Forensic analysis of file system intrusions using improved backtracking

Forensic analysis of file system intrusions using improved backtracking
复制标题

DOI:
10.1109/iwia.2005.9
复制
发表时间:
2005-03
期刊:
Third IEEE International Workshop on Information Assurance (IWIA'05)
影响因子:
--
通讯作者:
Sriranjani Sitaraman;S. Venkatesan
Sriranjani Sitaraman;S. Venkatesan
中科院分区:
其他
文献类型:
--
作者:
Sriranjani Sitaraman;S. Venkatesan

文献摘要

被引文献

相似文献

入侵检测系统提醒系统管理员入侵,但在大多数情况下,不提供有关哪些系统事件与入侵相关以及系统事件如何相关的详细信息。我们考虑文件系统的入侵。现有的工具,如BackTracker,通过提供包含可能与检测点相关的各种文件和进程之间的依赖关系信息的图形,帮助系统管理员从检测点(即具有可疑内容的文件)回溯到入侵的可能入口点。我们通过在正常操作(实时)期间记录文件系统的某些附加参数并在分析阶段检查记录的信息来改进这种回溯技术。此外,我们在与入侵相关的进程中使用了Cashlow分析来从依赖图中修剪不需要的路径。这导致搜索空间、搜索时间和误报的显著减少。我们还分析了存储空间和搜索时间方面所需的努力。
Intrusion detection systems alert the system administrators of intrusions but, in most cases, do not provide details about which system events are relevant to the intrusion and how the system events are related. We consider intrusions of file systems. Existing tools, like BackTracker, help the system administrator backtrack from the detection point, which is a file with suspicious contents, to possible entry points of the intrusion by providing a graph containing dependency information between the various files and processes that could be related to the detection point. We improve such backtracking techniques by logging certain additional parameters of the file system during normal operations (real-time) and examining the logged information during the analysis phase. In addition, we use dataflow analysis within the processes related to the intrusion to prune unwanted paths from the dependency graph. This results in significant reduction in search space, search time, and false positives. We also analyze the effort required in terms of storage space and search time.