Prototyping Flow-Net Logging for Accountability Management in Linux Operating Systems

被引:0
作者
Xiao, Yang [1 ,2 ]
Zeng, Lei [2 ]
Chen, Hui [3 ,4 ]
Li, Tieshan [1 ]
机构
[1] Dalian Maritime Univ, Nav Coll, Dalian 116026, Peoples R China
[2] Univ Alabama, Dept Comp Sci, Tuscaloosa, AL 35487 USA
[3] CUNY Brooklyn Coll, Dept Comp & Informat Sci, Brooklyn, NY 11210 USA
[4] CUNY, Grad Ctr, New York, NY 10016 USA
来源
IEEE ACCESS | 2019年 / 7卷
基金
中国国家自然科学基金;
关键词
Computer security; accountability; logging; auditing; flow-net; IoT; NETWORKS; SECURITY; DESIGN;
D O I
10.1109/ACCESS.2019.2937637
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Accountability in conjunction with preventative countermeasures is necessary to satisfy the needs of real-world computer security. A common method to achieve accountability is via logging and auditing. To achieve better accountability, a logging system should be capable of capturing activities as well as the relationships among the activities in a computer system or network. Existing logging techniques record activity events in isolation and rely on attributes and time stamps of the logged events to establish their relationships, and this approach leads to probable loss of event relationships among large and complex logs and a confusion during auditing. Prior works have indicated that flow-net is effective in addressing this problem by organizing events in a direct acyclic graph and preserving event relationships during logging. In this work, we provide a prototypical design and implementation of a flow-net accountable logging framework in the Linux operating system. Particularly, it can be applied to Internet of Things (IoTs) with Android Operating Systems. We measure the performance overhead introduced by the flow-net logging prototype via experiments in Linux. The results indicate that the flow-net prototype only introduces a small overhead when compared with existing logging methods. In addition, we show by examples enforcement of accountability policies in the flow-net logging framework and its performance overhead. This work thus constitutes a further step to advance flow-net in addressing accountability in computer systems and networks.
引用
收藏
页码:131172 / 131187
页数:16
相关论文
共 34 条
  • [1] A profile based data segmentation for in-home activity recognition
    Al Nadi, Rania
    Al Zamil, Mohammed G. H.
    [J]. INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2019, 29 (01) : 28 - 37
  • [2] Accountable Internet Protocol (AIP)
    Andersen, David G.
    Balakrishnan, Hari
    Feamster, Nick
    Koponen, Teemu
    Moon, Daekyeong
    Shenker, Scott
    [J]. ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2008, 38 (04) : 339 - 350
  • [3] [Anonymous], 2009, 5424 RFC
  • [4] Ayuso P. N., 2019, COMMUNICATING KERNEL
  • [5] Bilge Leyla, 2012, P 2012 ACM C COMP CO, P833, DOI DOI 10.1145/2382196.2382284
  • [6] FNF: Flow-net based fingerprinting and its applications
    Fu, Bo
    Xiao, Yang
    Chen, Hui
    [J]. COMPUTERS & SECURITY, 2018, 75 : 167 - 181
  • [7] A multi-resolution accountable logging and its applications
    Fu, Bo
    Xiao, Yang
    [J]. COMPUTER NETWORKS, 2015, 89 : 44 - 58
  • [8] Accountability and Q-Accountable Logging in Wireless Networks
    Fu, Bo
    Xiao, Yang
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2014, 75 (03) : 1715 - 1746
  • [9] Botnet in DDoS Attacks: Trends and Challenges
    Hoque, Nazrul
    Bhattacharyya, Dhruba K.
    Kalita, Jugal K.
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04): : 2242 - 2270
  • [10] Improving smart home security; integrating behaviour prediction into smart home
    Jose, Arun Cyril
    Malekian, Reza
    Letswamotse, Babedi B.
    [J]. INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2018, 28 (04) : 253 - 269