{"id":"https://openalex.org/W2213728018","doi":"https://doi.org/10.1145/2818000.2818039","title":"Accurate, Low Cost and Instrumentation-Free Security Audit Logging for Windows","display_name":"Accurate, Low Cost and Instrumentation-Free Security Audit Logging for Windows","publication_year":2015,"publication_date":"2015-12-07","ids":{"openalex":"https://openalex.org/W2213728018","doi":"https://doi.org/10.1145/2818000.2818039","mag":"2213728018"},"language":"en","primary_location":{"id":"doi:10.1145/2818000.2818039","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2818000.2818039","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101594068","display_name":"Shiqing Ma","orcid":"https://orcid.org/0000-0003-1551-8948"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Shiqing Ma","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033440818","display_name":"Kyu Hyoung Lee","orcid":"https://orcid.org/0000-0001-6843-6706"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kyu Hyung Lee","raw_affiliation_strings":["University of Georgia"],"affiliations":[{"raw_affiliation_string":"University of Georgia","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101947406","display_name":"Chung Hwan Kim","orcid":"https://orcid.org/0000-0002-0985-8439"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chung Hwan Kim","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054561146","display_name":"Junghwan Rhee","orcid":"https://orcid.org/0000-0002-4043-9371"},"institutions":[{"id":"https://openalex.org/I4210107353","display_name":"NEC (United States)","ror":"https://ror.org/01v791m31","country_code":"US","type":"company","lineage":["https://openalex.org/I118347220","https://openalex.org/I4210107353"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Junghwan Rhee","raw_affiliation_strings":["NEC Laboratories America"],"affiliations":[{"raw_affiliation_string":"NEC Laboratories America","institution_ids":["https://openalex.org/I4210107353"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107249133","display_name":"Xiangyu Zhang","orcid":"https://orcid.org/0000-0002-9544-2500"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiangyu Zhang","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5108280598","display_name":"Dongyan Xu","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dongyan Xu","raw_affiliation_strings":["Purdue University"],"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5101594068"],"corresponding_institution_ids":["https://openalex.org/I219193219"],"apc_list":null,"apc_paid":null,"fwci":5.9908,"has_fulltext":false,"cited_by_count":81,"citation_normalized_percentile":{"value":0.96586719,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"401","last_page":"410"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7503977417945862},{"id":"https://openalex.org/keywords/audit","display_name":"Audit","score":0.6265587210655212},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.6179623603820801},{"id":"https://openalex.org/keywords/instrumentation","display_name":"Instrumentation (computer programming)","score":0.5434885025024414},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.5147459506988525},{"id":"https://openalex.org/keywords/tracing","display_name":"Tracing","score":0.467936247587204},{"id":"https://openalex.org/keywords/logging","display_name":"Logging","score":0.4551647901535034},{"id":"https://openalex.org/keywords/accounting","display_name":"Accounting","score":0.10883739590644836}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7503977417945862},{"id":"https://openalex.org/C199521495","wikidata":"https://www.wikidata.org/wiki/Q181487","display_name":"Audit","level":2,"score":0.6265587210655212},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.6179623603820801},{"id":"https://openalex.org/C118530786","wikidata":"https://www.wikidata.org/wiki/Q1134732","display_name":"Instrumentation (computer programming)","level":2,"score":0.5434885025024414},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5147459506988525},{"id":"https://openalex.org/C138673069","wikidata":"https://www.wikidata.org/wiki/Q322229","display_name":"Tracing","level":2,"score":0.467936247587204},{"id":"https://openalex.org/C125620115","wikidata":"https://www.wikidata.org/wiki/Q845249","display_name":"Logging","level":2,"score":0.4551647901535034},{"id":"https://openalex.org/C121955636","wikidata":"https://www.wikidata.org/wiki/Q4116214","display_name":"Accounting","level":1,"score":0.10883739590644836},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.0},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/2818000.2818039","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2818000.2818039","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st