{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T16:16:08Z","timestamp":1783008968011,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":3,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2339483, CNS-2046540"],"award-info":[{"award-number":["CNS-2339483, CNS-2046540"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Commonwealth Cyber Initiative"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765024","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:33:16Z","timestamp":1763854396000},"page":"2624-2638","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing System"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-7898-6831","authenticated-orcid":false,"given":"Rui","family":"Zhao","sequence":"first","affiliation":[{"name":"University of Virginia, Charlottesville, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-2009-9542","authenticated-orcid":false,"given":"Muhammad","family":"Shoaib","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3092-6405","authenticated-orcid":false,"given":"Viet Tung","family":"Hoang","sequence":"additional","affiliation":[{"name":"Florida State University, Tallahassee, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5676-6027","authenticated-orcid":false,"given":"Wajih Ul","family":"Hassan","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Falco: cloud native runtime security tool for Linux operating systems. https:\/\/github.com\/falcosecurity\/falco."},{"key":"e_1_3_2_1_2_1","unstructured":"Aaron Kili. Sysdig -- a powerful system monitoring and troubleshooting tool for linux. https:\/\/www.tecmint.com\/sysdig-systemmonitoring-and-troubleshootingtool-for-linux\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Cilium. Cilium\/tetragon: eBPF-based security observability and runtime enforcement. https:\/\/github.com\/cilium\/tetragon."},{"key":"e_1_3_2_1_4_1","unstructured":"DARPA OPTC. https:\/\/github.com\/FiveDirections\/OpTC-data ."},{"key":"e_1_3_2_1_5_1","unstructured":"DARPA TC. https:\/\/github.com\/darpa-i2o\/Transparent-Computing ."},{"key":"e_1_3_2_1_6_1","unstructured":"What is eBPF? https:\/\/ebpf.io\/what-is-ebpf\/."},{"key":"e_1_3_2_1_7_1","unstructured":"The Linux audit daemon. https:\/\/linux.die.net\/man\/8\/auditd."},{"key":"e_1_3_2_1_8_1","unstructured":"OpenSSL: Cryptography and SSL\/TLS Toolkit. https:\/\/www.openssl.org\/."},{"key":"e_1_3_2_1_9_1","unstructured":"BPF ring buffer. https:\/\/www.kernel.org\/doc\/html\/next\/bpf\/ringbuf.html."},{"key":"e_1_3_2_1_10_1","unstructured":"Aqua Security. Tracee: Runtime security and forensics using eBPF. https:\/\/github.com\/aquasecurity\/tracee."},{"key":"e_1_3_2_1_11_1","volume-title":"Security Monitoring with eBPF. https:\/\/www.brendangregg.com\/Slides\/BSidesSF2017_BPF_security_monitoring\/","author":"SF","year":"2017","unstructured":"BSidesSF 2017: Security Monitoring with eBPF. https:\/\/www.brendangregg.com\/Slides\/BSidesSF2017_BPF_security_monitoring\/, 2017."},{"key":"e_1_3_2_1_12_1","volume-title":"AuditD from the HIDS perspective. https:\/\/sysdig.com\/blog\/falco-vsauditd-hids\/","author":"Falco","year":"2021","unstructured":"Falco vs. AuditD from the HIDS perspective. https:\/\/sysdig.com\/blog\/falco-vsauditd-hids\/, 2021."},{"key":"e_1_3_2_1_13_1","volume-title":"https:\/\/browserbench.org\/Speedometer2.0\/","author":"Speedometer","year":"2023","unstructured":"Speedometer 2.0. https:\/\/browserbench.org\/Speedometer2.0\/, 2023."},{"key":"e_1_3_2_1_14_1","volume-title":"https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/advancedencryption- standard-instructions-aes-ni.html","author":"Encryption Standard Intel\u00ae Advanced","year":"2024","unstructured":"Intel\u00ae Advanced Encryption Standard Instructions (AES-NI). https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/advancedencryption- standard-instructions-aes-ni.html, 2024."},{"key":"e_1_3_2_1_15_1","volume-title":"https:\/\/github.com\/iovisor\/bcc","author":"Compiler BPF","year":"2024","unstructured":"BPF Compiler Collection (BCC). https:\/\/github.com\/iovisor\/bcc, 2024."},{"key":"e_1_3_2_1_16_1","volume-title":"https:\/\/github.com\/iovisor\/bcc\/ blob\/master\/docs\/reference_guide.md","author":"Compiler BPF","year":"2024","unstructured":"BPF Compiler Collection (BCC) Reference Guide. https:\/\/github.com\/iovisor\/bcc\/ blob\/master\/docs\/reference_guide.md, 2024."