Establishing forensics capabilities in the presence of superuser insider threats. (September 2021)
- Record Type:
- Journal Article
- Title:
- Establishing forensics capabilities in the presence of superuser insider threats. (September 2021)
- Main Title:
- Establishing forensics capabilities in the presence of superuser insider threats
- Authors:
- Manral, Bharat
Somani, Gaurav - Abstract:
- Abstract: Insider threats are paving ways to the headlines of security articles and reports across the globe. It's a common practice across organizations to have designated employees as administrators with complete administrative or superuser capabilities for the IT infrastructure. In this paper, we argue that superusers with all the administrative and access control capabilities may escape from the scrutiny of forensic investigation and may also become a major obstacle in the process of evidence collection. Through this work, we open a discussion on forensic aspects of insider threats with a particular focus on superuser forensics. We identify the anti-forensic administrative privileges of the superusers and discuss the sheer forensic repercussions with the help of four generic insider threat cases. As our primary contribution, we identify and define the four important requirements for a superuser-immune solution. These requirements include denying and logical access to the potential forensic artifacts, timely synchronization and integrity of evidential artifacts, and ensuring the execution of legitimate code/service and notification capabilities. Based on the identified requirements, we propose a forensic compliant mechanism, "Log-of-logs server" to countermeasure the inherent anti-forensic capabilities of the superuser. We showcase that the proposed framework effectively helps in establishing forensic capabilities for superusers. We also present the security analysis ofAbstract: Insider threats are paving ways to the headlines of security articles and reports across the globe. It's a common practice across organizations to have designated employees as administrators with complete administrative or superuser capabilities for the IT infrastructure. In this paper, we argue that superusers with all the administrative and access control capabilities may escape from the scrutiny of forensic investigation and may also become a major obstacle in the process of evidence collection. Through this work, we open a discussion on forensic aspects of insider threats with a particular focus on superuser forensics. We identify the anti-forensic administrative privileges of the superusers and discuss the sheer forensic repercussions with the help of four generic insider threat cases. As our primary contribution, we identify and define the four important requirements for a superuser-immune solution. These requirements include denying and logical access to the potential forensic artifacts, timely synchronization and integrity of evidential artifacts, and ensuring the execution of legitimate code/service and notification capabilities. Based on the identified requirements, we propose a forensic compliant mechanism, "Log-of-logs server" to countermeasure the inherent anti-forensic capabilities of the superuser. We showcase that the proposed framework effectively helps in establishing forensic capabilities for superusers. We also present the security analysis of our framework and discuss its forensic feasibility. Highlights: We discuss a set of insider threat cases to showcase the anti-forensic capabilities of superusers that may allow them to escape from attribution and legal scrutiny. We identify and categorize potential forensic artifacts in the Linux environment. We prepare a set of requirements to design a forensic solution that is immune to superuser insider threats. Based on the requirements, we introduce our "Log-of-logs" framework to tackle common superuser threats such as log disabling, modification, or deletion. Finally, we reconstruct the real life superuser threats cases to discuss the forensics feasibility of our proposed framework. … (more)
- Is Part Of:
- Forensic science international. Volume 38(2021)Supplement
- Journal:
- Forensic science international
- Issue:
- Volume 38(2021)Supplement
- Issue Display:
- Volume 38, Issue 2021 (2021)
- Year:
- 2021
- Volume:
- 38
- Issue:
- 2021
- Issue Sort Value:
- 2021-0038-2021-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-09
- Subjects:
- Insider threats -- Superuser -- Insider threat forensics -- Superuser forensics
- Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.fsidi.2021.301263 ↗
- Languages:
- English
- ISSNs:
- 2666-2817
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 23943.xml