Skip to content
Conference

Automated Attack Trace Generation: Investigating Coverage and Cleanup Resilience

Jul 2026 · Annual International Computer Software and Applications Conference · pp. 2766-2773 · 0 citations · 21 references
Computer Science

Abstract

Attack trace datasets reflecting each organization's network and device configuration are essential for evaluating detection rules and incident response procedures, yet generalized datasets abstract such configurations away. To address this, we proposed a method that automatically selects, executes, and collects traces from feasible MITRE ATT&CK techniques within an operator-prepared virtual environment. However, its prototype collected only file differences and the Target's standard event logs, and did not account for volatile or post-cleanup traces. In this paper, we extend the trace collection mechanism with file-I/O API hooks and router-side communication log collection, and systematically evaluate the 747 Atomic Red Team techniques applicable to our experimental environment, quantifying per tactic and per log source the trace evidence captured before and after attacker cleanup. Approximately 86% of techniques were executable to completion, and traces remained after cleanup for about 76% of the executable techniques (rising to 83% under full-traffic logging). The resulting per-tactic, per-source coverage characterization provides a baseline for optimizing organizational monitoring configurations and prioritizing incident response.

View source

Similar papers

Jul 2026

Stack integrity for practical code-reuse attack defense

StackPatroller is proposed, a stack-integrity-based runtime supervision framework that enforces program integrity through configurable policies that monitors runtime stack contexts to detect early deviations from normal execution, enabling the identification of whole-function reuse and certain forward-edge attacks earl...

Yuanheng Xu, Si-Yu Zhang, Juan Wang et al. · 0 citations
Preprint Jul 2026

ContainmentBench: Trace-Based Evaluation of Post-Exposure Containment in Tool-Using LLM Agents

ContainmentBench, a sandboxed benchmark comprising a 504-scenario specification dataset, a shared rollout-trace schema, and stage-scoped metrics for endpoint violations, logged propagation, and explicitly authorized taint-exposed proposals that commit, is introduced.

Wen-Hao Lan, Shan Li, Meiqi Wu et al. · 0 citations
#machine learning Preprint Aug 2026

How Benchmarks and Evaluation Protocols Shape Conclusions in Provenance-Based Intrusion Detection

Provenance-based intrusion detection systems (PIDS) frequently report strong performance, but the conclusions drawn from these results can be highly sensitive to benchmarking choices and evaluation protocols. We investigate this dependency by re-evaluating representative PIDS on public datasets that meet our audit, lab...

Lorenzo Guerra, Thomas Chapuis, Guillaume Duc et al. · 0 citations
Jul 2026

FlowGuard: From Signals to Evidence for MCP Security Detection

Results show that evidence-grounded detection can assess both execution-related and semantic risks in MCP interactions, and compared with existing dynamic scanners, FlowGuard reduces end-to-end latency by up to 2.23x.

Baichao An, Pei Chen, Geng Hong et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.