Affiliation:
1. University of Plymouth, UK
Abstract
Logging User Actions in Relational Mode (LUARM) is an open source audit engine for Linux. It provides a near real-time snapshot of a number of user action data such as file access, program execution and network endpoint user activities, all organized in easily searchable relational tables. LUARM attempts to solve two fundamental problems of the insider IT misuse domain. The first concerns the lack of insider misuse case data repositories that could be used by post-case forensic examiners to aid an incident investigation. The second problem relates to how information security researchers can enhance their ability to specify accurately insider threats at system level. This paper presents LUARM’s design perspectives and a ’post mortem’ case study of an insider IT misuse incident. The results show that the prototype audit engine has good potential to provide a valuable insight into the way insider IT misuse incidents manifest on IT systems and can be a valuable complement to forensic investigators of IT misuse incidents.
Reference31 articles.
1. Live forensics
2. Barr, D. (1996). RFC 1912: Common DNS operational and configuration errors. Retrieved from http://www.faqs.org/rfcs/rfc1912.html
3. Cha, A. E. (2008). Even spies embrace China's free market. Retrieved from http://www.washingtonpost.com/wp-dyn/content/article/2008/02/14/AR2008021403550.html
Cited by
7 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献