TY - GEN
T1 - Sealing the Window
T2 - 47th IEEE Symposium on Security and Privacy, SP 2026
AU - Mishra, Sagar
AU - Sekar, R.
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Today's advanced cyber attacks routinely circumvent existing protection measures. Analysts must rely on after-the-fact detection, based on provenance logs, to understand and recover from these intrusions. Since attackers prize the ability to stay hidden, they take every measure to remove all signs of attacks from these logs. In this research, we begin with a study of previous work on protecting provenance logs from such tampering. Through a motivating experimental study, we show that audit logging systems deployed today are highly susceptible to tampering. Moreover, existing tamper detection measures either require specialized hardware and custom OS modifications, or they incur excessive performance costs. To overcome these challenges, we first analyze previous research to identify their key bottlenecks. We then present new techniques and algorithms that avoid these bottlenecks, while also providing several additional benefits. Our techniques have been implemented into a system WinSeal that achieves well over a 10 × reduction in overhead as compared to previous tamper detection techniques. On the protection front as well, WinSeal improves a key metric, namely, tamper window duration, by an order of magnitude as compared to previous techniques compatible with stock hardware and software. Our software is being open-sourced along with this paper.
AB - Today's advanced cyber attacks routinely circumvent existing protection measures. Analysts must rely on after-the-fact detection, based on provenance logs, to understand and recover from these intrusions. Since attackers prize the ability to stay hidden, they take every measure to remove all signs of attacks from these logs. In this research, we begin with a study of previous work on protecting provenance logs from such tampering. Through a motivating experimental study, we show that audit logging systems deployed today are highly susceptible to tampering. Moreover, existing tamper detection measures either require specialized hardware and custom OS modifications, or they incur excessive performance costs. To overcome these challenges, we first analyze previous research to identify their key bottlenecks. We then present new techniques and algorithms that avoid these bottlenecks, while also providing several additional benefits. Our techniques have been implemented into a system WinSeal that achieves well over a 10 × reduction in overhead as compared to previous tamper detection techniques. On the protection front as well, WinSeal improves a key metric, namely, tamper window duration, by an order of magnitude as compared to previous techniques compatible with stock hardware and software. Our software is being open-sourced along with this paper.
UR - https://www.scopus.com/pages/publications/105044399056
U2 - 10.1109/SP63933.2026.00092
DO - 10.1109/SP63933.2026.00092
M3 - Conference contribution
AN - SCOPUS:105044399056
T3 - Proceedings - IEEE Symposium on Security and Privacy
SP - 2424
EP - 2441
BT - Proceedings - 47th IEEE Symposium on Security and Privacy, SP 2026
A2 - Oprea, Alina
A2 - Nita-Rotaru, Cristina
A2 - Papernot, Nicolas
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 18 May 2026 through 21 May 2026
ER -