A Dataset of Kernel Exploits Represented as System Provenance Graphs
收藏资源简介:
CONTEXTS Dataset (A Dataset of Kernel Exploits Represented as Provenance Graphs) This repository contains datasets generated and used for testing CONTEXTS [1]. The datasets are in the form of provenance graphs captured by SPADE during system execution. The dataset includes the exploitation of kernel vulnerabilities, where: All provenance graphs are initially pruned based on the Initial Pruning step of CONTEXTS. The identified Points of Interest, Waypoints, and Ground Truth are annotated on the provenance graph using the tags POI, WP, and GT, respectively. For each dataset, the query generated by CONTEXTS is provided. [1] Sareh Mohammadi, Hugo Kermabon-Bobinnec, Azadeh Tabiban, Lingyu Wang, Tomás Navarro Múnera, Yosr Jarraya, "CONnecting The EXtra doTS (CONTEXTS): Correlating External Information about Point of Interest for Attack Investigation." in IEEE Symposium on Security and Privacy (S&P), 2025.
CONTEXTS数据集(以溯源图(provenance graphs)形式呈现的内核漏洞利用数据集) 本仓库包含为测试CONTEXTS所生成并使用的数据集[1]。该数据集采用系统执行期间由SPADE捕获的溯源图格式存储,涵盖内核漏洞利用场景,具体如下: 所有溯源图均先基于CONTEXTS的初始剪枝步骤完成预处理剪枝。已识别的兴趣点(Points of Interest)、途经点(Waypoints)与基准真值(Ground Truth)已分别通过POI、WP、GT标签标注至各溯源图中。针对每份数据集,均附带CONTEXTS生成的查询语句。 [1] Sareh Mohammadi、Hugo Kermabon-Bobinnec、Azadeh Tabiban、Lingyu Wang、Tomás Navarro Múnera、Yosr Jarraya:《CONnecting The EXtra doTS(CONTEXTS):关联兴趣点外部信息以开展攻击溯源调查》,发表于IEEE安全与隐私研讨会(IEEE Symposium on Security and Privacy,简称S&P),2025年。



