Title :
AccountabilityFS: A File System Monitor for Forensic Readiness
Author :
Nordvik, Rune ; Yi-Ching Liao ; Langweg, Hanno
Author_Institution :
Norwegian Inf. Security Lab., Gjovik Univ. Coll., Gjovik, Norway
Abstract :
We present a file system monitor, AccountabilityFS, which prepares an organization for forensic analysis and incident investigation in advance by ensuring file system operation traces readily available. We demonstrate the feasibility of AccountabilityFS in terms of performance and storage overheads, and prove its reliability against malware attacks.
Keywords :
digital forensics; invasive software; AccountabilityFS file system monitor; file system operation; forensic analysis; forensic readiness; malware attacks; performance overhead; storage overhead; Educational institutions; Forensics; Kernel; Malware; Monitoring; Reliability;
Conference_Titel :
Intelligence and Security Informatics Conference (JISIC), 2014 IEEE Joint
Conference_Location :
The Hague
Print_ISBN :
978-1-4799-6363-8
DOI :
10.1109/JISIC.2014.61