{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T13:14:09Z","timestamp":1778159649607,"version":"3.51.4"},"reference-count":22,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,4,26]],"date-time":"2023-04-26T00:00:00Z","timestamp":1682467200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGMETRICS Perform. Eval. Rev."],"published-print":{"date-parts":[[2023,4,26]]},"abstract":"<jats:p>Traditionally, security systems for enterprises have implicit access based on strong cryptography, authentication and key sharing, wherein access control is based on Role Based Access Control (RBAC), in which roles such as manager, accountant and so on provide a way of deciding a subject's authority. However, years of post-attack analysis on enterprise networks has shown that a majority of times, security breaches occur intentionally or accidently due to implicitly trusted people of an enterprise itself. Zero Trust Architecture works on the principle of never granting trust implicitly, but rather continuously evaluating the trust parameters for each resource access request and has a strict, but not rigid, set of protocols for access control of a subject to resources. Endpoint Detection and Response (EDR) systems are tools that collect a large number of attributes in and around machines within an enterprise network to have close visibility into sophisticated intrusion. In our work, we seek to deploy EDR systems and build trust algorithms using tactical provenance analysis, threshold cryptography and reputation management to continuously record data, evaluate trust of a subject, and simultaneously analyze them against a database of known threat vectors to provide conditional access control. However, EDR tools generate a high volume of data that leads to false alarms, misdetections and correspondingly a high backlog of tasks that makes it infeasible, which is addressed using tactical provenance analysis and information theory.<\/jats:p>","DOI":"10.1145\/3595244.3595247","type":"journal-article","created":{"date-parts":[[2023,4,27]],"date-time":"2023-04-27T10:27:14Z","timestamp":1682591234000},"page":"5-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Application of Data Collected by Endpoint Detection and Response Systems for Implementation of a Network Security System based on Zero Trust Principles and the EigenTrust Algorithm"],"prefix":"10.1145","volume":"50","author":[{"given":"Nitesh","family":"Kumar","sequence":"first","affiliation":[{"name":"Indian Institute of Technology Bombay, Mumbai, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gaurav S.","family":"Kasbekar","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Bombay, Mumbai, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"D.","family":"Manjunath","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology Bombay, Mumbai, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,4,27]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"2020 IEEE Symposium on Security and Privacy (SP) (pp. 1172--1189)","author":"Bates W.U.","unstructured":"Hassan, W.U. , Bates , A. and Marino , D ., 2020, May. \"Tactical provenance analysis for endpoint detection and response systems \", In 2020 IEEE Symposium on Security and Privacy (SP) (pp. 1172--1189) . IEEE. Hassan, W.U., Bates, A. and Marino, D., 2020, May. \"Tactical provenance analysis for endpoint detection and response systems\", In 2020 IEEE Symposium on Security and Privacy (SP) (pp. 1172--1189). IEEE."},{"key":"e_1_2_1_2_1","volume-title":"NIST Special Publication 800--207","author":"Scott","year":"2020","unstructured":"Rose, Scott W., Oliver Borchert , Stuart Mitchell , and Sean Connelly , \" Zero Trust Architecture .\" ( 2020 ). NIST Special Publication 800--207 . Rose, Scott W., Oliver Borchert, Stuart Mitchell, and Sean Connelly, \"Zero Trust Architecture.\" (2020). NIST Special Publication 800--207."},{"key":"e_1_2_1_3_1","volume-title":"12th international conference on World Wide Web (pp. 640--651)","author":"Schlosser S.D.","unstructured":"Kamvar, S.D. , Schlosser , M.T. and Garcia-Molina , H ., 2003, May. \"The eigentrust algorithm for reputation management in p2p networks \", 12th international conference on World Wide Web (pp. 640--651) . Kamvar, S.D., Schlosser, M.T. and Garcia-Molina, H., 2003, May. \"The eigentrust algorithm for reputation management in p2p networks\", 12th international conference on World Wide Web (pp. 640--651)."