Show simple item record

SealFS: Storage-Based Tamper-Evident Logging

dc.contributor.authorSoriano-Salvador, Enrique
dc.contributor.authorGuardiola Múzquiz, Gorka
dc.date.accessioned2023-11-10T10:39:04Z
dc.date.available2023-11-10T10:39:04Z
dc.date.issued2021
dc.identifier.citationEnrique Soriano-Salvador, Gorka Guardiola-Múzquiz, SealFS: Storage-based tamper-evident logging, Computers & Security, Volume 108, 2021, 102325, ISSN 0167-4048.es
dc.identifier.issn0167-4048
dc.identifier.urihttps://hdl.handle.net/10115/25800
dc.description.abstractLog analysis is essential for a forensic investigation. Upon intrusion, log files are usually forged in order to hide or fake evidence. If the system is completely compromised, malicious code can be executed in kernel or hypervisor mode making even signed log files vulnerable. As a countermeasure, some systems archive the log files on another system through the network. This solution is not always suitable or desirable and it just shifts the problem elsewhere. The log files need to be preserved on another networked machine which may itself be attacked. In this paper, we present a simple scheme to authenticate local log files based on a forward integrity model. The scheme is based on a realistic assumption: nowadays, storage is very cheap. We can authenticate the logged data generated, starting from boot time to the instant that the malicious code elevates privileges. This tamper-evident scheme does not depend on special security hardware or securing a distributed system. We also present a prototype implementation of this scheme, SealFS. Our implementation, which showcases this approach, is a novel stackable file system for Linux. It enables tamper-evident logging to all existing applications, provides backwards compatibility and instant deployability. Last, we present a performance evaluation of this prototype that shows the viability of this approach.
dc.language.isoenges
dc.publisherElsevieres
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subjectCybersecurityes
dc.subjectlogginges
dc.subjectfile systemes
dc.subjecttamper-evidentes
dc.subjectverificationes
dc.subjectauthenticationes
dc.subjectforensicses
dc.titleSealFS: Storage-Based Tamper-Evident Logginges
dc.typeinfo:eu-repo/semantics/articlees
dc.identifier.doi10.1016/j.cose.2021.102325es
dc.rights.accessRightsinfo:eu-repo/semantics/openAccesses


Files in this item

This item appears in the following Collection(s)

Show simple item record

Attribution-NonCommercial-NoDerivatives 4.0 InternacionalExcept where otherwise noted, this item's license is described as Attribution-NonCommercial-NoDerivatives 4.0 Internacional