EDBT 2026 Demo / reviewers in the wild / expert
Wajih Ul Hassan
dblp:184/8086
· DBLP profile ↗
28ranked-venue papers
6as first author
14since 2021 · last 2026
0000-0002-5676-6027ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 6 first-author · 11 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reconfigurable Computing Challenge: RapidScan High-Throughput Parameterized HLS-based Streaming String Matching Library for FPGAs
Shashank Obla, Tommy Tracy II, Matthew Beck, James C. Hoe, Kevin Skadron, Wajih Ul Hassan |
FCCM | 6 |
| 2026 | Catch Me If You Can: Detector-Resistant Evasion via Semantics-Preserving Command Re-Realization
Hare Sudhan Muthusamy, Tareq Alkhatib, Wajih Ul Hassan |
SP | 4 |
| 2026 | HADES: Detecting and Investigating Active Directory Attacks via Whole Network Provenance AnalyticsabstractDue to its crucial role in identity and access management in modern enterprise networks, Active Directory (AD) is a top target of Advanced Persistence Threat (APT) actors. Conventional intrusion detection systems (IDS) excel at identifying malicious behaviors caused by malware, but often fail to detect stealthy attacks launched by APT actors. Recent advance in provenance-based IDS (PIDS) shows promises by exposing malicious system activities in causal attack graphs. However, existing approaches are restricted to intra-machine tracing, and unable to reveal the scope of attackers' traversal inside a network. We proposeHADES, the first PIDS capable of performing accurate causality-based cross-machine tracing by leveraging a novel concept calledlogon session based execution partitioningto overcome several challenges in cross-machine tracing. We designHADESas an efficient on-demand tracing system, which performs whole-network tracing only when it first identifies an authentication anomaly signifying an ongoing AD attack, for which we introduce a novel lightweight authentication anomaly detection model rooted in our extensive analysis of AD attacks. To triage attack alerts, we present a new algorithm integrating two key insights we identified in AD attacks. Our evaluations show thatHADESoutperforms both popular open-source detection systems and a prominent commercial AD attack detector. Qi Liu 0023, Kaibin Bao, Wajih Ul Hassan, Veit Hagenmeyer |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Accurate and Scalable Detection and Investigation of Cyber Persistence ThreatsabstractIn Advanced Persistent Threat (APT) attacks, achieving stealthy persistence within target systems is often crucial for an attacker's success. This persistence allows adversaries to maintain prolonged access, often evading detection mechanisms. Recognizing its pivotal role in the APT lifecycle, this paper introduces Cyber Persistence Detector (CPD), a novel system dedicated to detecting cyber persistence through provenance analytics. CPD is founded on the insight that persistent operations typically manifest in two phases: the “persistence setup” and the subsequent “persistence execution”. By causally relating these phases, we enhance our ability to detect persistent threats. First, CPD discerns setups signaling an impending persistent threat and then traces processes linked to remote connections to identify persistence execution activities. A key feature of our system is the introduction ofpseudo-dependency edges(pseudoedges), which effectively connect these disjoint phases using data provenance analysis, andexpert-guided edges, which enable faster tracing and reduced log size. These edges empower us to detect persistence threats accurately and efficiently. Moreover, we propose a novel alert triage algorithm that further reduces false positives associated with persistence threats. Evaluations conducted on well-known datasets demonstrate that our system reduces the average false positive rate by 93% compared to stateof- the-art methods. Qi Liu 0023, Mati Ur Rehman, Kaibin Bao, Veit Hagenmeyer, Wajih Ul Hassan |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | R+R: From Claims to Crashes: A Systematic Re-evaluation of Graph-Based Network Intrusion Detection SystemsabstractGraph-based Network Intrusion Detection Systems (GIDS) are increasingly used to model complex communication patterns and detect sophisticated enterprise threats, yet the reproducibility and replicability of GIDS research remain underexplored, limiting the reliability and generalizability of published results. We present a rigorous reproduction and replication of five state-of-the-art GIDS across four public datasets and a new large-scale enterprise dataset. Even with original code and configurations, reproducing claimed performance is difficult; detection metrics vary by up to 40 percent due to undocumented assumptions, preprocessing discrepancies, and hyperparameter sensitivity. Models also fail to generalize to real-world enterprise traffic, exhibiting high false positive rates and scalability issues. We identify key implementation factors: graph snapshot size and threshold-setting strategies significantly affect detection performance but are inconsistently documented, and several GIDS are vulnerable to evasion attacks. Beyond confirming known challenges (e.g., parameter sensitivity), our results expose a critical reproducibility crisis in the GIDS literature: without transparent and systematic evaluation, reported results may mislead researchers and practitioners. We provide recommendations to improve reproducibility, replicability, and robustness, and urge the community to adopt rigorous standards for empirical evaluation. Pujia Zheng, Jiaping Gui, Cunqing Hua, Wajih Ul Hassan |