},{"key":"e_1_3_2_1_17_1","volume-title":"https:\/\/github.com\/microsoft\/ebpf-for-windows","year":"2024","unstructured":"ebpf for windows. https:\/\/github.com\/microsoft\/ebpf-for-windows, 2024."},{"key":"e_1_3_2_1_18_1","volume-title":"https:\/\/www.intel. com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-sdm.html","author":"Intel\u00ae","year":"2025","unstructured":"Intel\u00ae 64 and ia-32 architectures software developer manuals. https:\/\/www.intel. com\/content\/www\/us\/en\/developer\/articles\/technical\/intel-sdm.html, 2025."},{"key":"e_1_3_2_1_19_1","volume-title":"https:\/\/opensource.microsoft.com\/blog\/2022\/10\/25\/towards-debuggabilityand- secure-deployments-of-ebpf-programs-on-windows\/","author":"Towards","year":"2025","unstructured":"Towards debuggability and secure deployments of ebpf programs on windows. https:\/\/opensource.microsoft.com\/blog\/2022\/10\/25\/towards-debuggabilityand- secure-deployments-of-ebpf-programs-on-windows\/, 2025."},{"key":"e_1_3_2_1_20_1","volume-title":"https:\/\/microsoft.github.io\/ebpf-for-windows\/ebpf__structs_8h.html","year":"2025","unstructured":"ebpf for windows file reference. https:\/\/microsoft.github.io\/ebpf-for-windows\/ebpf__structs_8h.html, 2025."},{"key":"e_1_3_2_1_21_1","volume-title":"https:\/\/opensource.microsoft.com\/blog\/2022\/02\/22\/getting-linux-basedebpf- programs-to-run-with-ebpf-for-windows\/","author":"Getting","year":"2025","unstructured":"Getting linux based ebpf programs to run with ebpf for windows. https:\/\/opensource.microsoft.com\/blog\/2022\/02\/22\/getting-linux-basedebpf- programs-to-run-with-ebpf-for-windows\/, 2025."},{"key":"e_1_3_2_1_22_1","volume-title":"https:\/\/github.com\/microsoft\/ebpf-for-windows\/ blob\/main\/docs\/tutorial.md","author":"Tutorial","year":"2025","unstructured":"Tutorial of ebpf for windows. https:\/\/github.com\/microsoft\/ebpf-for-windows\/ blob\/main\/docs\/tutorial.md, 2025."},{"key":"e_1_3_2_1_23_1","volume-title":"https:\/\/docs.kernel.org\/bpf\/","author":"Linux","year":"2025","unstructured":"Linux bpf documentation. https:\/\/docs.kernel.org\/bpf\/, 2025."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833745"},{"key":"e_1_3_2_1_25_1","volume-title":"USENIX Security Symposium","author":"Alsaheel A.","year":"2021","unstructured":"A. Alsaheel, Y. Nan, S. Ma, L. Yu, G. Walkup, Z. B. Celik, X. Zhang, and D. Xu. Atlas: A sequence-based learning approach for attack investigation. In USENIX Security Symposium, 2021."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-34931-7_28"},{"key":"e_1_3_2_1_27_1","volume-title":"USENIX Security Symposium","author":"Bates A.","year":"2015","unstructured":"A. Bates, D. J. Tian, K. R. Butler, and T. Moyer. Trustworthy whole-system provenance for the linux kernel. In USENIX Security Symposium, 2015."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_25"},{"key":"e_1_3_2_1_29_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Ding H.","year":"2021","unstructured":"H. Ding, S. Yan, J. Zhai, and S. Ma. Elise: A storage efficient logging system powered by redundancy reduction and representation learning. In 30th USENIX Security Symposium (USENIX Security 21), 2021."},{"key":"e_1_3_2_1_30_1","first-page":"3277","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Ding H.","year":"2023","unstructured":"H. Ding, J. Zhai, D. Deng, and S. Ma. The case for learned provenance graph storage systems. In 32nd USENIX Security Symposium (USENIX Security 23), pages 3277--3294, 2023."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1111\/j.2517-6161.1954.tb00159.x"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/3620237.3620260"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35170-9_6"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427255"},{"key":"e_1_3_2_1_35_1","volume-title":"USENIX Security","author":"Hoang V. T.","year":"2022","unstructured":"V. T. Hoang, C. Wu, and X. Yuan. Faster yet safer: Logging system via Fixed-Key blockcipher. In USENIX Security, 2022."},{"key":"e_1_3_2_1_36_1","volume-title":"USENIX Security Symposium","author":"Hossain M. N.","year":"2017","unstructured":"M. N. Hossain, S. M. Milajerdi, J. Wang, B. Eshete, R. Gjomemo, R. Sekar, S. D. Stoller, and V. Venkatakrishnan. SLEUTH: Real-time attack scenario reconstruction from COTS audit data. In USENIX Security Symposium, 2017."