• DocumentCode
    2499487
  • Title

    A Kernel Level VFS Logger for Building Efficient File System Intrusion Detection System

  • Author

    Ansari, Md Sarfaraj Alam ; Chattopadhayay, Arijit ; Das, Suvrojit

  • Author_Institution
    Nat. Inst. of Technol., Durgapur, India
  • fYear
    2010
  • fDate
    23-25 April 2010
  • Firstpage
    273
  • Lastpage
    279
  • Abstract
    For any file, the modification, access and creation date and time stamp (MAC DTS) is a major parameter, which if preserved properly can be used to gain crucial evidence about activities on the file. Activities on a file system is generally protected by access control mechanism specific to the operating system; discretionary or mandatory access control mechanism being the most common ones. Generally, access control mechanisms deal with allow or deny a based rule (for access to a file) which even extends to role based access control in some cases. This directly implies that access protection mechanism is generally tightly coupled with almost all operating systems. Still, intrusion is a common phenomenon. This paper analyzes and measures the performance of our previously defined approach for efficient file system intrusion detection system. This paper also establishes how this approach can be complementary to existing access control mechanism for Linux kernel 2.6.x.
  • Keywords
    authorisation; file organisation; Linux kernel 2.6.x; access control mechanism; date stamp; file access; file creation; file modification; file system intrusion detection system; kernel level VFS logger; time stamp; virtual file system; Access control; Computer networks; File systems; Intrusion detection; Kernel; Linux; Operating systems; Performance analysis; Protection; Security; Access and Creation Date and Time stamp (MAC DTS); Host Based Intrusion Detection System (HIDS); Loadable Kernel Module (LKM); Modification; System calls; Virtual File System (VFS);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Network Technology (ICCNT), 2010 Second International Conference on
  • Conference_Location
    Bangkok
  • Print_ISBN
    978-0-7695-4042-9
  • Electronic_ISBN
    978-1-4244-6962-8
  • Type

    conf

  • DOI
    10.1109/ICCNT.2010.47
  • Filename
    5474493