遇见数据集

A Dataset of Kernel Exploits Represented as System Provenance Graphs

收藏
Zenodo2025-04-15 更新2026-05-26 收录
官方服务:

资源简介:

CONTEXTS Dataset (A Dataset of Kernel Exploits Represented as Provenance Graphs) This repository contains different datasets generated and used for testing CONTEXTS[1]. The datasets are in the form of provenance graphs captured by SPADE during system execution. Each dataset contains the exploitation of kernel vulnarabilities, where - All the provenance graphs are initially pruned based on the Initiall Pruning step of CONTEXTS.- The identified Point-of-Interest, Waypoints, and the Ground Truth are annotated on the provenance graph using POI, WP, and GT tags, respectively.- For each dataset, the query that is generated by CONTEXTS is provided. [1] Sareh Mohammadi, Hugo Kermabon-Bobinnec, Azadeh Tabiban, Lingyu Wang, Tomás Navarro Múnera, Yosr Jarraya, ***"CONnecting The EXtra doTS (CONTEXTS): Correlating External Information about Point of Interest for Attack Investigation."*** in IEEE Symposium on Security and Privacy (S&P), 2025.

CONTEXTS数据集(以溯源图(provenance graph)形式呈现的内核漏洞利用数据集) 本仓库包含为测试CONTEXTS[1]而生成并使用的多组数据集。这些数据集采用系统执行期间由SPADE捕获的溯源图形式。每组数据集均包含内核漏洞利用场景,具体如下: - 所有溯源图均首先基于CONTEXTS的初始剪枝步骤完成剪枝处理; - 已识别的兴趣点(Point-of-Interest)、航路点(Waypoints)与真实标签(Ground Truth)将分别通过POI、WP、GT标签标记于溯源图中; - 每组数据集均附带CONTEXTS生成的查询语句。 [1] Sareh Mohammadi、Hugo Kermabon-Bobinnec、Azadeh Tabiban、Lingyu Wang、Tomás Navarro Múnera、Yosr Jarraya:《CONnecting The EXtra doTS (CONTEXTS):关联兴趣点外部信息以开展攻击溯源》,发表于IEEE安全与隐私研讨会(S&P),2025年。

提供机构:
Zenodo
创建时间:
2025-04-09
二维码
社区交流群
二维码
科研交流群
商业服务