SealFS: Storage-Based Tamper-Evident Logging

dc.contributor.authorSoriano-Salvador, Enrique
dc.contributor.authorGuardiola Múzquiz, Gorka
dc.date.accessioned2023-11-10T10:39:04Z
dc.date.available2023-11-10T10:39:04Z
dc.date.issued2021
dc.description.abstractLog analysis is essential for a forensic investigation. Upon intrusion, log files are usually forged in order to hide or fake evidence. If the system is completely compromised, malicious code can be executed in kernel or hypervisor mode making even signed log files vulnerable. As a countermeasure, some systems archive the log files on another system through the network. This solution is not always suitable or desirable and it just shifts the problem elsewhere. The log files need to be preserved on another networked machine which may itself be attacked. In this paper, we present a simple scheme to authenticate local log files based on a forward integrity model. The scheme is based on a realistic assumption: nowadays, storage is very cheap. We can authenticate the logged data generated, starting from boot time to the instant that the malicious code elevates privileges. This tamper-evident scheme does not depend on special security hardware or securing a distributed system. We also present a prototype implementation of this scheme, SealFS. Our implementation, which showcases this approach, is a novel stackable file system for Linux. It enables tamper-evident logging to all existing applications, provides backwards compatibility and instant deployability. Last, we present a performance evaluation of this prototype that shows the viability of this approach.
dc.identifier.citationEnrique Soriano-Salvador, Gorka Guardiola-Múzquiz, SealFS: Storage-based tamper-evident logging, Computers & Security, Volume 108, 2021, 102325, ISSN 0167-4048.es
dc.identifier.doi10.1016/j.cose.2021.102325es
dc.identifier.issn0167-4048
dc.identifier.urihttps://hdl.handle.net/10115/25800
dc.language.isoenges
dc.publisherElsevieres
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.accessRightsinfo:eu-repo/semantics/openAccesses
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subjectCybersecurityes
dc.subjectlogginges
dc.subjectfile systemes
dc.subjecttamper-evidentes
dc.subjectverificationes
dc.subjectauthenticationes
dc.subjectforensicses
dc.titleSealFS: Storage-Based Tamper-Evident Logginges
dc.typeinfo:eu-repo/semantics/articlees

Archivos

Bloque original

Mostrando 1 - 1 de 1
Cargando...
Miniatura
Nombre:
sealfs-repositorio.pdf
Tamaño:
575.67 KB
Formato:
Adobe Portable Document Format
Descripción:
article

Bloque de licencias

Mostrando 1 - 1 de 1
No hay miniatura disponible
Nombre:
license.txt
Tamaño:
2.67 KB
Formato:
Item-specific license agreed upon to submission
Descripción: