DocumentCode :
1376584
Title :
A System for Formal Digital Forensic Investigation Aware of Anti-Forensic Attacks
Author :
Rekhis, Slim ; Boudriga, Noureddine
Author_Institution :
Commun. Networks & Security Res. Lab., Univ. of Carthage, Ariana, Tunisia
Volume :
7
Issue :
2
fYear :
2012
fDate :
4/1/2012 12:00:00 AM
Firstpage :
635
Lastpage :
650
Abstract :
To defeat the process of investigation and make the analysis and reconstruction of attack scenarios difficult, challenging, or even impossible, attackers are motivated by conducting anti-forensic attacks. Several methods were proposed by the literature to formally reconstruct the sequence of events executed during the incident using theoretical and scientifically proven methods. However, these methods are not tailored to cope with anti-forensic attacks, as they assume that the collected evidence is trusted, do not model anti-forensic actions, and do not characterize provable anti-forensic attacks based on the knowledge of attacks, security solutions, and forms of evidence expected to be generated. We develop in this work a theoretical approach of digital investigation aware of anti-forensic attacks. After describing an investigation process which is able to address these attacks, we develop a state-based logic to describe the investigated system, the deployed security solution, the evidence they provide, and the library of attacks. An inference system is proposed to mitigate anti-forensic attacks and generate potential scenarios starting from traces that were targeted by these attacks. To exemplify the proposal, we provide a case study related to the investigation of an incident that exhibited anti-forensic attacks.
Keywords :
computer forensics; formal logic; inference mechanisms; antiforensic attacks; digital investigation; inference system; security solution; state based logic; Analytical models; Computational modeling; Digital forensics; Libraries; Observers; Security; Anti-forensic attacks investigation; formal attack scenarios reconstruction; inference system;
fLanguage :
English
Journal_Title :
Information Forensics and Security, IEEE Transactions on
Publisher :
ieee
ISSN :
1556-6013
Type :
jour
DOI :
10.1109/TIFS.2011.2176117
Filename :
6081933
Link To Document :
بازگشت