Implementation and overhead analysis of a log-based intrusion recovery module on Linux file system
Jae-Kook Lee, Hyong-Shik Kim · 2005
Most people always want to get reliable information, even if there are intrusions that illegitimate hacker damages to file systems through operations modifying, appending, and deleting files. To accomplish this, we need the recovery function with transparent to user and return to its former state. This paper proposes design and implementation of a log-based intrusion recovery module (LBIRM). It can keep the previous contents of designated files as a chain of logs and recover the damaged file by using the log.