Skip to main navigation Skip to search Skip to main content

IR4CF: A intrusion replay system for computer forensics

  • Lei Xu*
  • , Zhihong Tian
  • , Jianwei Ye
  • , Hongli Zhang
  • *Corresponding author for this work
  • Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

When computer intrusions occur, one of the most costly, time-consuming, and human-intensive tasks is to analysis and take the evidence of the compromised system. IR4CF: a system call based intrusion replay system for supporting the computer forensics. IR4CF uses three key mechanisms to improve the accuracy and reduce the human overhead of performing forensic analysis. First, it streams the kernel event information in real-time, to append-only storage on a separate, hardened, logging machine, making the system resilient to a wide variety of attacks. Second, it uses system-call hijacking technology to perform comprehensive monitoring of the execution of a target system at the kernel event level, giving a high-resolution, application-independent view of all activity. Third, it analyses and replays the intrusion actions dynamically, which can be used for evidence in a court of law.

Original languageEnglish
Title of host publicationCCIE 2011 - Proceedings
Subtitle of host publication2011 IEEE 2nd International Conference on Computing, Control and Industrial Engineering
Pages66-69
Number of pages4
DOIs
StatePublished - 2011
EventIEEE 2nd International Conference on Computing, Control and Industrial Engineering, CCIE 2011 - Wuhan, China
Duration: 20 Aug 201121 Aug 2011

Publication series

NameCCIE 2011 - Proceedings: 2011 IEEE 2nd International Conference on Computing, Control and Industrial Engineering
Volume1

Conference

ConferenceIEEE 2nd International Conference on Computing, Control and Industrial Engineering, CCIE 2011
Country/TerritoryChina
CityWuhan
Period20/08/1121/08/11

Keywords

  • Auditing
  • Forensics
  • Intrusion replay

Fingerprint

Dive into the research topics of 'IR4CF: A intrusion replay system for computer forensics'. Together they form a unique fingerprint.

Cite this