Yüksek LisansAçık Erişim

Detection of persistence structures by performing in-depth forensics analysis for linux systems

2022
0 görüntülenme
0 i̇ndirme
Danışman: Doç. Dr. Fatih Ertam

Özet (EN)

Today, cyber attackers can spread rapidly on the machines they have seized. Incident response teams conduct an end-to-end inspection of compromised machines to detect traces of the attack and track down potential threats. In the incident response and forensic analysis processes, it is of great importance to examine digital evidence and make a transition to the prosecution phase. In Windows operating systems, forensic experts have the opportunity to collect and analyze data from some machines in a fast and collective way in order to continue the attack. Since the visibility is more limited in Linux open source operating systems, it is necessary to evaluate and make sense of the relevant resources. With the prevalence of forensic analysis processes and the developing technology structure, file system records or collection of log files were managed in order to determine the source and spread of the attack in Linux open source operating systems. While forensic evidence features are more and clear in the Windows operating system, attack activities are less visible in Linux systems. Attackers not only violate the systems with certain methods, but also try to create mechanisms for collecting information from the system by adding scheduled tasks, leaving persistence on the system. It will be sufficient for the forensic expert to collect important operating system files from a live system or a forensic image for rapid analysis of the case. In this thesis, the management of forensic analysis processes in Linux operating systems will be tested by testing which structures the attackers use to stay on Linux systems and the findings will be conveyed in the light of the analysis processes. Failure to detect persistent attack activities on Linux systems poses a great threat to the corporate network. Within the scope of this thesis, some processes aiming to be permanent on the system for many years by performing timed attack tasks and detecting attack activities with the data collected from the active directories of the devices on the Linux operating system and managing the process up to the prosecution phase are conveyed.

Yazar

Dr. Büşra Aytekin

Bu Yayına Nasıl Atıf Yapılır

Büşra Aytekin (Master Thesis). Detection of persistence structures by performing in-depth forensics analysis for linux systems, 2022, Fırat University.

Lisans

Tüm Hakları Saklıdır

Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.

Fırat University tezlerinden daha fazlası