Back to results

University of Illinois at Urbana-Champaign

Towards trustworthy foundations for operating system Forensics

Abstract

dc:description

System logging is an essential component of building and maintaining secure systems. Unfortunately, attackers regularly engage in anti-forensic activities after a break-in, covering their tracks from system logs in order to frustrate the efforts of investigators. In response to this threat, a variety of secure logging solutions have appeared in the industry and the literature that attempt to provide tamper-resistance (e.g., Write-Once-Read-Many drives, remote storage servers) or tamper-evidence (e.g., cryptographic integrity proofs) for system logs. However, these approaches have not seen widespread adoption and moreover do not address the operational requirements of system-layer auditing frameworks. As such, the vast majority of system logs today remain vulnerable to adversarial tampering and removal. In this thesis, we revisit the goal of secure logging within the context of standard operating system abstractions. We introduce Custos, a comprehensive framework for the detection and prevention of tampering in system logs. Custos enables real-time detection of log integrity violations within an enterprise-class network while being minimally invasive to the underlying logging framework. Next, we present and validate an in-memory attack on the integrity of auditing frameworks. Our attack exploits the intrinsically asynchronous nature of I/O and IPC activity, demonstrating that an attacker can snatch the very evidence of their own intrusion out of message buffers before it is securely recorded. Finally, we present KennyLoggings, the first kernel-based tamper evident logging scheme that cryptographically secures event records at the moment of the event’s occurrence. We demonstrate that our systems are practical and impose modest (< 10%) costs to the operating system, while being able to detect violations even in the presence of powerful distributed adversaries. More generally, the systems presented in this thesis dramatically mitigate the threat of a covert anti-forensic attacker, enabling analysts to inspect a verifiable chain of custody for forensic data. Thus, this thesis demonstrates a viable path forward to achieving trustworthy foundations for operating system forensics.

Degree

thesis:*
Name thesis:degree_name
M.S.
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Computer Science
Grantor
University of Illinois at Urbana-Champaign
Year dc:date
2019

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Paccagnella, Riccardo
Contributors dc:contributor
  • Bates, Adam M

Subjects

dc:subject × 9

Rights

dc:rights
Statement dc:rights
  • Copyright 2019 Riccardo Paccagnella
Language dc:language
en

Identifiers

dc:identifier.*
Handle dc:identifier
http://hdl.handle.net/2142/105946
OAI identifier oai:identifier
oai:www.ideals.illinois.edu:2142/105946

Chain of custody

source
Harvested from
University of Illinois - Urbana-Champaign
Base URL
www.ideals.illinois.edu/oai-pmh
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Paccagnella, Riccardo. Towards trustworthy foundations for operating system Forensics. Thesis thesis, University of Illinois at Urbana-Champaign, 2019. http://hdl.handle.net/2142/105946