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/65.806983"},{"key":"e_1_2_1_5_1","unstructured":"T.M. Cover J.A. Thomas \"Elements of Information Theory\" John Wiley & Sons Inc. 2004.  T.M. Cover J.A. Thomas \"Elements of Information Theory\" John Wiley & Sons Inc. 2004."},{"key":"#cr-split#-e_1_2_1_6_1.1","doi-asserted-by":"crossref","unstructured":"G. Karantzas C. Patsakis 2021 \"An Empirical Assessment of Endpoint Detection and Response Systems against Advanced Persistent Threats Attack Vectors\" https:\/\/doi.org\/10.3390\/jcp1030021. 10.3390\/jcp1030021","DOI":"10.3390\/jcp1030021"},{"key":"#cr-split#-e_1_2_1_6_1.2","doi-asserted-by":"crossref","unstructured":"G. Karantzas C. Patsakis 2021 \"An Empirical Assessment of Endpoint Detection and Response Systems against Advanced Persistent Threats Attack Vectors\" https:\/\/doi.org\/10.3390\/jcp1030021.","DOI":"10.3390\/jcp1030021"},{"key":"e_1_2_1_7_1","first-page":"787","volume-title":"CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security","author":"Joey","year":"2020","unstructured":"Joey Allen et al., \"Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation System \", CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security , pp. 787 -- 802 , October 2020 . Joey Allen et al., \"Mnemosyne: An Effective and Efficient Postmortem Watering Hole Attack Investigation System\", CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pp. 787--802, October 2020."},{"key":"e_1_2_1_8_1","unstructured":"Vincent Hu David Ferraiolo Richard Kuhn (NIST) SP 800--205 \"Attribute Considerations for Access Control Systems\" June 2019.  Vincent Hu David Ferraiolo Richard Kuhn (NIST) SP 800--205 \"Attribute Considerations for Access Control Systems\" June 2019."},{"key":"e_1_2_1_9_1","first-page":"1","volume-title":"NIST special publication, 800 (162)","author":"Vincent","year":"2020","unstructured":"Hu, Vincent C., David Ferraiolo , Rick Kuhn , Arthur R. Friedman , Alan J. Lang , Margaret M. Cogdell , Adam Schnitzer , Kenneth Sandlin , Robert Miller , and Karen Scarfone , \" Guide to Attribute Based Access Control (ABAC) Definition and Considerations.\" ( 2020 ), NIST special publication, 800 (162) , pp. 1 -- 54 . Hu, Vincent C., David Ferraiolo, Rick Kuhn, Arthur R. Friedman, Alan J. Lang, Margaret M. Cogdell, Adam Schnitzer, Kenneth Sandlin, Robert Miller, and Karen Scarfone, \"Guide to Attribute Based Access Control (ABAC) Definition and Considerations.\" (2020), NIST special publication, 800 (162), pp.1--54."},{"key":"e_1_2_1_10_1","unstructured":"W. Fisher (NIST) N. Brickman (MITRE) et al SP 1800--3 Attribute Based Access Control (2nd Draft).  W. Fisher (NIST) N. Brickman (MITRE) et al SP 1800--3 Attribute Based Access Control (2nd Draft)."},{"key":"e_1_2_1_11_1","volume-title":"2018 29th Irish Signals and Systems Conference (ISSC).","author":"Romans","unstructured":"Romans Vanickis et al., \"Access Control Policy Enforcement for Zero-Trust-Networking \", 2018 29th Irish Signals and Systems Conference (ISSC). Romans Vanickis et al., \"Access Control Policy Enforcement for Zero-Trust-Networking\", 2018 29th Irish Signals and Systems Conference (ISSC)."},{"key":"e_1_2_1_12_1","first-page":"522","volume-title":"STOC 1994","author":"Santis A. D.","unstructured":"A. D. Santis , Y. Desmedt , Y. Frankel , M. Yung , \" How to Share a Function Securely\" , STOC 1994 : pp. 522 - 533 . A. D. Santis, Y. Desmedt, Y. Frankel, M. Yung, \"How to Share a Function Securely\", STOC 1994: pp. 522 - 533."},{"key":"e_1_2_1_13_1","volume-title":"Forrester Research","author":"Kindervag J.","year":"2016","unstructured":"J. Kindervag , \"No more chewy centres: The zero trust model of information security \", Forrester Research , Mar 2016 . J. Kindervag, \"No more chewy centres: The zero trust model of information security\", Forrester Research, Mar 2016."