loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
15th Annual Computer Security Applications Conference (ACSAC '99)
Adding Availability to Log Services of Untrusted Machines
Phoenix, Arizona
December 06-December 10
ISBN: 0-7695-0346-2
Arianna Arona, Universit? degli Studi di Milano
Danilo Bruschi, Universit? degli Studi di Milano
Emilia Rosti, Universit? degli Studi di Milano
Uncorrupted log files are the critical system component for computer forensics in case of intrusion and for real time system monitoring and auditing. Protection from tampering with information can be achieved using cryptographic functions that provide authenticity, integrity, and confidentiality. However, they cannot provide the prerequisite for any further information processing, i.e., information availability. In this case, fault tolerant strategies can be of great help improving information availability in case of accidental or deliberate deletion.In this paper we propose a system that increases log files availability in case of software deletion by reliably and efficiently distributing the logs on multiple independent machines. The proposed scheme is more efficient than simple replication, both from the storage space and the network bandwidth points of view. The proposed system has been implemented and its impact on performance has been measured. Since it operates as a postprocessor after log generation, the proposed system can be easily integrated with logging systems that provide various cryptographic functions for forensic purposes.
Index Terms:
availability, security, fault-tolerance, log files
Citation:
Arianna Arona, Danilo Bruschi, Emilia Rosti, "Adding Availability to Log Services of Untrusted Machines," acsac, pp.199, 15th Annual Computer Security Applications Conference (ACSAC '99), 1999
Usage of this product signifies your acceptance of the Terms of Use.