ACSAC | 5 |
| 2025 | Rethinking Tamper-Evident Logging: A High-Performance, Co-Designed Auditing SystemabstractExisting tamper-evident logging systems suffer from high overhead and severe data loss in high-load settings, yet only provide coarse-grained tamper detection. Moreover, installing such systems requires recompiling kernel code. To address these challenges, we present Nitro, a high-performance, tamper-evident audit logging system that supports fine-grained detection of log tampering. Even better, our system avoids kernel recompilation by using the eBPF technology. To formally justify the security of Nitro, we provide a new definitional framework for logging systems, and give a practical cryptographic construction meeting this new goal. Unlike prior work that focus only on the cryptographic processing, we codesign the cryptographic part with the pre- and post-processing of the logs to exploit all system-level optimizations. Our evaluations demonstrate Nitro's superior performance, achieving 10X-25X improvements in high-stress conditions and 2X-10X in real-world scenarios while maintaining near-zero data loss. We also provide an advanced variant, Nitro-R that introduces in-kernel log reduction techniques to reduce runtime overhead even further. Viet Tung Hoang, Wajih Ul Hassan |
CCS | 4 |
| 2025 | A Principled Approach for Detecting APTs in Massive Networks via Multi-Stage Causal Analytics
Jiaping Gui, Mingjie Nie, Jinyao Guo, Futai Zou, Mati Ur Rehman, Wajih Ul Hassan |
INFOCOM | 6 |
| 2025 | Demo: Investigating Immersive Attacks with REALITYCHECKabstractRealityCheck, recently published at USENIX Security 2025, is the first provenance-based auditing framework that enables comprehensive root-cause and impact analysis of complex attacks against Augmented/Virtual-Reality (AR/VR) head-mounted devices. This demonstration paper describes the live, hands-on instantiation of RealityCheck, highlighting how security analysts can transparently capture multi-layer logs from commodity headsets, automatically transform these heterogeneous traces into concise multilayer provenance graphs, and perform real-time exploratory queries to isolate attack causality. We demonstrate RealityCheck reconstructing an end-to-end provenance graph for the Object-in-the-middle attack, published at USENIX Security 2024, on a Meta Quest 2, achieving millisecond-level query latency with negligible runtime overhead. Wajih Ul Hassan |
MobiHoc | 2 |
| 2025 | Principled and Automated Approach for Investigating AR/VR Attacks
Alex Suh, Wajih Ul Hassan |
USENIX Security Symposium | 3 |
| 2024 | Flash: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation LearningabstractRecently, provenance-based Intrusion Detection Systems (IDSes) have gained popularity for their potential in detecting sophisticated Advanced Persistent Threat (APT) attacks. These IDSes employ provenance graphs created from system logs to identify potentially malicious activities. Despite their potential, they face challenges in accuracy, practicality, and scalability, particularly when dealing with large provenance graphs. We present Flash, a scalable IDS that leverages graph representation learning through Graph Neural Networks (GNNs) on data provenance graphs to overcome these limitations. Flash employs a Word2Vec-based semantic encoder to capture essential semantic attributes (e.g., process names and file paths) and the temporal ordering of events within the provenance graph. Furthermore, Flash incorporates a novel adaptation of a GNN-based contextual encoder to efficiently encode both local and global graph structures into expressive node embeddings. To learn benign node behaviors, we utilize a lightweight classifier that combines the GNN and Word2Vec embeddings. Recognizing the computational demands and slow processing times of GNN, particularly for large provenance graphs, we have developed an embedding recycling database to store the node embeddings generated during the training phase. During runtime, our lightweight classifier leverages the stored embeddings, obviating the need to regenerate GNN embeddings, thus facilitating real-time APT detection. Extensive evaluation of Flash on real-world datasets demonstrates superior detection accuracy compared to existing provenance-based IDSes. The results also illustrate Flash’s scalability, robustness against mimicry attacks, and potential for accelerating the alert verification process. Mati Ur Rehman, Hadi Ahmadi, Wajih Ul Hassan |
