Analyzing computer intrusions

Andrew Harrison Gross · 1998

Concern is growing about the misuse of computers and their resources. Although most efforts in computer security focus on detecting security violations, understanding what the misuser's interest is and what methods are used, aids detection, assessment, and recovery. In the case of misuse, determining if the actions involved destruction or falsification of data would affect the response, e.g., legal prosecution or fortifying precautionary and recovery procedures. In the case of an intrusion knowing the specific flaw exploited could allow prevention and detection of future exploits. An accurate assessment of the intruder's skill and potential threat based on his or her actions provides data for the site to use to bolster their protective measures and system auditing. We present the method for reconstructing an offender's actions. This requires modelling the system in order to understand how it evolves, and what residual information in the system enables derivation of (parts of) prior states and state transitions. The major questions addressed are how the relevant states and state transitions can be reconstructed, how much of the session can be reconstructed, and what information is needed for complete reconstruction. As part of reconstruction, we may need to recover deleted files. In the case of intrusion, critical information is routinely deleted, e.g., tools used to attack the system and log files. We model a general file system and present techniques for characterizing and identifying deleted data. We use the file system model to provide ordering information for the identified data in addition to that present in the structure of the file being recovered. Recovering these files is a useful exercise in applying the principles of reconstruction. We apply our results to the UNIX operating system, as it is a popular system originally designed for a friendly environment. We explore memory and file system traces left in the wake of an intrusion and how they can be used. A real world example highlights these techniques and their application. We discuss various techniques for recovering deleted files, and modifications to a file system to enable more reliable recovery. Techniques for augmenting logging and auditing data are presented.

Read the paper · More papers on PaperTik