conference-paper
Open access
Towards Provenance for Cybersecurity in Cloud-Native Production Infrastructure
Research footprint
At a glance
- Citations
- 0
- References
- 15
- Comments
- 0
Paper overview
Abstract
System provenance models the interactions between system subjects and objects, enabling post-mortem and root-cause analyses of cyberattacks. Despite numerous contributions to provenance systems, there remains little consensus on the reliability of existing telemetry collection methods. Linux Security Module (LSM) interfaces present a promising alternative thanks to their inherent stability and safety for production environments. However, since LSM do not capture the full granularity of system calls, it is unclear whether they can support the creation of sound provenance graphs. In this work, we study the evolution of these kernel interfaces and their coverage.
Record transparency
Publication details
- DOI
- 10.1109/dsn-s65789.2025.00023
- OpenAlex
- W4412129965
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.