DOE OSTI · 2311396
ProvSec: Open Cybersecurity System Provenance Analysis Benchmark Dataset with Labels
Abstract
System provenance forensic analysis has been studied by a large body of research work. This area needs fine granularity data such as system calls along with event fields to track the dependencies of events. While prior work on security datasets has been proposed, we found a useful dataset of realistic attacks and details that are needed for high-quality provenance tracking is lacking. We created a new dataset of eleven vulnerable cases for system forensic analysis. It includes the full details of system calls including syscall parameters. Realistic attack scenarios with real software vulnerabilities and exploits are used. For each case, we created two sets of benign and adversary scenarios which are manually labeled for supervised machine-learning analysis. In addition, we present an algorithm to improve the data quality in the system provenance forensic analysis. We demonstrate the details of the dataset events and dependency analysis of our dataset cases.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Shrestha, Madhukar, Kim, Yonghyun, Oh, Jeehyun, Rhee, Junghwan, Choe, Yung Ryn, Zuo, Fei, Park, Myungah, Qian, Gang. 2023-11-15. ProvSec: Open Cybersecurity System Provenance Analysis Benchmark Dataset with Labels. https://doi.org/10.1007/s44227-023-00014-9
Cite the original work for its findings. Save a collection to share your selection of sources.