DFS3: automated distributed file system storage state reconstruction

DFS3: automated distributed file system storage state reconstruction
复制标题

DFS3:自动化分布式文件系统存储状态重建

DOI:
10.1145/3407023.3407056
复制
发表时间:
2020
期刊:
Reliability and Security
影响因子:
--
通讯作者:
Glisson, William
Glisson, William
中科院分区:
--
文献类型:
--
作者:
Harshany, Edward;Benton, Ryan;Bourrie, David;Black, Michael;Glisson, William

文献摘要

参考文献

相似文献

与传统的本地挂载文件系统卷相比,分布式文件系统提出了独特的取证挑战。存储设备介质可能数以千计,在这种情况下的取证调查需要量身定制的数据收集方法。Hadoop分布式文件系统(HFDS)产生并维护部分持久的元数据,这些元数据与集中式服务器上的逻辑卷、文件系统和文件地址一致。因此,本研究探讨使用残余的中央服务器的数字文物,以产生一个历史模型的分布式文件系统的可行性。历史模式为调查人员提供了一个低层次事件的高层次视角,以缩小调查过程的义务。该模型是通过文件系统基本数据结构的集合论关系生成的。将图论排序应用于事件以提供历史模型。研究的贡献是快速重建的HDFS存储状态转换生成系统事件的时间表,以取证评估HDFS属性与传统的低级别文件系统取证工具输出的概念相似。本研究的结果提供了一个原型工具,DFS 3,快速和非侵入性的数据存储状态时间轴重建在大数据分布式文件系统。
Distributed file systems present distinctive forensic challenges in comparison to traditional locally mounted file system volume. Storage device media can number in the thousands, and forensic investigations in this setting necessitate a tailored approach to data collection. The Hadoop Distributed File System (HFDS) produces and maintains partially persistent metadata that is pursuant with a logical volume, a file system, and file addresses on the centralized server. Hence, this research investigates the viability of using a residual central server digital artifact to generate a history model of the distributed file system. The history model affords an investigator a high-level perspective of low-level events to narrow investigative process obligations. The model is generated through set-theoretic relations of the file system essential data structure. Graph-theoretic ordering is applied to the events to provide a history model. The research contribution is a rapid reconstruction of the HDFS storage state transitions generating timelines for system events to forensically assess HDFS properties with conceptual similarity to traditional low-level file system forensic tool output. The results of this research provide a prototype tool, DFS3, for rapid and noninvasive data storage state timeline reconstruction in a big data distributed file system.
用于事件后时间线重建的机器学习
DOI: --
发表时间: 2006
期刊:
影响因子: --
作者:
Muhammad Naeem Khan;I. Wakeman
通讯作者: I. Wakeman
DOI: --
发表时间: 2012
期刊: Digital Investigation. The International Journal of Digital Forensics and Incident Response
影响因子: --
作者:
C. Hargreaves;Jonathan Patterson
通讯作者: Jonathan Patterson
小亚细亚的现代希腊语(续)
DOI: --
发表时间: --
影响因子: 0.1
作者:
R. M. Dawkins
通讯作者: R. M. Dawkins
用于快速取证分析的容器和虚拟机可视化
DOI: --
发表时间: 2020
期刊: Hawaii International Conference on System Sciences
影响因子: --
作者:
Jordan Shropshire;Ryan G. Benton
通讯作者: Ryan G. Benton
DFRWS 2020 EU e 第七届年度 DFRWS 欧洲大数据取证:Hadoop 3.2.0 重构
DOI: --
发表时间: --
期刊:
影响因子: --
作者:
Edward Harshany;Ryan Benton;David M. Bourrie;W. Glisson
通讯作者: W. Glisson