University of Illinois Urbana-Champaign
Designing practical security systems via information flow analysis of log data
Abstract
dc:descriptionSecurity systems must fundamentally distinguish permissible behaviors from insecure, forbidden behaviors. At a system-wide level, this is achieved by defining allowable relationships between system subjects, such as users or services, and objects, such as files or sockets. However, security policies benefit greatly from knowledge of application-specific behaviors. For example, applications may define their own subjects, such as users in a web server, that are not visible at the system level. Processes can become compromised due to exploits, allowing attackers to execute code for their own purposes instead of the original program. Attacks may even involve processes that appear to be running the correct program on behalf of the correct user, but are nonetheless undesirable, such as compromises from phishing or other methods of credential theft. Overall, while security is often thought of in terms of application-specific behavior, program logic is not explicitly visible at the system level. In this dissertation, we make the key observation that although program logic is not visible at the system level, it is implicitly expressed through the information and control flows through processes that are visible. Therefore, by analyzing these information and control flows, we can design more accurate security systems that account for program-specific behavior. We explore three systems designed to leverage these flows. We design T-difc, an access control system that can transparently define application-specific policies at the system level without any additional instrumentation of programs. Next, using information and control flow analysis, we measure the variation and relationships between benign and attack program activity to contextualize the performance of state-of-the-art intrusion detection systems and explain why intrusion detection is still unsolved, contrary to their excellent evaluation results. Finally, we refine attack investigations to remove noise by heuristically using behaviors found through information and control flow analysis to ignore irrelevant flows. Our work demonstrates that information and control flow analysis is a viable method to infer program logic for practical security systems.
Degree
thesis:*- Name thesis:degree_name
- Ph.D.
- Level thesis:degree_level
- Dissertation
- Discipline thesis:degree_discipline
- Computer Science
- Grantor
- University of Illinois Urbana-Champaign
- Year dc:date
- 2025
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Liu, Jason
- Contributors dc:contributor
-
- Bates, Adam
- Wang, Gang
- Xu, Tianyin
- Traynor, Patrick
Subjects
dc:subject × 3Rights
dc:rights- Statement dc:rights
-
- Copyright 2025 Jason Liu
- Language dc:language
- en, eng
Identifiers
dc:identifier.*- Handle dc:identifier
- https://hdl.handle.net/2142/129924