首页> 外文期刊>Security and Communications Networks >BAFi: a practical cryptographic secure audit logging scheme for digital forensics
【24h】

BAFi: a practical cryptographic secure audit logging scheme for digital forensics

机译:BAFi:一种适用于数字取证的实用密码安全审计记录方案

获取原文
获取原文并翻译 | 示例

摘要

Audit logs provide information about historical states of computer systems. They also contain highly valuable data that can be used by law enforcement in forensic investigations. Thus, ensuring the authenticity and integrity of audit logs is of vital importance. An ideal security mechanism for audit logging must also satisfy security properties such as forward-security (compromise resiliency), compactness, and computational efficiency. Unfortunately, existing secure audit logging schemes lack the computational or storage efficiency for modern performance requirements. Indeed, the practicality of such schemes has not been investigated in real-life systems, where logs generated in various occasions could be terabytes of data per day. To address this limitation, we developed an efficient, publicly verifiable, forward-secure, privacy-preserving, and aggregate logging scheme called blind-aggregate-forward improved (BAFi). BAFi is based on BAF, with new properties and performance improvements as follows: (i) BAFi improves the efficiency of BAF via implementation specific optimizations; (ii) BAFi has the option to not expose sensitive information in logs to protect valuable forensic information; (iii) BAFi was experimentally tested in real-world logs; and (iv) BAFi improves the security of BAF against log substitution. Our analysis shows that BAFi outperforms previous alternatives with similar properties and therefore is an ideal solution for nowadays highly intense logging systems. Copyright (c) 2015John Wiley & Sons, Ltd.
机译:审核日志提供有关计算机系统历史状态的信息。它们还包含非常有价值的数据,可供执法部门用于法医调查。因此,确保审核日志的真实性和完整性至关重要。用于审核日志记录的理想安全机制还必须满足安全属性,例如前向安全性(危害弹性),紧凑性和计算效率。不幸的是,现有的安全审核日志记录方案缺乏满足现代性能要求的计算或存储效率。实际上,尚未在实际系统中研究过这种方案的实用性,在现实系统中,在各种情况下生成的日志每天可能是TB级数据。为了解决此限制,我们开发了一种有效的,可公开验证的,前向安全的,隐私保护的聚合日志记录方案,称为盲聚合改进(BAFi)。 BAFi基于BAF,具有以下新特性和性能改进:(i)BAFi通过特定于实现的优化来提高BAF的效率; (ii)BAFi可以选择不在日志中公开敏感信息,以保护宝贵的法医信息; (iii)BAFi已在真实日志中进行了实验测试; (iv)BAFi改进了BAF防止日志替换的安全性。我们的分析表明,BAFi的性能优于以前的同类产品,因此是当今高度密集的测井系统的理想解决方案。版权所有(c)2015 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号