{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:18:29Z","timestamp":1783437509188,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T00:00:00Z","timestamp":1670198400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,12,5]]},"DOI":"10.1145\/3564625.3567990","type":"proceedings-article","created":{"date-parts":[[2022,12,3]],"date-time":"2022-12-03T01:01:29Z","timestamp":1670029289000},"page":"813-826","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":10,"title":["FAuST: Striking a Bargain between Forensic Auditing\u2019s Security and Throughput"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8347-1742","authenticated-orcid":false,"given":"Muhammad Adil","family":"Inam","sequence":"first","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2484-6185","authenticated-orcid":false,"given":"Akul","family":"Goyal","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8173-6914","authenticated-orcid":false,"given":"Jason","family":"Liu","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9390-3900","authenticated-orcid":false,"given":"Jaron","family":"Mink","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0320-7990","authenticated-orcid":false,"given":"Noor","family":"Michael","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8613-8286","authenticated-orcid":false,"given":"Sneha","family":"Gaur","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1511-4951","authenticated-orcid":false,"given":"Adam","family":"Bates","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5676-6027","authenticated-orcid":false,"given":"Wajih Ul","family":"Hassan","sequence":"additional","affiliation":[{"name":"University of Virginia, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,5]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"DARPA Transparent Computing","year":"2020","unstructured":"2020. DARPA Transparent Computing . 2020 . Transparent Computing Engagement 3 Data Release . (2020). 2020. DARPA Transparent Computing. 2020. Transparent Computing Engagement 3 Data Release. (2020)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831164"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3062180"},{"key":"e_1_3_2_1_4_1","unstructured":"Tara\u00a0Siegel Bernard Tiffany Hsu Nicole Perlroth and Ron Lieber. 2019. Equifax Says Cyberattack May Have Affected 143 Million in the U.S.https:\/\/www.nytimes.com\/2017\/09\/07\/business\/equifax-cyberattack.html.  Tara\u00a0Siegel Bernard Tiffany Hsu Nicole Perlroth and Ron Lieber. 2019. Equifax Says Cyberattack May Have Affected 143 Million in the U.S.https:\/\/www.nytimes.com\/2017\/09\/07\/business\/equifax-cyberattack.html."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1142473.1142574"},{"key":"e_1_3_2_1_6_1","unstructured":"Carbon Black. 2018. Global Incident Response Threat Report. https:\/\/www.carbonblack.com\/global-incident-response-threat-report\/november-2018\/. Last accessed 04-20-2019.  Carbon Black. 2018. Global Incident Response Threat Report. https:\/\/www.carbonblack.com\/global-incident-response-threat-report\/november-2018\/. Last accessed 04-20-2019."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2834050.2834111"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.5281\/zenodo.5760077"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134015"},{"key":"e_1_3_2_1_10_1","unstructured":"FireEye Inc.2019. How Many Alerts is Too Many to Handle?https:\/\/www2.fireeye.com\/StopTheNoise-IDC-Numbers-Game-Special-Report.html.  FireEye Inc.2019. How Many Alerts is Too Many to Handle?https:\/\/www2.fireeye.com\/StopTheNoise-IDC-Numbers-Game-Special-Report.html."},{"key":"e_1_3_2_1_11_1","unstructured":"Gartner Peer Insights. 