• DocumentCode
    3042584
  • Title

    Forensic analysis of compromised systems

  • Author

    Balaz, Anton ; Hlinka, R.

  • Author_Institution
    Dept. of Comput. & Inf., Tech. Univ. of Kosice, Kosice, Slovakia
  • fYear
    2012
  • fDate
    8-9 Nov. 2012
  • Firstpage
    27
  • Lastpage
    30
  • Abstract
    This article presents a study on whether and how may forensic analysis contribute to a compromised system. It explores the use of specific procedures for conducting security examinations of such a system, allowing gaining and store relevant evidence. Test results in laboratory-scale environment demonstrate the feasibility of performing general methods on live computer systems, operations systems in particular, all intended for the scale of forensic analyses. The study also weighs the relative contributions of possible forensic data sources which may a forensic analyst reveal throughout the analysis, especially important data obtained from operation systems Windows and Linux, whereby it is possible to extract valuable information. Finally, the exploratory activities result in the list of procedures applicable to Linux operating system that are seen to satisfy the security requirements for important data. The present study also intends to examine the mediating role of computer security as a process or mechanism by which to explain the relationship between forensic analysis and computing systems.
  • Keywords
    Linux; digital forensics; information retrieval; Linux; Windows; compromised systems; computer security; computer systems; data security requirements; forensic analysis; forensic data sources; information extraction; laboratory-scale environment; operation systems; security examinations; Computers; Digital forensics; Linux; Operating systems; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging eLearning Technologies & Applications (ICETA), 2012 IEEE 10th International Conference on
  • Conference_Location
    Stara Lesna
  • Print_ISBN
    978-1-4673-5120-1
  • Type

    conf

  • DOI
    10.1109/ICETA.2012.6418288
  • Filename
    6418288