DocumentCode :
3404165
Title :
A Method for Historical Ext3 Inode to Filename Translation on Honeypots
Author :
Fairbanks, Kevin D. ; Xia, Ying H. ; Owen, Henry L., III
Author_Institution :
Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
Volume :
2
fYear :
2009
fDate :
20-24 July 2009
Firstpage :
392
Lastpage :
397
Abstract :
In an environment where computer compromises are no longer anomalies, but are frequent occurrences, the field of computer forensics has increasingly gained importance. The development of this forensic field is matched by a growth in anti-forensic techniques. To overcome potential difficulties with external applications, operating systems should contain methods for storing and protecting meaningful information. The Linux Ext3 journal is one source of information that should be fully utilized for its intended purpose and forensics as well. However, due to its limited size and circular nature, this source of information has restrictions that can be addressed by the operating system. For example, when collecting and examining Ext3 journal data, it can be difficult to determine the filename that an inode number is associated with. In this paper, the design of a method for honeypots is presented which takes advantage of the virtual file system layer in Linux to address this difficulty. This technique allows the translation of inode numbers to filenames in a historical context thereby providing a forensic analyst with a better picture of what has transpired.
Keywords :
Linux; file organisation; forensic science; security of data; Linux Ext3 journal; antiforensic techniques; computer forensics; filename translation; historical Ext3 inode; honeypots; meaningful information protection; meaningful information storing; operating systems; virtual file system layer; Application software; Computer applications; Software debugging; Dentry; Ext3; File System; Forensics; Inode; TimeKeeper; Virtual File System (VFS);
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
Conference_Location :
Seattle, WA
ISSN :
0730-3157
Print_ISBN :
978-0-7695-3726-9
Type :
conf
DOI :
10.1109/COMPSAC.2009.165
Filename :
5254058
Link To Document :
بازگشت