Repository logo
  • Log In
    New user? Click here to register.Have you forgotten your password?
University College Dublin
    Colleges & Schools
    Statistics
    All of DSpace
  • Log In
    New user? Click here to register.Have you forgotten your password?
  1. Home
  2. College of Science
  3. School of Computer Science
  4. Computer Science Research Collection
  5. Towards Automated Logging for Forensic-Ready Software Systems
 
  • Details
Options

Towards Automated Logging for Forensic-Ready Software Systems

Author(s)
Rivera-Ortiz, Fanny  
Pasquale, Liliana  
Uri
http://hdl.handle.net/10197/11551
Date Issued
2019-09-27
Date Available
2020-09-08T14:37:36Z
Abstract
Security incidents can arise from the misuse of existing software systems. Thus, appropriate logging mechanisms should be implemented at the software level to support the detection and investigation of security incidents. However, due to insufficient logging, security incidents often go undetected for long periods. Moreover, even after a security incident is detected, there is not enough information to fully reconstruct how an incident occurred. Insufficient logging may be due to the limited security expertise of software developers, who may not know what are the most critical security incidents. Also, for large software systems and a multitude of potential misuse scenarios, it is cumbersome to identify when and what logging instructions should be implemented. In this paper, we propose a preliminary idea to automate the development of "forensic-ready" software systems. These systems can log a minimum amount of relevant data that can be used to detect and investigate potential security incidents. Our approach allows a security engineer to elicit a set of potential software misuse scenarios, expressed as annotated sequence diagrams. These diagrams are then used—together with a control flow graph of the software system— to identify the exact location where logging instructions should be placed and the information they should log. Finally, logging instructions can be injected into designated software system locations using Aspect-Oriented Programming. We illustrate our approach using an example of software misuse in a human resources management software system.
Sponsorship
Science Foundation Ireland
Type of Material
Conference Publication
Publisher
IEEE
Copyright (Published Version)
2019 IEEE
Subjects

Bioengineering

Forensic readiness

Forensic-ready softwa...

Logging

Logging in software s...

Digital forensics

DOI
10.1109/rew.2019.00033
Web versions
http://re19.ajou.ac.kr/
Language
English
Status of Item
Peer reviewed
Journal
2019 IEEE 27th International Requirements Engineering Conference Workshops: Proceedings
Conference Details
The 27th IEEE International Requirements Engineering Conference, Jeju Island, South Korea, 23-27 September 2019
This item is made available under a Creative Commons License
https://creativecommons.org/licenses/by-nc-nd/3.0/ie/
File(s)
Loading...
Thumbnail Image
Name

Dev_FR_SS_DRAFT_15.pdf

Size

2.42 MB

Format

Adobe PDF

Checksum (MD5)

d5a018756f159afa2414b18e0f0e165a

Owning collection
Computer Science Research Collection

Item descriptive metadata is released under a CC-0 (public domain) license: https://creativecommons.org/public-domain/cc0/.
All other content is subject to copyright.

For all queries please contact research.repository@ucd.ie.

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Cookie settings
  • Privacy policy
  • End User Agreement