본문 바로가기
  • Home

A design of Secure Audit / Trace Module to Support Computer Forensics

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2004, 9(1), pp.79-86
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science

고병수 1 Choi,Yong-Rak 1 박영신 1

1대전대학교

ABSTRACT

In general, operating system is offering the security function of OS level to support several web services. However, it is true that security side of OS level is weak from many parts. Specially, it is needed to audit/trace function in security kernel level to satisfy security more than B2 level that define in TCSEC(Trusted Computer System Evaluation Criteria). So we need to create audit data at system call invocation for this, and do to create audit data of equal format about almost event and supply information to do traceback late. This paper proposes audit/trace system module that use LKM(Loadable Kernel Module) technique. It is applicable without alteration about existing linux kernel to ensure safe evidence. It offers interface that can utilize external audit data such as intrusion detection system, and also offers safe role based system that is divided system administrator and security administrator. These data will going to utilize to computer forensics' data that legal confrontation is possible.

Citation status

* References for papers published after 2023 are currently being built.