CamFlow / camflow-devLinks
Generates kernel patch for CamFlow Linux Provenance Capture.
☆27Updated last year
Alternatives and similar repositories for camflow-dev
Users that are interested in camflow-dev are comparing it to the libraries listed below
Sorting:
- ☆101Updated 4 years ago
- SPADE: Support for Provenance Auditing in Distributed Environments☆186Updated last month
- GraphChi's C++ version. Big Data - small machine.☆17Updated 4 years ago
- ☆14Updated 4 years ago
- Have fun with audit log analysis :)☆152Updated last year
- Material from the DARPA Transparent Computing Program☆207Updated 5 years ago
- GAINS: Getting stArted wIth biNary analysiS☆31Updated 3 years ago
- eAudit suite for recording provenance-related system calls on Linux☆13Updated 2 years ago
- Contextualizing System Calls in Containers for Anomaly-Based Intrusion Detection (CHIDS) - CCSW'22☆24Updated 2 years ago
- ☆11Updated 6 years ago
- PalanTír: Optimizing Attack Provenance with Hardware-enhanced System Observability, ACM CCS'22☆24Updated 11 months ago
- SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit Records, Oakland'22☆82Updated 2 years ago
- ☆28Updated 3 years ago
- This repository is used to analysis the shared resources of different containers☆31Updated 11 months ago
- System traces dataset generation tool.☆13Updated 3 years ago
- Datasets used in the StreamSpot experiments☆61Updated 9 years ago
- ☆72Updated 7 months ago
- ATLAS: A Sequence-based Learning Approach for Attack Investigation☆168Updated 3 years ago
- ☆16Updated last year
- ☆82Updated 2 years ago
- LID-DS is an intrusion detection data simulation framework.☆51Updated 4 months ago
- This tool set can generate required capabilities for binaries. A system call to capability mapping is used to assign capability to the bi…☆14Updated 2 years ago
- Discovering Malicious Functionality through Binary Reconstruction☆58Updated 4 years ago
- ☆20Updated 4 years ago
- ☆15Updated 4 years ago
- Towards the Detection of Inconsistencies in Public Security Vulnerability Reports☆75Updated 2 years ago
- Evading Provenance-Based ML Detectors with Adversarial System Actions☆33Updated last year
- Original implementation and resources of DeepCASE as in the S&P '22 paper☆95Updated 2 years ago
- A general cross-architecture C/C++ hotpatch solution using customized userspace eBPF runtime. One patch release can fix the same vulnera…☆26Updated last year
- Source code of AsiaCCS'22 paper - RecIPE: Revisiting the Evaluation of Memory Error Defenses☆13Updated 2 years ago