2019. Endpoint Detection and Response Solutions Market. https:\/\/www.gartner.com\/reviews\/market\/endpoint-detection-and-response-solutions.  Gartner Peer Insights. 2019. Endpoint Detection and Response Solutions Market. https:\/\/www.gartner.com\/reviews\/market\/endpoint-detection-and-response-solutions."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35170-9_6"},{"key":"e_1_3_2_1_13_1","volume-title":"Unicorn: Runtime provenance-based detector for advanced persistent threats. In NDSS.","author":"Han Xueyuan","year":"2020","unstructured":"Xueyuan Han , Thomas Pasquier , Adam Bates , James Mickens , and Margo Seltzer . 2020 . Unicorn: Runtime provenance-based detector for advanced persistent threats. In NDSS. Xueyuan Han, Thomas Pasquier, Adam Bates, James Mickens, and Margo Seltzer. 2020. Unicorn: Runtime provenance-based detector for advanced persistent threats. In NDSS."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Wajih\u00a0Ul Hassan Lemay Aguse Nuraini Aguse Adam Bates and Thomas Moyer. 2018. Towards scalable cluster auditing through grammatical inference over provenance graphs. In NDSS.  Wajih\u00a0Ul Hassan Lemay Aguse Nuraini Aguse Adam Bates and Thomas Moyer. 2018. Towards scalable cluster auditing through grammatical inference over provenance graphs. In NDSS.","DOI":"10.14722\/ndss.2018.23141"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23141"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00096"},{"key":"e_1_3_2_1_17_1","volume-title":"Nodoze: Combatting threat alert fatigue with automated provenance triage. In NDSS.","author":"Hassan Wajih\u00a0Ul","year":"2019","unstructured":"Wajih\u00a0Ul Hassan , Shengjian Guo , Ding Li , Zhengzhang Chen , Kangkook Jee , Zhichun Li , and Adam Bates . 2019 . Nodoze: Combatting threat alert fatigue with automated provenance triage. In NDSS. Wajih\u00a0Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen, Kangkook Jee, Zhichun Li, and Adam Bates. 2019. Nodoze: Combatting threat alert fatigue with automated provenance triage. In NDSS."},{"key":"e_1_3_2_1_18_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Hossain Md\u00a0Nahid","unstructured":"Md\u00a0Nahid Hossain , Sadegh\u00a0 M. Milajerdi , Junao Wang , Birhanu Eshete , Rigel Gjomemo , R. Sekar , Scott Stoller , and V.N. Venkatakrishnan . 2017. SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data . In 26th USENIX Security Symposium (USENIX Security 17) . USENIX Association, Vancouver, BC, 487\u2013504. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/hossain Md\u00a0Nahid Hossain, Sadegh\u00a0M. Milajerdi, Junao Wang, Birhanu Eshete, Rigel Gjomemo, R. Sekar, Scott Stoller, and V.N. Venkatakrishnan. 2017. SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 487\u2013504. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/hossain"},{"key":"e_1_3_2_1_19_1","volume-title":"USENIX Security Symposium.","author":"Hossain Md\u00a0Nahid","year":"2017","unstructured":"Md\u00a0Nahid Hossain , Sadegh\u00a0 M Milajerdi , Junao Wang , Birhanu Eshete , Rigel Gjomemo , R Sekar , Scott Stoller , and VN Venkatakrishnan . 2017 . {SLEUTH}: Real-time attack scenario reconstruction from {COTS} audit data . In USENIX Security Symposium. Md\u00a0Nahid Hossain, Sadegh\u00a0M Milajerdi, Junao Wang, Birhanu Eshete, Rigel Gjomemo, R Sekar, Scott Stoller, and VN Venkatakrishnan. 2017. {SLEUTH}: Real-time attack scenario reconstruction from {COTS} audit data. In USENIX Security Symposium."