首页> 外文期刊>Journal of Computational Methods in Sciences and Engineering >Enhancement of forensic capabilities of the linux kernel via file timestamp preservation
【24h】

Enhancement of forensic capabilities of the linux kernel via file timestamp preservation

机译:通过文件时间戳保存增强Linux内核的取证功能

获取原文
获取原文并翻译 | 示例

摘要

The National Institute of Standards and Technology [1] lists the importance of preservation of file time stamps for forensic and intrusion detection purposes. Most operating systems keep track of certain timestamps related to files, the most commonly used timestamps being modification, access, er, UNIX based Operating systems retain the last modification, last inode change, and last access times. This relates to the fact that operating systems only have the most recently updated file timestamp information, which along with any inaccuracies does not guarantee a successful recreation of timeline of events, for an effective incident response. This paper proposes a novel approach in terms of augmenting the core of pathname lookup operation in the LINUX kernel, towards accurate and authentic preservation of file time stamps of system wide critical files.
机译:美国国家标准技术研究院[1]列出了保存文件时间戳以进行法医和入侵检测的重要性。大多数操作系统都会跟踪与文件相关的某些时间戳,最常用的时间戳是修改,访问,基于UNIX的操作系统。操作系统会保留最后的修改,最后的inode更改和最后的访问时间。这与以下事实有关:操作系统仅具有最近更新的文件时间戳记信息,再加上任何不准确性,都不能保证成功地重新生成事件的时间轴,以实现有效的事件响应。本文针对增强LINUX内核中的路径名查找操作的核心,提出了一种新颖的方法,旨在准确,可靠地保存系统级关键文件的文件时间戳。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号