DocumentCode
3404165
Title
A Method for Historical Ext3 Inode to Filename Translation on Honeypots
Author
Fairbanks, Kevin D. ; Xia, Ying H. ; Owen, Henry L., III
Author_Institution
Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
Volume
2
fYear
2009
fDate
20-24 July 2009
Firstpage
392
Lastpage
397
Abstract
In an environment where computer compromises are no longer anomalies, but are frequent occurrences, the field of computer forensics has increasingly gained importance. The development of this forensic field is matched by a growth in anti-forensic techniques. To overcome potential difficulties with external applications, operating systems should contain methods for storing and protecting meaningful information. The Linux Ext3 journal is one source of information that should be fully utilized for its intended purpose and forensics as well. However, due to its limited size and circular nature, this source of information has restrictions that can be addressed by the operating system. For example, when collecting and examining Ext3 journal data, it can be difficult to determine the filename that an inode number is associated with. In this paper, the design of a method for honeypots is presented which takes advantage of the virtual file system layer in Linux to address this difficulty. This technique allows the translation of inode numbers to filenames in a historical context thereby providing a forensic analyst with a better picture of what has transpired.
Keywords
Linux; file organisation; forensic science; security of data; Linux Ext3 journal; antiforensic techniques; computer forensics; filename translation; historical Ext3 inode; honeypots; meaningful information protection; meaningful information storing; operating systems; virtual file system layer; Application software; Computer applications; Software debugging; Dentry; Ext3; File System; Forensics; Inode; TimeKeeper; Virtual File System (VFS);
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Software and Applications Conference, 2009. COMPSAC '09. 33rd Annual IEEE International
Conference_Location
Seattle, WA
ISSN
0730-3157
Print_ISBN
978-0-7695-3726-9
Type
conf
DOI
10.1109/COMPSAC.2009.165
Filename
5254058
Link To Document