Design and Evaluation of a Network Forensic Logging System

Tae-Kyou Park, Ilkyeun Ra · 2008

This paper describes a forensic logging system that collects fine-grained evidence from target servers and networks. For the logging system, we developed a TCSEC-B1 level secure operating system and a dedicated network processor that collects network traffic. The logging system is also capable of protecting servers from malicious attacks as well as allowing security managers to obtain forensic evidences when the target server is assaulted by violations. We describe the design and implementation of the system and discuss the benchmark result of the prototype system.

Read the paper · More papers on PaperTik