کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456599 695746 2007 18 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Run-time label propagation for forensic audit data
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Run-time label propagation for forensic audit data
چکیده انگلیسی

It is desirable to be able to gather more forensically valuable audit data from computing systems than is currently done or possible. This is useful for the analysis of events that took place on the system for the purpose of digital forensic investigations. In this paper we propose a mechanism that allows arbitrary meta-information bound to principals on a system to be propagated based on causality and influenced by information flow. We further discuss how to implement such a mechanism for the FreeBSD operating system and present a proof-of-concept implementation that has little overhead compared to the system without label propagation.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 26, Issues 7–8, December 2007, Pages 496–513
نویسندگان
, ,