Xutong Chen

dblp:301/5879 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2022
0000-0001-9201-3893ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2022 Conan: A Practical Real-Time APT Detection System With High Accuracy and Efficiency
abstract
Advanced Persistent Threat (APT) attacks have caused serious security threats and financial losses worldwide. Various real-time detection mechanisms that combine context information and provenance graphs have been proposed to defend against APT attacks. However, existing real-time APT detection mechanisms suffer from accuracy and efficiency issues due to inaccurate detection models and the growing size of provenance graphs. To address the accuracy issue, we propose a novel and accurate APT detection model that removes unnecessary phases and focuses on the remaining ones with improved definitions. To address the efficiency issue, we propose a state-based framework in which events are consumed as streams and each entity is represented in an FSA-like structure without storing historic data. Additionally, we reconstruct attack scenarios by storing just one in a thousand events in a database. Finally, we implement our design, calledConan, on Windows and conduct comprehensive experiments under real-world scenarios to show thatConancan accurately and efficiently detect all attacks within our evaluation. The memory usage and CPU efficiency ofConanremain constant over time (1-10 MB of memory and hundreds of times faster than data generation), makingConana practical design for detecting both known and unknown APT attacks in real-world scenarios.
Chun-lin Xiong, Tiantian Zhu 0001, Weihao Dong, Linqi Ruan, Runqing Yang, Yueqiang Cheng, Yan Chen 0004, Xutong Chen
IEEE Trans. Dependable Secur. Comput.9
2022 RATScope: Recording and Reconstructing Missing RAT Semantic Behaviors for Forensic Analysis on Windows
abstract
Remote Access Trojan (RAT) attacks have become an extensively prevailing and serious threat to enterprise security. A forensic system targeting RAT attacks is needed to record and reconstruct fine-grained semantic behaviors of RATs. However, existing forensic systems suffer from various issues such as intrusive instrumentation, nontrivial recording overhead, and RAT behavior blindness. In this article, we first conduct a large-scale study of a representative set of real-world RAT families active from 1999 to 2016. This is the first study to understand the landscape of RATs in the literature. Based on the study, we then proposeRATScope, an instrumentation-free RAT forensic system targeting Windows platform. Specifically,RATScopeoffers an audit logging module to efficiently record system logs by leveraging Event Tracing for Windows (ETW), and provides a novel program behavior modeling technique to reconstruct semantic behaviors of RATs accurately. We implement a prototype ofRATScopeand evaluate the recording overhead and the behavior identification accuracy. The results show that the audit logging module only incurs 3.7 percent runtime overhead on average. Our system can achieve around 90 percent true positive rate in the cross-family experiment, around 80 percent true positive rate in the two-year spanning temporal experiment, and nearzerofalse positive rate.
Runqing Yang, Xutong Chen, Haitao Xu 0002, Yueqiang Cheng, Chun-lin Xiong, Linqi Ruan, Mohammad Kavousi, Zhenyuan Li, Liheng Xu, Yan Chen 0004
IEEE Trans. Dependable Secur. Comput.2
2021 CLARION: Sound and Clear Provenance Tracking for Microservice Deployments
Xutong Chen, Hassaan Irshad, Yan Chen 0004, Ashish Gehani, Vinod Yegneswaran
USENIX Security Symposium1