},{"key":"e_1_3_2_1_37_1","volume-title":"USENIX Security Symposium","author":"Hossain M. N.","year":"2018","unstructured":"M. N. Hossain, J. Wang, R. Sekar, and S. D. Stoller. Dependence-preserving data compaction for scalable forensic analysis. In USENIX Security Symposium, 2018."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567990"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179405"},{"key":"e_1_3_2_1_40_1","volume-title":"The art of computer systems performance analysis","author":"Jain R.","year":"1991","unstructured":"R. Jain. The art of computer systems performance analysis. John Wiley & Sons, 1991."},{"key":"e_1_3_2_1_41_1","volume-title":"USENIX Security Symposium","author":"Jiang P.","year":"2023","unstructured":"P. Jiang, R. Huang, D. Li, Y. Guo, X. Chen, J. Luan, Y. Ren, and X. Hu. Auditing frameworks need resource isolation: A systematic study on the super producer threat to system auditing and its mitigation. In USENIX Security Symposium, 2023."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053034"},{"key":"e_1_3_2_1_43_1","volume-title":"Postmark: A new file system benchmark","author":"Katcher J.","year":"1997","unstructured":"J. Katcher. Postmark: A new file system benchmark. 1997. URL https:\/\/api.semanticscholar.org\/CorpusID:59816446."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3--540--79263--5_10"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945467"},{"key":"e_1_3_2_1_46_1","volume-title":"CCS","author":"Lee K. H.","year":"2013","unstructured":"K. H. Lee, X. Zhang, and D. Xu. Loggc: garbage collecting audit log. In CCS, 2013."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23254"},{"key":"e_1_3_2_1_48_1","volume-title":"USENIX Annual Technical Conference (ATC)","author":"Ma S.","year":"2018","unstructured":"S. Ma, J. Zhai, Y. Kwon, K. H. Lee, X. Zhang, G. Ciocarlie, A. Gehani, V. Yegneswaran, D. Xu, and S. Jha. Kernel-supported cost-effective audit logging for causality tracking. In USENIX Annual Technical Conference (ATC), 2018."},{"key":"e_1_3_2_1_49_1","volume-title":"USENIX Annual Technical Conference (ATC)","author":"McVoy L.","year":"1996","unstructured":"L. McVoy and C. Staelin. lmbench: Portable tools for performance analysis. In USENIX Annual Technical Conference (ATC), 1996."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-13051-4_19"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24065"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417862"},{"key":"e_1_3_2_1_53_1","volume-title":"TCC","author":"Pasquier T.","year":"2015","unstructured":"T. Pasquier, J. Singh, D. Eyers, and J. Bacon. Camflow: Managed data-sharing for cloud services. In TCC, 2015."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"e_1_3_2_1_55_1","volume-title":"Learning eBPF: Programming the Linux Kernel for Enhanced Observability, Networking, and Security","author":"Rice L.","year":"2023","unstructured":"L. Rice. Learning eBPF: Programming the Linux Kernel for Enhanced Observability, Networking, and Security. O'Reilly Media, 2023. ISBN 9781098135089. URL https:\/\/books.google.com\/books?id=OqCyEAAAQBAJ."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00087"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3679048"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243763"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978378"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690188"},{"key":"e_1_3_2_1_61_1","volume-title":"Rethinking tamper-evident logging: A high-performance, co-designed auditing system. arXiv preprint arXiv:2509.03821","author":"Zhao R.","year":"2025","unstructured":"R. Zhao, M. Shoaib, V. T. Hoang, and W. U. Hassan. Rethinking tamper-evident logging: A high-performance, co-designed auditing system. arXiv preprint arXiv:2509.03821, 2025. URL https:\/\/arxiv.org\/abs\/2509.03821."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3689031.3717497"}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765024","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765024","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:19:11Z","timestamp":1766441951000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765024"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":62,"alternative-id":["10.1145\/3719027.3765024","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765024","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}