SP | 3 |
| 2023 | SoK: History is a Vast Early Warning System: Auditing the Provenance of System IntrusionsabstractAuditing, a central pillar of operating system security, has only recently come into its own as an active area of public research. This resurgent interest is due in large part to the notion of data provenance, a technique that iteratively parses audit log entries into a dependency graph that explains the history of system execution. Provenance facilitates precise threat detection and investigation through causal analysis of sophisticated intrusion behaviors. However, the absence of a foundational audit literature, combined with the rapid publication of recent findings, makes it difficult to gain a holistic picture of advancements and open challenges in the area.In this work, we survey and categorize the provenance-based system auditing literature, distilling contributions into a layered taxonomy based on the audit log capture and analysis pipeline. Recognizing that the Reduction Layer remains a key obstacle to the further proliferation of causal analysis technologies, we delve further on this issue by conducting an ambitious independent evaluation of 8 exemplar reduction techniques against the recently-released DARPA Transparent Computing datasets. Our experiments uncover that past approaches frequently prune an overlapping set of activities from audit logs, reducing the synergistic benefits from applying them in tandem; further, we observe an inverse relation between storage efficiency and anomaly detection performance. However, we also observe that log reduction techniques are able to synergize effectively with data compression, potentially reducing log retention costs by multiple orders of magnitude. We conclude by discussing promising future directions for the field. Muhammad Adil Inam, Yinfang Chen, Akul Goyal, Jason Liu 0002, Jaron Mink, Noor Michael, Sneha Gaur, Adam Bates 0001, Wajih Ul Hassan |
SP | 9 |
| 2022 | FAuST: Striking a Bargain between Forensic Auditing's Security and ThroughputabstractSystem logs are invaluable to forensic audits, but grow so large that in practice fine-grained logs are quickly discarded – if captured at all – preventing the real-world use of the provenance-based investigation techniques that have gained popularity in the literature. Encouragingly, forensically-informed methods for reducing the size of system logs are a subject of frequent study. Unfortunately, many of these techniques are designed for offline reduction in a central server, meaning that the up-front cost of log capture, storage, and transmission must still be paid at the endpoints. Moreover, to date these techniques exist as isolated (and, often, closed-source) implementations; there does not exist a comprehensive framework through which the combined benefits of multiple log reduction techniques can be enjoyed. Muhammad Adil Inam, Akul Goyal, Jason Liu 0002, Jaron Mink, Noor Michael, Sneha Gaur, Adam Bates 0001, Wajih Ul Hassan |
ACSAC | 8 |
| 2022 | Forensic Analysis of Configuration-based Attacks
Muhammad Adil Inam, Wajih Ul Hassan, Ali Ahad, Adam Bates 0001, Rashid Tahir, Tianyin Xu, Fareed Zaffar |
NDSS | 2 |
| 2021 | Validating the Integrity of Audit Logs Against Execution Repartitioning AttacksabstractProvenance-based causal analysis of audit logs has proven to be an invaluable method of investigating system intrusions. However, it also suffers from dependency explosion, whereby long-running processes accumulate many dependencies that are hard to unravel. Execution unit partitioning addresses this by segmenting dependencies into units of work, such as isolating the events that processed a single HTTP request. Unfortunately, we discover that current designs have a semantic gap problem due to how system calls and application log messages are used to infer complex internal program states. We demonstrate how attackers can modify existing code exploits to control event partitioning, breaking links in the attack and framing innocent users. We also show how our techniques circumvent existing program and log integrity defenses. Carter Yagemann, Mohammad A. Noureddine, Wajih Ul Hassan, Simon P. Chung, Adam Bates 0001, Wenke Lee |
CCS | 3 |
