finds.dev← search

// the find

BasantaChaulagain/faseal

C · MIT · updated Mar 2026

An implementation of FA-SEAL: Forensically Analyzable Symmetric Encryption for Audit Logs. (ACSAC '24)

Research-grade implementation of FA-SEAL, a system from an ACSAC 2024 paper that lets you forensically query audit logs without decrypting the whole log — only the fields relevant to an attack trace get revealed. Aimed at security researchers or incident responders dealing with outsourced/cloud log storage where full log access to a third party is a non-starter, not at anyone wanting a drop-in logging tool.

Backed by a peer-reviewed paper with actual measured numbers (30GB/day in ~90 minutes on a single core, 0.68% data exposure), so the claims aren't just marketing copy. The client/server/investigator split matches the threat model directly — the server storing logs never needs to be trusted with plaintext. The `tracking/` component reuses established provenance-tracking primitives (forward/backward causality tracing over process/file dependency graphs) rather than inventing a new audit format from scratch.

Zero stars, zero forks, and a README that's mostly bullet points and emoji with the actual technical detail pushed into a separate instruction.md you have to go dig up. Codebase mixes Python (client/server) and C/C++ (tracking) with no visible test suite or CI, which is typical for a paper artifact but means you're on your own for correctness once you deviate from the exact experimental setup the authors ran. The tracking directory leans on bundled third-party headers (uthash.h, utlist.h) and raw syscall parsing (parse_sock.pl, bridge.c) that smell like it was lifted from prior audit-tracking research code — expect rough edges adapting it to a kernel/audit version it wasn't tested against.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →