Jul 2026· Annual International Computer Software and Applications Conference· pp. 2766-2773· 0 citations· 21 references
Computer Science
Abstract
Attack trace datasets reflecting each organization's network and device configuration are essential for evaluating detection rules and incident response procedures, yet generalized datasets abstract such configurations away. To address this, we proposed a method that automatically selects, executes, and collects traces from feasible MITRE ATT&CK techniques within an operator-prepared virtual environment. However, its prototype collected only file differences and the Target's standard event logs, and did not account for volatile or post-cleanup traces. In this paper, we extend the trace collection mechanism with file-I/O API hooks and router-side communication log collection, and systematically evaluate the 747 Atomic Red Team techniques applicable to our experimental environment, quantifying per tactic and per log source the trace evidence captured before and after attacker cleanup. Approximately 86% of techniques were executable to completion, and traces remained after cleanup for about 76% of the executable techniques (rising to 83% under full-traffic logging). The resulting per-tactic, per-source coverage characterization provides a baseline for optimizing organizational monitoring configurations and prioritizing incident response.
StackPatroller is proposed, a stack-integrity-based runtime supervision framework that enforces program integrity through configurable policies that monitors runtime stack contexts to detect early deviations from normal execution, enabling the identification of whole-function reuse and certain forward-edge attacks earl...
Yuanheng Xu, Si-Yu Zhang, Juan Wang et al.· Journal of computing and sec...· 0 citations
ContainmentBench, a sandboxed benchmark comprising a 504-scenario specification dataset, a shared rollout-trace schema, and stage-scoped metrics for endpoint violations, logged propagation, and explicitly authorized taint-exposed proposals that commit, is introduced.
Wen-Hao Lan, Shan Li, Meiqi Wu et al.· 0 citations
Provenance-based intrusion detection systems (PIDS) frequently report strong performance, but the conclusions drawn from these results can be highly sensitive to benchmarking choices and evaluation protocols. We investigate this dependency by re-evaluating representative PIDS on public datasets that meet our audit, lab...
Lorenzo Guerra, Thomas Chapuis, Guillaume Duc et al.· 0 citations
Results show that evidence-grounded detection can assess both execution-related and semantic risks in MCP interactions, and compared with existing dynamic scanners, FlowGuard reduces end-to-end latency by up to 2.23x.
Baichao An, Pei Chen, Geng Hong et al.· arXiv.org· 0 citations
The results show that build integration, not candidate generation or fuzzing, is the primary barrier to reliable LLM-assisted dynamic analysis of full autonomous-vehicle software stacks.
Overall, TraceGate shows that rethinking debugging through controlled observability, rather than relying solely on stronger models or larger prompts, can make LLM-assisted repair more effective, efficient and controllable.
Nicolas Schuler, MateVincenzoScotti, RaffaelaMirandola· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.