University of Illinois at Urbana-Champaign
Towards trustworthy foundations for operating system Forensics
Abstract
dc:descriptionSystem logging is an essential component of building and maintaining secure systems. Unfortunately, attackers regularly engage in anti-forensic activities after a break-in, covering their tracks from system logs in order to frustrate the efforts of investigators. In response to this threat, a variety of secure logging solutions have appeared in the industry and the literature that attempt to provide tamper-resistance (e.g., Write-Once-Read-Many drives, remote storage servers) or tamper-evidence (e.g., cryptographic integrity proofs) for system logs. However, these approaches have not seen widespread adoption and moreover do not address the operational requirements of system-layer auditing frameworks. As such, the vast majority of system logs today remain vulnerable to adversarial tampering and removal. In this thesis, we revisit the goal of secure logging within the context of standard operating system abstractions. We introduce Custos, a comprehensive framework for the detection and prevention of tampering in system logs. Custos enables real-time detection of log integrity violations within an enterprise-class network while being minimally invasive to the underlying logging framework. Next, we present and validate an in-memory attack on the integrity of auditing frameworks. Our attack exploits the intrinsically asynchronous nature of I/O and IPC activity, demonstrating that an attacker can snatch the very evidence of their own intrusion out of message buffers before it is securely recorded. Finally, we present KennyLoggings, the first kernel-based tamper evident logging scheme that cryptographically secures event records at the moment of the event’s occurrence. We demonstrate that our systems are practical and impose modest (< 10%) costs to the operating system, while being able to detect violations even in the presence of powerful distributed adversaries. More generally, the systems presented in this thesis dramatically mitigate the threat of a covert anti-forensic attacker, enabling analysts to inspect a verifiable chain of custody for forensic data. Thus, this thesis demonstrates a viable path forward to achieving trustworthy foundations for operating system forensics.
Degree
thesis:*- Name thesis:degree_name
- M.S.
- Level thesis:degree_level
- Thesis
- Discipline thesis:degree_discipline
- Computer Science
- Grantor
- University of Illinois at Urbana-Champaign
- Year dc:date
- 2019
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Paccagnella, Riccardo
- Contributors dc:contributor
-
- Bates, Adam M
Subjects
dc:subject × 9Rights
dc:rights- Statement dc:rights
-
- Copyright 2019 Riccardo Paccagnella
- Language dc:language
- en
Identifiers
dc:identifier.*- Handle dc:identifier
- http://hdl.handle.net/2142/105946
- OAI identifier oai:identifier
- oai:www.ideals.illinois.edu:2142/105946