| 2020 | This is Why We Can't Cache Nice Things: Lightning-Fast Threat Hunting using Suspicion-Based Hierarchical StorageabstractRecent advances in the causal analysis can accelerate incident response time, but only after a causal graph of the attack has been constructed. Unfortunately, existing causal graph generation techniques are mainly offline and may take hours or days to respond to investigator queries, creating greater opportunity for attackers to hide their attack footprint, gain persistency, and propagate to other machines. To address that limitation, we present Swift, a threat investigation system that provides high-throughput causality tracking and real-time causal graph generation capabilities. We design an in-memory graph database that enables space-efficient graph storage and online causality tracking with minimal disk operations. We propose a hierarchical storage system that keeps forensically-relevant part of the causal graph in main memory while evicting rest to disk. To identify the causal graph that is likely to be relevant during the investigation, we design an asynchronous cache eviction policy that calculates the most suspicious part of the causal graph and caches only that part in the main memory. We evaluated Swift on a real-world enterprise to demonstrate how our system scales to process typical event loads and how it responds to forensic queries when security alerts occur. Results show that Swift is scalable, modular, and answers forensic queries in real-time even when analyzing audit logs containing tens of millions of events. Wajih Ul Hassan, Ding Li 0001, Kangkook Jee, Xiao Yu 0007, Kexuan Zou, Zhengzhang Chen, Zhichun Li, Junghwan Rhee, Jiaping Gui, Adam Bates 0001 |
ACSAC | 1 |
| 2020 | On the Forensic Validity of Approximated Audit LogsabstractAuditing is an increasingly essential tool for the defense of computing systems, but the unwieldy nature of log data imposes significant burdens on administrators and analysts. To address this issue, a variety of techniques have been proposed for approximating the contents of raw audit logs, facilitating efficient storage and analysis. However, the security value of these approximated logs is difficult to measure—relative to the original log, it is unclear if these techniques retain the forensic evidence needed to effectively investigate threats. Unfortunately, prior work has only investigated this issue anecdotally, demonstrating sufficient evidence is retained for specific attack scenarios. Noor Michael, Jaron Mink, Jason Liu 0002, Sneha Gaur, Wajih Ul Hassan, Adam Bates 0001 |
ACSAC | 5 |
| 2020 | OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log Analysis
Wajih Ul Hassan, Mohammad A. Noureddine, Pubali Datta, Adam Bates 0001 |
NDSS | 1 |
| 2020 | Custos: Practical Tamper-Evident Auditing of Operating Systems Using Trusted Execution
Riccardo Paccagnella, Pubali Datta, Wajih Ul Hassan, Adam Bates 0001, Christopher W. Fletcher, Jing (Dave) Tian |
NDSS | 3 |
| 2020 | You Are What You Do: Hunting Stealthy Malware via Data Provenance Analysis
Qi Wang 0017, Wajih Ul Hassan, Ding Li 0001, Kangkook Jee, Xiao Yu 0007, Kexuan Zou, Junghwan Rhee, Zhengzhang Chen, Wei Cheng 0002, Carl A. Gunter |
NDSS | 2 |
| 2020 | Tactical Provenance Analysis for Endpoint Detection and Response SystemsabstractEndpoint Detection and Response (EDR) tools provide visibility into sophisticated intrusions by matching system events against known adversarial behaviors. However, current solutions suffer from three challenges: 1) EDR tools generate a high volume of false alarms, creating backlogs of investigation tasks for analysts; 2) determining the veracity of these threat alerts requires tedious manual labor due to the overwhelming amount of low-level system logs, creating a "needle-in-a-haystack" problem; and 3) due to the tremendous resource burden of log retention, in practice the system logs describing long-lived attack campaigns are often deleted before an investigation is ever initiated.This paper describes an effort to bring the benefits of data provenance to commercial EDR tools. We introduce the notion of Tactical Provenance Graphs (TPGs) that, rather than encoding low-level system event dependencies, reason about causal dependencies between EDR-generated threat alerts. TPGs provide compact visualization of multi-stage attacks to analysts, accelerating investigation. To address EDR's false alarm problem, we introduce a threat scoring methodology that assesses risk based on the temporal ordering between individual threat alerts present in the TPG. In contrast to the retention of unwieldy system logs, we maintain a minimally-sufficient skeleton graph that can provide linkability between existing and future threat alerts. We evaluate our system, RapSheet, using the Symantec EDR tool in an enterprise environment. Results show that our approach can rank truly malicious TPGs higher than false alarm TPGs. Moreover, our skeleton graph reduces the long-term burden of log retention by up to 87%. Wajih Ul Hassan, Adam Bates 0001, Daniel Marino |
SP | 1 |
| 2019 | NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage
Wajih Ul Hassan, Shengjian Guo, Ding Li 0001, Zhengzhang Chen, Kangkook Jee, Zhichun Li, Adam Bates 0001 |
NDSS | 1 |
| 2019 | How effective are existing Java API specifications for finding bugs during runtime verification?
