www.splunk.com\/."},{"key":"e_1_3_2_1_60_1","unstructured":"STIX. 2019. STIX Visualization. https:\/\/oasis-open.github.io\/cti-documentation\/stix\/gettingstarted.html#stix-visualization. Accessed: 2019-05--15.  STIX. 2019. STIX Visualization. https:\/\/oasis-open.github.io\/cti-documentation\/stix\/gettingstarted.html#stix-visualization. Accessed: 2019-05--15."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2821095"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.14778\/2311906.2311907"},{"key":"e_1_3_2_1_63_1","volume-title":"Buckeye: Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak. https:\/\/www.symantec.com\/blogs\/threat-intelligence\/buckeye-windows-zero-day-exploit.","year":"2019"},{"key":"e_1_3_2_1_64_1","unstructured":"Nextron Systems. 2017. LOKI free IOC scanner - Nextron Systems. https:\/\/www.nextron-systems.com\/loki\/.  Nextron Systems. 2017. LOKI free IOC scanner - Nextron Systems. https:\/\/www.nextron-systems.com\/loki\/."},{"key":"e_1_3_2_1_65_1","unstructured":"ClearSky Cyber Security Team. 2016. Operation DustySky. https:\/\/www.clearskysec.com\/wp-content\/uploads\/2016\/01\/Operation%20DustySky_TLP_WHITE.pdf. Accessed: 2019-04--19.  ClearSky Cyber Security Team. 2016. Operation DustySky. https:\/\/www.clearskysec.com\/wp-content\/uploads\/2016\/01\/Operation%20DustySky_TLP_WHITE.pdf. Accessed: 2019-04--19."},{"key":"e_1_3_2_1_66_1","volume-title":"STIX team","author":"MITRE","year":"2013"},{"key":"e_1_3_2_1_67_1","volume-title":"STIX team","author":"MITRE","year":"2013"},{"key":"e_1_3_2_1_68_1","unstructured":"New York Times. 2019. How Chinese Spies Got the N.S.A.'s Hacking Tools and Used Them for Attacks. https:\/\/www.nytimes.com\/2019\/05\/06\/us\/politics\/china-hacking-cyber.html.  New York Times. 2019. How Chinese Spies Got the N.S.A.'s Hacking Tools and Used Them for Attacks. https:\/\/www.nytimes.com\/2019\/05\/06\/us\/politics\/china-hacking-cyber.html."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/1281192.1281271"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586145"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2012.28"},{"key":"e_1_3_2_1_72_1","unstructured":"David Westcott and Kiran Bandla. 2018. APT Notes. https:\/\/github.com\/aptnotes\/data.  David Westcott and Kiran Bandla. 2018. APT Notes. https:\/\/github.com\/aptnotes\/data."},{"key":"e_1_3_2_1_73_1","unstructured":"Workbench. 2019. Jetstream2. https:\/\/browserbench.org\/JetStream\/index.html. Accessed: 2019-08--27.  Workbench. 2019. Jetstream2. https:\/\/browserbench.org\/JetStream\/index.html. Accessed: 2019-08--27."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978378"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00039"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2014.6816704"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.14778\/2856318.2856320"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.14778\/1687627.1687727"}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3363217","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3363217","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3363217","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:33Z","timestamp":1750203873000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3363217"}},"subtitle":["Aligning Attack Behavior with Kernel Audit Records for Cyber Threat Hunting"],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":78,"alternative-id":["10.1145\/3319535.3363217","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3363217","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}