},{"key":"e_1_2_1_14_1","volume-title":"USENIX Security Symposium 2021:  3523--3540","author":"Alrawi O.","unstructured":"O. Alrawi , M. Ike , M. Pruett , R. Pai Kasturi , S. Barua , T. Hirani , B. Hill , B. Saltaformaggio : \" Forecasting Malware Capabilities from Cyber Attack Memory Images \", USENIX Security Symposium 2021: 3523--3540 . O. Alrawi, M. Ike, M. Pruett, R. Pai Kasturi, S. Barua, T. Hirani, B. Hill, B. Saltaformaggio: \"Forecasting Malware Capabilities from Cyber Attack Memory Images\", USENIX Security Symposium 2021: 3523--3540."},{"key":"e_1_2_1_15_1","first-page":"1533","volume-title":"CCS '20: ACM SIGSAC Conference on Computer and Communications Security","author":"Nahid","year":"2020","unstructured":"Nahid Juma et al., \"Forensic Analysis in Access Control: Foundations and a Case-Study from Practice \", CCS '20: ACM SIGSAC Conference on Computer and Communications Security , October 2020 pp. 1533 -- 1550 . Nahid Juma et al., \"Forensic Analysis in Access Control: Foundations and a Case-Study from Practice\", CCS '20: ACM SIGSAC Conference on Computer and Communications Security, October 2020 pp. 1533--1550."},{"key":"e_1_2_1_16_1","volume-title":"Carl Hamacher, Zvonko Vranesic, Safwat Zaky, \"Computer Organization\"","year":"2002","unstructured":"Carl Hamacher, Zvonko Vranesic, Safwat Zaky, \"Computer Organization\" , Fifth Edition, Mc Graw Hill Education , 2002 . Carl Hamacher, Zvonko Vranesic, Safwat Zaky, \"Computer Organization\", Fifth Edition, Mc Graw Hill Education, 2002."},{"key":"e_1_2_1_17_1","volume-title":"Abraham Silberschatz, Henry F. Korth, S. Sudarshan, \"Database System Concepts\"","year":"2013","unstructured":"Abraham Silberschatz, Henry F. Korth, S. Sudarshan, \"Database System Concepts\" , 6 th Edition, 2013 , McGraw Hill Publication . Abraham Silberschatz, Henry F. Korth, S. Sudarshan, \"Database System Concepts\", 6th Edition, 2013, McGraw Hill Publication.","edition":"6"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359176"},{"key":"e_1_2_1_19_1","volume-title":"Springer","author":"Frankel Yair","year":"1991","unstructured":"Desmedt, Yvo, and Yair Frankel , \"Shared generation of authenticators and signatures.\" In Annual International Cryptology Conference, pp. 457--469 . Springer , Berlin, Heidelberg , 1991 . Desmedt, Yvo, and Yair Frankel, \"Shared generation of authenticators and signatures.\" In Annual International Cryptology Conference, pp. 457--469. Springer, Berlin, Heidelberg, 1991."},{"key":"e_1_2_1_20_1","volume-title":"Springer","author":"Hwang Tzonelih","year":"1993","unstructured":"Li, Chuan-Ming, Tzonelih Hwang , and Narn-Yih Lee , \"Remark on the threshold RSA signature scheme.\" In Annual International Cryptology Conference, pp. 413--419 . Springer , Berlin, Heidelberg , 1993 . Li, Chuan-Ming, Tzonelih Hwang, and Narn-Yih Lee, \"Remark on the threshold RSA signature scheme.\" In Annual International Cryptology Conference, pp. 413--419. Springer, Berlin, Heidelberg, 1993."},{"key":"e_1_2_1_21_1","first-page":"677","volume-title":"Manipulation- Resistant Reputation Systems, E. Friedman, et al","author":"N. Nissan","year":"2007","unstructured":"N. Nissan et al , \" Algorithmic Game Theory \", Manipulation- Resistant Reputation Systems, E. Friedman, et al , pp. 677 - 695 . Cambridge University Press , 2007 . N. Nissan et al, \"Algorithmic Game Theory\", Manipulation- Resistant Reputation Systems, E. Friedman, et al, pp. 677- 695. Cambridge University Press, 2007."}],"container-title":["ACM SIGMETRICS Performance Evaluation Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3595244.3595247","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3595244.3595247","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:08Z","timestamp":1750182548000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3595244.3595247"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,26]]},"references-count":22,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,4,26]]}},"alternative-id":["10.1145\/3595244.3595247"],"URL":"https:\/\/doi.org\/10.1145\/3595244.3595247","relation":{},"ISSN":["0163-5999"],"issn-type":[{"value":"0163-5999","type":"print"}],"subject":[],"published":{"date-parts":[[2023,4,26]]},"assertion":[{"value":"2023-04-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}