Owolabi Legunsen, Nader Al Awar, Wajih Ul Hassan, Grigore Rosu, Darko Marinov |
Autom. Softw. Eng. | 4 |
| 2018 | Towards Scalable Cluster Auditing through Grammatical Inference over Provenance Graphs
Wajih Ul Hassan, Mark Lemay, Nuraini Aguse, Adam Bates 0001, Thomas Moyer |
NDSS | 1 |
| 2018 | Fear and Logging in the Internet of Things
Qi Wang 0017, Wajih Ul Hassan, Adam Bates 0001, Carl A. Gunter |
NDSS | 2 |
| 2018 | Analysis of Privacy Protections in Fitness Tracking Social Networks -or- You can run, but can you hide?
Wajih Ul Hassan, Saad Hussain, Adam Bates 0001 |
USENIX Security Symposium | 1 |
| 2017 | Don't cry over spilled records: Memory elasticity of data-parallel applications and its application to cluster scheduling
Calin Iorgulescu, Florin Dinu, Aunn Raza, Wajih Ul Hassan, Willy Zwaenepoel |
USENIX ATC | 4 |
| 2017 | Transparent Web Service Auditing via Network Provenance FunctionsabstractDetecting and explaining the nature of attacks in distributed web services is often difficult -- determining the nature of suspicious activity requires following the trail of an attacker through a chain of heterogeneous software components including load balancers, proxies, worker nodes, and storage services. Unfortunately, existing forensic solutions cannot provide the necessary context to link events across complex workflows, particularly in instances where application layer semantics (e.g., SQL queries, RPCs) are needed to understand the attack. In this work, we present a transparent provenance-based approach for auditing web services through the introduction of Network Provenance Functions (NPFs). NPFs are a distributed architecture for capturing detailed data provenance for web service components, leveraging the key insight that mediation of an application's protocols can be used to infer its activities without requiring invasive instrumentation or developer cooperation. We design and implement NPF with consideration for the complexity of modern cloud-based web services, and evaluate our architecture against a variety of applications including DVDStore, RUBiS, and WikiBench to show that our system imposes as little as 9.3% average end-to-end overhead on connections for realistic workloads. Finally, we consider several scenarios in which our system can be used to concisely explain attacks. NPF thus enables the hassle-free deployment of semantically rich provenance-based auditing for complex applications workflows in the Cloud. Adam Bates 0001, Wajih Ul Hassan, Kevin R. B. Butler, Alin Dobra, Bradley Reaves, Patrick T. Cable II, Thomas Moyer, Nabil Schear |
WWW | 2 |
| 2016 | How good are the specs? a study of the bug-finding effectiveness of existing Java API specificationsabstractRuntime verification can be used to find bugs early, during software development, by monitoring test executions against formal specifications (specs). The quality of runtime verification depends on the quality of the specs. While previous research has produced many specs for the Java API, manually or through automatic mining, there has been no large-scale study of their bug-finding effectiveness. Owolabi Legunsen, Wajih Ul Hassan, Grigore Rosu, Darko Marinov |
ASE | 2 |