Detection of persistence structures by performing in-depth forensics analysis for linux systems
2022
0 görüntülenme
0 i̇ndirme
Danışman: Doç. Dr. Fatih Ertam
Özet (EN)
Today, cyber attackers can spread rapidly on the machines they have seized. Incident response teams conduct an end-to-end inspection of compromised machines to detect traces of the attack and track down potential threats. In the incident response and forensic analysis processes, it is of great importance to examine digital evidence and make a transition to the prosecution phase. In Windows operating systems, forensic experts have the opportunity to collect and analyze data from some machines in a fast and collective way in order to continue the attack. Since the visibility is more limited in Linux open source operating systems, it is necessary to evaluate and make sense of the relevant resources. With the prevalence of forensic analysis processes and the developing technology structure, file system records or collection of log files were managed in order to determine the source and spread of the attack in Linux open source operating systems. While forensic evidence features are more and clear in the Windows operating system, attack activities are less visible in Linux systems. Attackers not only violate the systems with certain methods, but also try to create mechanisms for collecting information from the system by adding scheduled tasks, leaving persistence on the system. It will be sufficient for the forensic expert to collect important operating system files from a live system or a forensic image for rapid analysis of the case. In this thesis, the management of forensic analysis processes in Linux operating systems will be tested by testing which structures the attackers use to stay on Linux systems and the findings will be conveyed in the light of the analysis processes. Failure to detect persistent attack activities on Linux systems poses a great threat to the corporate network. Within the scope of this thesis, some processes aiming to be permanent on the system for many years by performing timed attack tasks and detecting attack activities with the data collected from the active directories of the devices on the Linux operating system and managing the process up to the prosecution phase are conveyed.
Yazar
Dr. Büşra Aytekin
Kurum
Bu Yayına Nasıl Atıf Yapılır
Büşra Aytekin (Master Thesis). Detection of persistence structures by performing in-depth forensics analysis for linux systems, 2022, Fırat University.
Anahtar Kelimeler
Lisans
Tüm Hakları Saklıdır
Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.
Fırat University tezlerinden daha fazlası
- Using social media as an integrated marketing communication tool(2018)
- Foundation of Dutch East İndia Company and her rising in İndonesia in the 17th century(2013)
- Color usage at Turkish Divan of Fuzûlî(2013)
- Yavuzeli (Gaziantep) surrounding volcanic outcropping of rocks petrographic and geochemical features(2014)
- The effects of thermal aging in Cu-Al-Ni and Cu-Al-Be shape memory alloys(2009)
- 1551 M. (959 H.) tarih ve 282 No'lu Tapu Tahrir Defterine göre Basra(1996)