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00064"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277331"},{"key":"e_1_3_2_1_22_1","volume-title":"USENIX Security Symposium.","author":"Hossain Md\u00a0Nahid","year":"2018","unstructured":"Md\u00a0Nahid Hossain , Junao Wang , Ofir Weisse , R Sekar , Daniel Genkin , Boyuan He , Scott\u00a0 D Stoller , Gan Fang , Frank Piessens , Evan Downing , 2018 . Dependence-preserving data compaction for scalable forensic analysis . In USENIX Security Symposium. Md\u00a0Nahid Hossain, Junao Wang, Ofir Weisse, R Sekar, Daniel Genkin, Boyuan He, Scott\u00a0D Stoller, Gan Fang, Frank Piessens, Evan Downing, 2018. Dependence-preserving data compaction for scalable forensic analysis. In USENIX Security Symposium."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134045"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053034"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"e_1_3_2_1_26_1","unstructured":"Brendan\u00a0I. Koerner. 2016. Inside the Cyberattack That Shocked the US Government. https:\/\/www.wired.com\/2016\/10\/inside-cyberattack-shocked-us-government\/.  Brendan\u00a0I. Koerner. 2016. Inside the Cyberattack That Shocked the US Government. https:\/\/www.wired.com\/2016\/10\/inside-cyberattack-shocked-us-government\/."},{"key":"e_1_3_2_1_27_1","unstructured":"George Kurtz. 2010. Operation Aurora Hit Google Others. Available at http:\/\/securityinnovator.com\/index.php?articleID=42948&sectionID=25.  George Kurtz. 2010. Operation Aurora Hit Google Others. Available at http:\/\/securityinnovator.com\/index.php?articleID=42948&sectionID=25."},{"key":"e_1_3_2_1_28_1","volume-title":"MCI: Modeling-based Causality Inference in Audit Logging for Attack Investigation.. In NDSS.","author":"Kwon Yonghwi","year":"2018","unstructured":"Yonghwi Kwon , Fei Wang , Weihang Wang , Kyu\u00a0Hyung Lee , Wen-Chuan Lee , Shiqing Ma , Xiangyu Zhang , Dongyan Xu , Somesh Jha , Gabriela\u00a0 F Ciocarlie , 2018 . MCI: Modeling-based Causality Inference in Audit Logging for Attack Investigation.. In NDSS. Yonghwi Kwon, Fei Wang, Weihang Wang, Kyu\u00a0Hyung Lee, Wen-Chuan Lee, Shiqing Ma, Xiangyu Zhang, Dongyan Xu, Somesh Jha, Gabriela\u00a0F Ciocarlie, 2018. MCI: Modeling-based Causality Inference in Audit Logging for Attack Investigation.. In NDSS."},{"key":"e_1_3_2_1_29_1","unstructured":"Kyu\u00a0Hyung Lee Xiangyu Zhang and Dongyan Xu. 2013. High Accuracy Attack Provenance via Binary-based Execution Partition.. In NDSS.  Kyu\u00a0Hyung Lee Xiangyu Zhang and Dongyan Xu. 2013. High Accuracy Attack Provenance via Binary-based Execution Partition.. In NDSS."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516731"},{"key":"e_1_3_2_1_31_1","unstructured":"Kyu\u00a0Hyung Lee Xiangyu Zhang and Dongyan Xu. 2013. LogGC: garbage collecting audit log. In CCS.  Kyu\u00a0Hyung Lee Xiangyu Zhang and Dongyan Xu. 2013. LogGC: garbage collecting audit log. In CCS."},{"key":"e_1_3_2_1_32_1","unstructured":"Jure Leskovec. 2009. Stanford network analysis package. Online http:\/\/snap. stanford. edu(2009).  Jure Leskovec. 2009. Stanford network analysis package. Online http:\/\/snap. stanford. edu(2009)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Yushan Liu Mu Zhang Ding Li Kangkook Jee Zhichun Li Zhenyu Wu Junghwan Rhee and Prateek Mittal. 2018. Towards a Timely Causality Analysis for Enterprise Security.. In NDSS.  Yushan Liu Mu Zhang Ding Li Kangkook Jee Zhichun Li Zhenyu Wu Junghwan Rhee and Prateek Mittal. 2018. Towards a Timely Causality Analysis for Enterprise Security.. In NDSS.","DOI":"10.14722\/ndss.2018.23254"},{"key":"e_1_3_2_1_34_1","volume-title":"Kernel-Supported Cost-Effective Audit Logging for Causality Tracking. In 2018 USENIX Annual Technical Conference (USENIX ATC 18)","author":"Ma Shiqing","year":"2018","unstructured":"Shiqing Ma , Juan Zhai , Yonghwi Kwon , Kyu\u00a0Hyung Lee , Xiangyu Zhang , Gabriela Ciocarlie , Ashish Gehani , Vinod Yegneswaran , Dongyan Xu , and Somesh Jha . 