UPM Institutional Repository

File integrity monitor scheduling based on file security level classification


Citation

Abdullah, Zul Hilmi and Udzir, Nur Izura and Mahmod, Ramlan and Samsudin, Khairulmizam (2011) File integrity monitor scheduling based on file security level classification. In: Second International Conference on Software Engineering and Computer Systems (ICSECS 2011), 27-29 June 2011, Kuantan, Pahang, Malaysia. (pp. 177-189).

Abstract

Integrity of operating system components must be carefully handled in order to optimize the system security. Attackers always attempt to alter or modify these related components to achieve their goals. System files are common targets by the attackers. File integrity monitoring tools are widely used to detect any malicious modification to these critical files. Two methods, off-line and on-line file integrity monitoring have their own disadvantages. This paper proposes an enhancement to the scheduling algorithm of the current file integrity monitoring approach by combining the off-line and on-line monitoring approach with dynamic inspection scheduling by performing file classification technique. Files are divided based on their security level group and integrity monitoring schedule is defined based on related groups. The initial testing result shows that our system is effective in on-line detection of file modification.


Download File

[img] Text (Abstract)
File integrity monitor scheduling based on file security level classification.pdf

Download (34kB)

Additional Metadata

Item Type: Conference or Workshop Item (Paper)
Divisions: Faculty of Computer Science and Information Technology
Faculty of Engineering
DOI Number: https://doi.org/10.1007/978-3-642-22191-0_16
Publisher: Springer
Keywords: Operating system security; Files integrity; Monitoring schedule; File security classification; Malicious modification; HIDS
Depositing User: Nabilah Mustapa
Date Deposited: 05 Feb 2020 04:25
Last Modified: 05 Feb 2020 04:25
Altmetrics: http://www.altmetric.com/details.php?domain=psasir.upm.edu.my&doi=10.1007/978-3-642-22191-0_16
URI: http://psasir.upm.edu.my/id/eprint/76646
Statistic Details: View Download Statistic

Actions (login required)

View Item View Item