Skip to content

Diagnosing Programmable Data Plane Attacks with Provenance Observability

· 0 citations · 85 references

TL;DR

This work presents ProvP4, a provenance-based cross-plane observer designed to observe and analyze stateful data plane attacks in programmable networks, and demonstrates that ProvP4 imposes minimal overhead in terms of storage and performance, while significantly enhancing security analysis capabilities.

View source

Similar papers

Preprint Aug 2026

A Study of Kernel Telemetry Options for Security-Oriented Provenance

Provenance aims to capture the origins, transformations, and interactions of system objects for security and forensic applications. Existing provenance capture approaches still face major challenges and are not yet ready for production environments. In this paper, we first analyze the main kernel telemetry capture approaches, identifying eBPF as the most promising, and complement this analysis with micro benchmarks to assess its performance overhead and the filtering mechanisms used to achieve capture granularity, such as restricting capture to individual containers. Building on this foundation, we then classify, according to the studied capture approaches and filtering methods, eight provenance systems and five capture agents that could serve as their capture layers, collectively referred to as tools. Our study reveals that these tools are built on highly heterogeneous capture layers, most of which cannot guarantee the integrity and availability of the captured events, completely failing to meet the requirements of security-oriented use cases.

Paul R. B. Houssel, Olivier Levillain, Sylvie Laniepce et al. · 0 citations
Preprint Aug 2026

Improving the Security of Containerized Workloads using Transparency and Traceability Services

This paper presents an architecture for verifiable container image distribution that addresses key-management challenges and enables policy-enforced admission-time verification, and implements a proof-of-concept integrated with GitHub Actions and GitLab Runners that mitigates common supply-chain attacks under a realistic threat model.

N. Fotiou, Lefteris Georgiadis, Ignacio Lacalle et al. · 0 citations
Open access 2026

Automated & Real-Time Privacy Quantification for Microservices Architectures

: The decentralized nature of microservice architectures introduces privacy challenges that exceed the capabilities of traditional static auditing. To address this, we present a real-time privacy quantification framework based on the Privacy-sensitive Data Categorization (PsDC) model. By combining Layer 7 Deep Packet In-spection (DPI) with Natural Language Processing (NLP), our methodology continuously inspects the semantic intent of network payloads. We introduce the Privacy Exposure Index (PEI), a dynamic risk metric that links the detection of sensitive entities directly with their operational context. We validated this approach in a Ku-bernetes environment using a custom ingestion engine and analyzer. Experimental results show high fidelity in identifying complex threats, including DNS-based data exfiltration, and successfully isolated high-risk service interactions with localized PEI scores of 5.32. Ultimately, this work establishes a foundation for a proactive DevPrivOps lifecycle, demonstrating that semantic-aware observability can replace manual privacy checks and act as the core decision engine for active privacy enforcement.

Catarina Silva, Bernardo Falé, Paulo Barraca et al. · 0 citations
Open access Sep 2026

Playbook-Guided Executable SOC Automation for Privacy-Preserving Response in Distributed Networked Systems

INTRODUCTION: Distributed networks require security operations center (SOC) automation that connects data security monitoring, privacy-aware evidence handling, controlled execution, and measurable evidence. Static playbooks cannot fully handle ambiguous cross-domain incident context. OBJECTIVES: This paper presents an executable multi-agent framework for data security monitoring and response in distributed networks. METHODS: LLM-based roles generate event analysis, tasks, actions, commands, execution records, and summaries. Security orchestration, automation, and response (SOAR) playbooks and a virtual security capability layer provide controlled execution and repeatable evaluation. RESULTS: On 83 labeled incidents, the framework achieved 0.9684 precision, 0.4742 recall, 0.6367 F1-score, and 76.45 s average handling time for tool-call evaluation. CONCLUSION: The framework makes distributed data-security response auditable and quantitatively evaluable. The main improvement direction is stronger planning verification for complex multi-step incidents.

Jie Zhang, Hai-Zhuang Liu, Le Ren et al. · 0 citations
Open access Aug 2026

Security and Privacy Controls in Ingestion Pipelines (PII masking, Encryption, Access Governance)

The use of high-throughput data ingestion pipelines that can constantly amass and process data collected by heterogeneous sources into a centralized or distributed data storage system is increasingly becoming the cornerstone of modern enterprise data ecosystems. Since these pipelines handle delicate personally identifiable information (PII) and financial data, healthcare data, and proprietary telemetry, it has become a critical concern of organizations that have to work within high regulatory standards, including GDPR, HIPAA, and CCPA, to guarantee high-quality security and privacy controls through all ingestion phases. Formal comparison with the Apache Kafka and Apache Spark-based pipeline deployments shows that the suggested framework yields an overhead of the throughput no more than 7.3% and offers extensive coverage of PII protection and role-based access control. These findings suggest that appropriately designed security controls can be integrated into production ingestion pipelines without degrading the performance of those pipelines materially, disproving the long-standing belief that there is an inherent trade-off between the security of data and the operation of pipelines.

Shreyansh Sharma · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.