---
格式版本: 2
标题: "CUSTOS: Toward Forensic-Ready Zero Trust at the Capture-Containment Boundary"
原文链接: "https://arxiv.org/abs/2608.17068"
发布日期: "2026-08-17"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Mon, 17 Aug 2026 19:17:15 UTC (262 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:47:05+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:43:02+08:00"
入库时间: "2026-08-20T07:47:05.581Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=throughput&searchtype=all"
匹配关键词:
  - "throughput"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 5
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为零信任取证，与超节点/AI Rack/机柜级AI基础设施完全无关，属明显无关内容。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:52:40+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "该文提出CUSTOS，一种面向取证的零信任参考架构，以取证管理点（FMP）协调分层捕获、身份关联重建与受控调查访问。原型实测显示，网关哈希链记录决策仅增加1.9-3.0%吞吐成本；"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:24:45.729Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.17068"
---

## Computer Science > Cryptography and Security

## Title:CUSTOS: Toward Forensic-Ready Zero Trust at the Capture-Containment Boundary

Authors:[Avinash Srinivasan](https://arxiv.org/search/cs?searchtype=author&query=Avinash), [John Paramadilok](https://arxiv.org/search/cs?searchtype=author&query=Paramadilok,+J)

[View PDF](https://arxiv.org/pdf/2608.17068) [HTML (experimental)](https://arxiv.org/html/2608.17068v1)

> Abstract:Zero Trust (ZT) replaces implicit trust with continuous verification, but mutual TLS, ephemeral workloads, identity-centric control, and automated remediation reduce payload visibility, weaken IP-based attribution, and shrink the window for acquiring volatile evidence. We propose CUSTOS, a forensic-ready ZT reference architecture centered on a Forensic Management Point (FMP) that coordinates tiered capture, identity- and policy-linked reconstruction, telemetry orchestration, and ZT-controlled investigative access. We evaluate a composed, component-level prototype using a live enforcement gateway plus separate runtime and orchestrator experiments. An always-on decision record is captured and hash-chained on the gateway at a 1.9-3.0\\% throughput cost on in-process policy engines, preserving decision provenance outside the monitored workload under stated trust assumptions. Reactive checkpointing (about 65 ms) precedes seconds-scale defender-routed eviction but loses to unsequenced direct SIGKILL (about 9 ms), in-kernel enforcement, and adversarial self-destruction, producing the forensic shredder effect. On a real container, concurrent capture and SIGKILL recovered the planted secret in 0/1000 trials; sequencing SIGKILL behind the FMP barrier recovered it in 1000/1000. The primary integrated single-node Kubernetes race checkpoints an FMP-controlled process; container-memory capture is evaluated separately and was unavailable in the managed-Kubernetes configuration. Across five public benchmark datasets and a synthetic schema reference, identity-oriented telemetry populates 64-75\\% of the decision-record schema against 18-30\\% for network-oriented, while rate limiting bounds the full-memory admission ceiling. These results show that forensic-ready ZT requires both an always-on evidentiary floor and bounded reactive capture, while identifying where volatile evidence remains unrecoverable.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR) |
| ACM classes: | D.4.6; C.2.0 |
| Cite as: | [arXiv:2608.17068](https://arxiv.org/abs/2608.17068) \[cs.CR\] |
|  | (or [arXiv:2608.17068v1](https://arxiv.org/abs/2608.17068v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.17068](https://doi.org/10.48550/arXiv.2608.17068) |

## Submission history

From: Avinash Srinivasan \[[view email](https://arxiv.org/show-email/effb57b5/2608.17068)\]  
**\[v1\]** Mon, 17 Aug 2026 19:17:15 UTC (262 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.17068) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
