conference-paper Open access

Towards Provenance for Cybersecurity in Cloud-Native Production Infrastructure

Research footprint

At a glance

Citations
0
References
15
Comments
0
Paper overview

Abstract

System provenance models the interactions between system subjects and objects, enabling post-mortem and root-cause analyses of cyberattacks. Despite numerous contributions to provenance systems, there remains little consensus on the reliability of existing telemetry collection methods. Linux Security Module (LSM) interfaces present a promising alternative thanks to their inherent stability and safety for production environments. However, since LSM do not capture the full granularity of system calls, it is unclear whether they can support the creation of sound provenance graphs. In this work, we study the evolution of these kernel interfaces and their coverage.

Record transparency

Publication details

DOI
10.1109/dsn-s65789.2025.00023
OpenAlex
W4412129965
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.