Modeling System Activity Logging for Evidence Collection
ABSTRACT
System activity logs create an ongoing history of chronologically ordered records that describe events taking place in a computing system. Although system activity logs were originally designed for performance monitoring and troubleshooting, they can be used to collect forensic evidence. This paper develops a generic ‘technology-independent’ model of an event reporting service. The paper finds three key features that determine data collection capability – ‘event detection’, ‘event selection’ and ‘event description’. Design constraints in each of these features typically found in mainstream operating systems are identified and the limitations imposed on the forensic evidence collection capability of modern operating systems are discussed.
AUTHORS
Department of Computing and Information Systems,University of Melbourne,
Australia
Atif Ahmad is an information security researcher and independent security consultant based at the Department of Information Systems, University of Melbourne. His research interests are in asymmetric warfare and information security risk assessments especially where knowledge artefacts are concerned. In previous years Atif has worked as a consultant for Pinkerton and WorleyParsons where he applied his expertise to Internet corporations and critical infrastructure installations. Atif is a Board Certified Protection Professional (CPP) with the American Society for Industrial Security and holds an adjunct position at the Security Research Institute at Edith Cowan University.
School of Information Systems, Deakin University,
Australia
Anthonie Ruighaver is an Honorary Fellow at Deakin University in the School of Information Systems in the Faculty of Business and Law. He is a regular contributor to the Information Security Research Group. Previously he was the head of the Computer Security and Forensics Group based at the University of Melbourne. He was the coordinator of an E-crime course conducted as part of a collaboration between Melbourne University and Victoria Police. Dr. Ruighaver's primary interests are in Security Governance and Computer Forensics.
Published In
Journal of Information Warfare
The definitive publication for the best and latest research and analysis on information warfare, information operations, and cyber crime. Available in traditional hard copy or online.
Quick Links
Archive