PANDAcap: A framework for streamlining collection of full-system traces

0Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Full-system, deterministic record and replay has proven to be an invaluable tool for reverse engineering and systems analysis. However, acquiring a full-system recording typically involves signifcant planning and manual effort. This represents a distraction from the actual goal of recording a trace, i.e. analyzing it. We present PANDAcap, a framework based on PANDA full-system record and replay tool. PANDAcap combines off-the-shelf and custom-built components in order to streamline the process of recording PANDA traces. More importantly, in addition to making the setup of one-off experiments easier, PANDAcap also caters to the streamlining of systematic repeatable experiments in order to create PANDA trace datasets. As a demonstration, we have used PANDAcap to deploy an ssh honeypot aiming to study the actions of brute-force ssh attacks.

Cite

CITATION STYLE

APA

Stamatogiannakis, M., Bos, H., & Groth, P. (2020). PANDAcap: A framework for streamlining collection of full-system traces. In Proceedings of the 13th European Workshop on Systems Security, EuroSec 2020 (pp. 1–6). Association for Computing Machinery, Inc. https://doi.org/10.1145/3380786.3391396

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free