Master'sOpen Access

Development of cyber incident response tool that performs analysis of windows operating system remnants and extraction of event timeline

2021
0 views
0 downloads
Advisor: Doç. Dr. Fatih Ertam

Abstract (EN)

The use of the Windows operating system is increasing day by day around the world. However, versions of the windows operating system are developing and being updated. Crime techniques and variants are constantly changing in widely used versions of Windows, and attackers' impact on their victims is increasing rapidly. During this time, forensic analysis and forensic copy methods on the victims' machines take a long time to perform, so detecting the attackers and preventing the attack is time consuming. Windows operating systems are trying to reduce time loss by using up-to-date methods and tools to detect processes, user activities, file system and registry records, application and user residues on the machine. In Windows operating systems, the commercial load of the tools used in forensic copying and analysis of the obtained copies poses an obstacle to the development of the field and delays the investigations. For this reason, the loss of time and commercial dimension can be reduced by examining the log records, which enable to analyze the events involving the victim directly, with open source software. At the same time, the damage caused by the attack can be observed by creating an attack timeline with the log records obtained. In this thesis, it is presented that the log records and residues that attackers usually leave traces in Windows operating systems are collected and then parsed and then the event timeline is extracted. In addition to current methods for separating residues, the development of an open source cyber incident response tool was carried out. The record schedule of the aggressor-victim relationship is mentioned by creating an event-timeline of the separated remains. It is thought that the software developed in this thesis study, called IR-Parser, will be beneficial to people working in the field of forensic information and cyber security.

Author

Dr. Ali Hüsamiddin Uçar

How to Cite

Ali Hüsamiddin Uçar (Master Thesis). Development of cyber incident response tool that performs analysis of windows operating system remnants and extraction of event timeline, 2021, Fırat University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Fırat University