• DocumentCode
    3404165
  • Title

    A Method for Historical Ext3 Inode to Filename Translation on Honeypots

  • Author

    Fairbanks, Kevin D. ; Xia, Ying H. ; Owen, Henry L., III

  • Author_Institution
    Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
  • Volume
    2
  • fYear
    2009
  • fDate
    20-24 July 2009
  • Firstpage
    392
  • Lastpage
    397
  • Abstract
    In an environment where computer compromises are no longer anomalies, but are frequent occurrences, the field of computer forensics has increasingly gained importance. The development of this forensic field is matched by a growth in anti-forensic techniques. To overcome potential difficulties with external applications, operating systems should contain methods for storing and protecting meaningful information. The Linux Ext3 journal is one source of information that should be fully utilized for its intended purpose and forensics as well. However, due to its limited size and circular nature, this source of information has restrictions that can be addressed by the operating system. For example, when collecting and examining Ext3 journal data, it can be difficult to determine the filename that an inode number is associated with. In this paper, the design of a method for honeypots is presented which takes advantage of the virtual file system layer in Linux to address this difficulty. This technique allows the translation of inode numbers to filenames in a historical context thereby providing a forensic analyst with a better picture of what has transpired.
  • Keywords
    Linux; file organisation; forensic science; security of data; Linux Ext3 journal; antiforensic techniques; computer forensics; filename translation; historical Ext3 inode; honeypots; meaningful information protection; meaningful information storing; operating systems; virtual file system layer; Application software; Computer applications; Software debugging; Dentry; Ext3; File System; Forensics; Inode; TimeKeeper; Virtual File System (VFS);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
  • Conference_Location
    Seattle, WA
  • ISSN
    0730-3157
  • Print_ISBN
    978-0-7695-3726-9
  • Type

    conf

  • DOI
    10.1109/COMPSAC.2009.165
  • Filename
    5254058