Annual Computer Security Applications Conference","raw_type":"proceedings-article"},{"id":"pmh:oai:alma.01RUT_INST:11695743850004646","is_oa":false,"landing_page_url":"https://scholarship.libraries.rutgers.edu/esploro/outputs/conferencePaper/Accurate-low-cost-and-instrumentation-free-security/991031794684104646","pdf_url":null,"source":{"id":"https://openalex.org/S4210197018","display_name":"View","issn_l":"2688-268X","issn":["2688-268X","2688-3988"],"is_oa":false,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310320595","host_organization_name":"Wiley","host_organization_lineage":["https://openalex.org/P4310320595"],"host_organization_lineage_names":["Wiley"],"type":"journal"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference Paper"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6399999856948853,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320307791","display_name":"Cisco Systems","ror":"https://ror.org/03yt1ez60"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":30,"referenced_works":["https://openalex.org/W47175211","https://openalex.org/W596492259","https://openalex.org/W1499241274","https://openalex.org/W1563576199","https://openalex.org/W1683791865","https://openalex.org/W1858703999","https://openalex.org/W1956767865","https://openalex.org/W1987837522","https://openalex.org/W2039157918","https://openalex.org/W2093406244","https://openalex.org/W2096347345","https://openalex.org/W2102970979","https://openalex.org/W2103499520","https://openalex.org/W2108747667","https://openalex.org/W2112127916","https://openalex.org/W2122672392","https://openalex.org/W2133089788","https://openalex.org/W2142753309","https://openalex.org/W2144801589","https://openalex.org/W2150990363","https://openalex.org/W2151135920","https://openalex.org/W2152582571","https://openalex.org/W2159357881","https://openalex.org/W2162765234","https://openalex.org/W2293351723","https://openalex.org/W2295705535","https://openalex.org/W2394543764","https://openalex.org/W2397699236","https://openalex.org/W4245671428","https://openalex.org/W4255411440"],"related_works":["https://openalex.org/W2350278424","https://openalex.org/W2071432835","https://openalex.org/W4239401009","https://openalex.org/W4234371507","https://openalex.org/W1628824497","https://openalex.org/W4299534542","https://openalex.org/W2053441600","https://openalex.org/W1990401748","https://openalex.org/W2047586841","https://openalex.org/W2141018266"],"abstract_inverted_index":{"Audit":[0],"logging":[1,13,33],"is":[2,51,61],"an":[3],"important":[4],"approach":[5],"to":[6,84,88,108],"cyber":[7],"attack":[8,111],"investigation.":[9],"However,":[10],"traditional":[11],"audit":[12,32],"either":[14],"lacks":[15],"accuracy":[16,37],"or":[17],"requires":[18],"expensive":[19],"and":[20,38,73,113],"complex":[21],"binary":[22],"instrumentation.":[23],"In":[24],"this":[25],"paper,":[26],"we":[27],"propose":[28],"a":[29,79,94],"Windows":[30,67],"based":[31],"technique":[34,60],"that":[35],"features":[36],"low":[39],"cost.":[40],"More":[41],"importantly,":[42],"it":[43],"does":[44],"not":[45],"require":[46],"instrumenting":[47],"the":[48,99],"applications,":[49],"which":[50],"critical":[52,74],"for":[53,66],"commercial":[54],"software":[55],"with":[56],"IP":[57],"protection.":[58],"The":[59],"build":[62],"on":[63],"Event":[64],"Tracing":[65],"(ETW).":[68],"By":[69],"analyzing":[70],"ETW":[71,86],"log":[72,87,116],"parts":[75],"of":[76],"application":[77],"executables,":[78],"model":[80],"can":[81],"be":[82],"constructed":[83],"parse":[85],"units":[89],"representing":[90],"independent":[91],"sub-executions":[92],"in":[93],"process.":[95],"Causality":[96],"inferred":[97],"at":[98],"unit":[100],"level":[101],"renders":[102],"much":[103],"higher":[104],"accuracy,":[105],"allowing":[106],"us":[107],"perform":[109],"accurate":[110],"investigation":[112],"highly":[114],"effective":[115],"reduction.":[117]},"counts_by_year":[{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":7},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":5},{"year":2021,"cited_by_count":12},{"year":2020,"cited_by_count":15},{"year":2019,"cited_by_count":5},{"year":2018,"cited_by_count":12},{"year":2017,"cited_by_count":3},{"year":2016,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
