Zero Trust (ZT) replaces implicit trust with continuous verification, but automated containment can destroy volatile evidence before preservation. We propose CUSTOS, a forensic-ready ZT reference architecture whose Forensic Management Point (FMP) links identity and policy context to tiered, rate-limited capture and orders volatile-state acquisition ahead of defender-routed destructive containment. In a controlled real-container experiment, the planted artifact was lost in all 1000 trials when capture and SIGKILL began concurrently, showing that the direct kill outran the evaluated acquisition path. The sequencing barrier completed capture before releasing that same kill in all 1000 trials. In a matched four-condition comparison, only sequencing recovered the transient artifact (200/200); a periodic snapshot-chain baseline recovered long-lived evidence (200/200) but missed the transient artifact at both cadences. Sequencing added 0.140 s of containment delay and 9.99 MB per event. At a 2 s cadence, the chain added no containment delay but suspended the workload for 4.9% of wall-clock and accrued 59.2 KB/s after its root snapshot. The always-on decision record reduced in-process request-path throughput by 1.9-3.0%. In-kernel enforcement and adversarial self-destruction bypass the sequencing barrier; CUSTOS preserves volatile state otherwise lost to defender-routed containment at measured cost.
翻译:暂无翻译