2018 . Kernel-Supported Cost-Effective Audit Logging for Causality Tracking. In 2018 USENIX Annual Technical Conference (USENIX ATC 18) . USENIX Association, Boston, MA, 241\u2013254. https:\/\/www.usenix.org\/conference\/atc18\/presentation\/ma-shiqing Shiqing Ma, Juan Zhai, Yonghwi Kwon, Kyu\u00a0Hyung Lee, Xiangyu Zhang, Gabriela Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Dongyan Xu, and Somesh Jha. 2018. Kernel-Supported Cost-Effective Audit Logging for Causality Tracking. In 2018 USENIX Annual Technical Conference (USENIX ATC 18). USENIX Association, Boston, MA, 241\u2013254. https:\/\/www.usenix.org\/conference\/atc18\/presentation\/ma-shiqing"},{"key":"e_1_3_2_1_35_1","volume-title":"USENIX Security Symposium.","author":"Ma Shiqing","year":"2017","unstructured":"Shiqing Ma , Juan Zhai , Fei Wang , Kyu\u00a0Hyung Lee , Xiangyu Zhang , and Dongyan Xu . 2017 . {MPI}: Multiple perspective attack investigation with semantic aware execution partitioning . In USENIX Security Symposium. Shiqing Ma, Juan Zhai, Fei Wang, Kyu\u00a0Hyung Lee, Xiangyu Zhang, and Dongyan Xu. 2017. {MPI}: Multiple perspective attack investigation with semantic aware execution partitioning. In USENIX Security Symposium."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23350"},{"key":"e_1_3_2_1_37_1","unstructured":"Shiqing Ma Xiangyu Zhang and Dongyan Xu. 2016. ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and Tainting. In NDSS.  Shiqing Ma Xiangyu Zhang and Dongyan Xu. 2016. ProTracer: Towards Practical Provenance Tracing by Alternating Between Logging and Tainting. In NDSS."},{"key":"e_1_3_2_1_38_1","unstructured":"Keith McCammon. 2018. Evaluating Endpoint Products. https:\/\/redcanary.com\/blog\/evaluating-endpoint-products-in-a-crowded-confusing-market\/.  Keith McCammon. 2018. Evaluating Endpoint Products. https:\/\/redcanary.com\/blog\/evaluating-endpoint-products-in-a-crowded-confusing-market\/."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427272"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Noor Michael Jaron Mink Jason Liu Sneha Gaur Wajih\u00a0Ul Hassan and Adam Bates. 2020. On the Forensic Validity of Approximated Audit Logs. In ACSAC.  Noor Michael Jaron Mink Jason Liu Sneha Gaur Wajih\u00a0Ul Hassan and Adam Bates. 2020. On the Forensic Validity of Approximated Audit Logs. In ACSAC.","DOI":"10.1145\/3427228.3427272"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363217"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05171-6_6"},{"key":"e_1_3_2_1_43_1","unstructured":"MITRE Corporation. 2019. APT29. https:\/\/attack.mitre.org\/groups\/G0016\/.  MITRE Corporation. 2019. APT29. https:\/\/attack.mitre.org\/groups\/G0016\/."},{"key":"e_1_3_2_1_44_1","unstructured":"MITRE Corporation. 2019. APT3. https:\/\/attack.mitre.org\/groups\/G0022\/.  MITRE Corporation. 2019. APT3. https:\/\/attack.mitre.org\/groups\/G0022\/."},{"key":"e_1_3_2_1_45_1","unstructured":"MITRE Corporation. 2019. MITRE ATT&CK. https:\/\/attack.mitre.org.  MITRE Corporation. 2019. MITRE ATT&CK. https:\/\/attack.mitre.org."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.5555\/1267359.1267363"},{"key":"e_1_3_2_1_47_1","volume-title":"Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution. In 27th ISOC Network and Distributed System Security Symposium(NDSS\u201920)","author":"Paccagnella Riccardo","year":"2020","unstructured":"Riccardo Paccagnella , Pubali Datta , Wajih\u00a0Ul Hassan , Adam Bates , Christopher\u00a0 W. Fletcher , Andrew Miller , and Dave Tian . 2020 . Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution. In 27th ISOC Network and Distributed System Security Symposium(NDSS\u201920) . Riccardo Paccagnella, Pubali Datta, Wajih\u00a0Ul Hassan, Adam Bates, Christopher\u00a0W. Fletcher, Andrew Miller, and Dave Tian. 2020. Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution. In 27th ISOC Network and Distributed System Security Symposium(NDSS\u201920)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Thomas Pasquier Xueyuan Han Thomas Moyer Adam Bates Olivier Hermant David Eyers Jean Bacon and Margo Seltzer. 2018. Runtime analysis of whole-system provenance. In CCS.  Thomas Pasquier Xueyuan Han Thomas Moyer Adam Bates Olivier Hermant David Eyers Jean Bacon and Margo Seltzer. 2018. Runtime analysis of whole-system provenance. In CCS.","DOI":"10.1145\/3243734.3243776"},{"key":"e_1_3_2_1_49_1","unstructured":"Nicole Perlroth and David\u00a0E. Sanger. 2018. Cyberattacks Put Russian Fingers on the Switch at Power Plants U.S. Says. https:\/\/www.nytimes.com\/2018\/03\/15\/us\/politics\/russia-cyberattacks.html.  Nicole Perlroth and David\u00a0E. Sanger. 2018. Cyberattacks Put Russian Fingers on the Switch at Power Plants U.S. Says. https:\/\/www.nytimes.com\/2018\/03\/15\/us\/politics\/russia-cyberattacks.html."},{"key":"e_1_3_2_1_50_1","volume-title":"Proceedings of the 2012 Annual Computer Security Applications Conference(ACSAC \u201912)","author":"Pohly D.J.","unstructured":"D.J. Pohly , S. McLaughlin , P. McDaniel , and K. Butler . 2012. Hi-Fi: Collecting High-Fidelity Whole-System Provenance . In Proceedings of the 2012 Annual Computer Security Applications Conference(ACSAC \u201912) . Orlando, FL, USA. D.J. Pohly, S. McLaughlin, P. McDaniel, and K. Butler. 2012. Hi-Fi: Collecting High-Fidelity Whole-System Provenance. In Proceedings of the 2012 Annual Computer Security Applications Conference(ACSAC \u201912). Orlando, FL, USA."},{"key":"e_1_3_2_1_51_1","unstructured":"Michael Riley Ben Elgin Dune Lawrence and Carol Matlack. 2019. Target Missed Warnings in Epic Hack of Credit Card Data. https:\/\/bloom.bg\/2KjElxM.  Michael Riley Ben Elgin Dune Lawrence and Carol Matlack. 2019. Target Missed Warnings in Epic Hack of Credit Card Data. https:\/\/bloom.bg\/2KjElxM."},{"key":"e_1_3_2_1_52_1","unstructured":"Dan Sullivan. 2016. Splunk Enterprise Security: Product overview. https:\/\/www.techtarget.com\/searchsecurity\/feature\/Splunk-Enterprise-Security-Product-overview.  Dan Sullivan. 2016. Splunk Enterprise Security: Product overview. https:\/\/www.techtarget.com\/searchsecurity\/feature\/Splunk-Enterprise-Security-Product-overview."},{"key":"e_1_3_2_1_53_1","unstructured":"Symantec EDR 4.6 Docs. 2022. About purging reports. https:\/\/techdocs.broadcom.com\/us\/en\/symantec-security-software\/endpoint-security-and-management\/endpoint-detection-and-response\/4-6\/about-reports-v117056913-d38e36074\/about-purging-reports-v118097546-d38e36892.html.  Symantec EDR 4.6 Docs. 2022. About purging reports. https:\/\/techdocs.broadcom.com\/us\/en\/symantec-security-software\/endpoint-security-and-management\/endpoint-detection-and-response\/4-6\/about-reports-v117056913-d38e36074\/about-purging-reports-v118097546-d38e36892.html."},{"key":"e_1_3_2_1_54_1","unstructured":"Symantec EDR 4.6 Docs. 2022. How Symantec EDR purges data from the Symantec EDR database. https:\/\/techdocs.broadcom.com\/us\/en\/symantec-security-software\/endpoint-security-and-management\/endpoint-detection-and-response\/4-6\/Settings\/how-purges-data-from-the-database-v106460598-d38e46998.html.  Symantec EDR 4.6 Docs. 2022. How Symantec EDR purges data from the Symantec EDR database. https:\/\/techdocs.broadcom.com\/us\/en\/symantec-security-software\/endpoint-security-and-management\/endpoint-detection-and-response\/4-6\/Settings\/how-purges-data-from-the-database-v106460598-d38e46998.html."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243763"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Yutao Tang Ding Li Zhichun Li Mu Zhang Kangkook Jee Xusheng Xiao Zhenyu Wu Junghwan Rhee Fengyuan Xu and Qun Li. 2018. Nodemerge: template based efficient data reduction for big-data causality analysis. In CCS.  Yutao Tang Ding Li Zhichun Li Mu Zhang Kangkook Jee Xusheng Xiao Zhenyu Wu Junghwan Rhee Fengyuan Xu and Qun Li. 2018. Nodemerge: template based efficient data reduction for big-data causality analysis. In CCS.","DOI":"10.1145\/3243734.3243763"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Qi Wang Wajih\u00a0Ul Hassan Adam Bates and Carl Gunter. 2018. Fear and logging in the internet of things. In NDSS.  Qi Wang Wajih\u00a0Ul Hassan Adam Bates and Carl Gunter. 2018. Fear and logging in the internet of things. In NDSS.","DOI":"10.14722\/ndss.2018.23282"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"crossref","unstructured":"Qi Wang Wajih\u00a0Ul Hassan Ding Li Kangkook Jee Xiao Yu Kexuan Zou Junghwan Rhee Zhengzhang Chen Wei Cheng C Gunter 2020. You are what you do: Hunting stealthy malware via data provenance analysis. In NDSS.  Qi Wang Wajih\u00a0Ul Hassan Ding Li Kangkook Jee Xiao Yu Kexuan Zou Junghwan Rhee Zhengzhang Chen Wei Cheng C Gunter 2020. You are what you do: Hunting stealthy malware via data provenance analysis. In NDSS.","DOI":"10.14722\/ndss.2020.24167"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978378"},{"key":"e_1_3_2_1_60_1","unstructured":"Zhang Xu Zhenyu Wu Zhichun Li Kangkook Jee Junghwan Rhee Xusheng Xiao Fengyuan Xu Haining Wang and Guofei Jiang. 2016. High fidelity data reduction for big data security dependency analyses. In CCS.  Zhang Xu Zhenyu Wu Zhichun Li Kangkook Jee Junghwan Rhee Xusheng Xiao Fengyuan Xu Haining Wang and Guofei Jiang. 2016. High fidelity data reduction for big data security dependency analyses. In CCS."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"crossref","unstructured":"Carter Yagemann Mohammad Noureddine Wajih\u00a0Ul Hassan Simon Chung Adam Bates and Wenke Lee. 2021. Validating the Integrity of Audit Logs Against Execution Repartitioning Attacks. In CCS.  Carter Yagemann Mohammad Noureddine Wajih\u00a0Ul Hassan Simon Chung Adam Bates and Wenke Lee. 2021. Validating the Integrity of Audit Logs Against Execution Repartitioning Attacks. In CCS.","DOI":"10.1145\/3460120.3484551"},{"key":"e_1_3_2_1_62_1","volume-title":"Secure Network Provenance. In ACM Symposium on Operating Systems Principles (SOSP).","author":"Zhou Wenchao","year":"2011","unstructured":"Wenchao Zhou , Qiong Fei , Arjun Narayan , Andreas Haeberlen , Boon\u00a0Thau Loo , and Micah Sherr . 2011 . Secure Network Provenance. In ACM Symposium on Operating Systems Principles (SOSP). Wenchao Zhou, Qiong Fei, Arjun Narayan, Andreas Haeberlen, Boon\u00a0Thau Loo, and Micah Sherr. 2011. Secure Network Provenance. In ACM Symposium on Operating Systems Principles (SOSP)."}],"event":{"name":"ACSAC: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC"},"container-title":["Proceedings of the 38th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3567990","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3564625.3567990","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:12Z","timestamp":1750183752000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3564625.3567990"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,5]]},"references-count":62,"alternative-id":["10.1145\/3564625.3567990","10.1145\/3564625"],"URL":"https:\/\/doi.org\/10.1145\/3564625.3567990","relation":{},"subject":[],"published":{"date-parts":[[2022,12,5]]},"assertion":[{"value":"2022-12-05","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}