首页> 外文期刊>Digital investigation >Establishing forensics capabilities in the presence of superuser insider threats
【24h】

Establishing forensics capabilities in the presence of superuser insider threats

机译:在超级用户内幕威胁的存在下建立取证能力

获取原文
获取原文并翻译 | 示例
           

摘要

Insider threats are paving ways to the headlines of security articles and reports across the globe. It's a common practice across organizations to have designated employees as administrators with complete administrative or superuser capabilities for the IT infrastructure. In this paper, we argue that superusers with all the administrative and access control capabilities may escape from the scrutiny of forensic investigation and may also become a major obstacle in the process of evidence collection. Through this work, we open a discussion on forensic aspects of insider threats with a particular focus on superuser forensics. We identify the anti-forensic administrative privileges of the superusers and discuss the sheer forensic repercussions with the help of four generic insider threat cases. As our primary contribution, we identify and define the four important requirements for a superuser-immune solution. These requirements include denying and logical access to the potential forensic artifacts, timely synchronization and integrity of evidential artifacts, and ensuring the execution of legitimate code/service and notifi-cation capabilities. Based on the identified requirements, we propose a forensic compliant mechanism, "Log-of-logs server" to countermeasure the inherent anti-forensic capabilities of the superuser. We showcase that the proposed framework effectively helps in establishing forensic capabilities for super users. We also present the security analysis of our framework and discuss its forensic feasibility. (c) 2021 Elsevier Ltd. All rights reserved.
机译:内幕威胁正在铺平到全球安全文章的头条新闻和报告的方式。跨组织的常见做法是指定员工作为管理员,为IT基础架构提供完整的管理或超级用户功能。在本文中,我们认为超级用户拥有所有行政和访问控制能力可能逃离法医调查的审查,并且也可能成为证据收集过程中的主要障碍。通过这项工作,我们开展了关于Insider威胁的法医方面,特别关注超级用户取证。我们确定超级用户的反法医行政特权,并在四个通用内部威胁案件的帮助下讨论纯粹的法医反应。作为我们的主要贡献,我们识别并确定超人免疫解决方案的四个重要要求。这些要求包括否认和逻辑访问潜在的取证工件,及时同步和简正工件的完整性,并确保执行合法代码/服务和通知功能。根据所识别的要求,我们提出了一种法医兼容机制,“日志记录服务器”,以对策超级用户的固有反异常功能。我们展示了所提出的框架有效地帮助为超级用户建立取证功能。我们还提出了我们框架的安全分析,并讨论了其法医可行性。 (c)2021 elestvier有限公司保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号