A New Approach for Real Time Evidence Collection from Linux Environment
Journal: International Journal of Science and Research (IJSR) (Vol.5, No. 5)Publication Date: 2016-05-05
Authors : Neethu P Nair; Maniveena C;
Page : 1487-1489
Keywords : inode; inotify; post-mortem analysis; syslog; monitoring;
Abstract
Evidence collection from computers is an important step in the process of digital investigations. An event could correspond to a system log entry where the operating system has recorded that a particular user or application performs a certain action. Depending on the configuration of the system the logs may omit some types of forensically interesting events and include various forensically uninteresting events. So there is an increased need of a system that will collect evidences related to computer activities. Through this paper a real time computer forensics system that records computer activity for forensic investigation on a Linux based computer system is aimed. This will help investigators who look for evidences in these operating systems. This method is different from the traditional post-mortem method of examining data since activities are being recorded as they are happening.
Other Latest Articles
- Chemical and Microbiological Studies for Determination the Influence of Fertilizers Produced by ?Agropolychim? Ad on Winter Common Wheat and Oilseed Rape
- A Clinical Study of Enterocutaneous Fistula and Management Options
- Ghana's Readiness to Pull the Plug on Analogue Transmission in 2016
- Copyright Protection in Cyberspace-A Comparative Study of USA and India
- Hypotensive and Antihypertensive Effects of Total Aqueous Extract of Justicia secunda Vahl M. (Acanthaceae) in Rabbits
Last modified: 2021-07-01 14:37:34