CUSTOS: Toward Forensic-Ready Zero Trust at the Capture-Containment Boundary
Avinash Srinivasan, John Paramadilok
Abstract
Zero Trust (ZT) replaces implicit trust with continuous verification, but automated containment can destroy volatile evidence before preservation. We propose CUSTOS, a forensic-ready ZT reference architecture whose Forensic Management Point (FMP) links identity and policy context to tiered, rate-limited capture and orders volatile-state acquisition ahead of defender-routed destructive containment. In a controlled real-container experiment, the planted artifact was lost in all 1000 trials when capture and SIGKILL began concurrently, showing that the direct kill outran the evaluated acquisition path. The sequencing barrier completed capture before releasing that same kill in all 1000 trials. In a matched four-condition comparison, only sequencing recovered the transient artifact (200/200); a periodic snapshot-chain baseline recovered long-lived evidence (200/200) but missed the transient artifact at both cadences. Sequencing added 0.140 s of containment delay and 9.99 MB per event. At a 2 s cadence, the chain added no containment delay but suspended the workload for 4.9% of wall-clock and accrued 59.2 KB/s after its root snapshot. The always-on decision record reduced in-process request-path throughput by 1.9-3.0%. In-kernel enforcement and adversarial self-destruction bypass the sequencing barrier; CUSTOS preserves volatile state otherwise lost to defender-routed containment at measured cost.
Create a lesson
Related papers
Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs
Ramana Ranganatham, Chirag Adiga, Michael Zuzak et al.
Characterizing Network Centralization and Observability in the Remote MCP Ecosystem
Muhammad Abdullah Sohail
When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic
Muhammad Abdullah Sohail
Hamming Ideals and Grobner Bases for ISD-like Syndrome Decoding
Roberto La Scala, Marco Marchesin, Sharwan K. Tiwari
ASLEval: Measuring Privacy Exposure Displacement in LLM Agent Sessions
Guosen Wu, Huizhen Huang, Guoxiong Long et al.
CASHEWS: Source Preprocessor for LLM-based Malicious Package Detection
Jean-Charles Noirot Ferrand, David Adei, Anders Møller et al.