An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS An Ontology for Digital Forensics in IT Security Incidents - OPUS

opus.bibliothek.uni.augsburg.de
from opus.bibliothek.uni.augsburg.de More from this publisher
15.01.2014 Views

52 CHAPTER 6. FORENSIC ONTOLOGY Partition1 fs : hasFSFileName FsFn6 FsFn6 rdf : type fs : FSFileName FsFn6 fsfn : name " Root Object / UserData / Malware " FsO6 rdf : type fs : File FsO6 fs : containsFSFileName FsFn6 FsO6 fs : childOf FsO2 Partition1 fs : hasFSFileName FsFn7 FsFn7 rdf : type fs : FSFileName FsFn7 fsfn : name " Root Object / UserData / ImportantDocument " FsO7 rdf : type fs : File FsO7 fs : containsFSFileName FsFn7 FsO7 fs : childOf FsO2 Partition1 fs : hasFSFileName FsFn8 FsFn8 rdf : type fs : FSFileName FsFn8 fsfn : name " Root Object / System / Kernel " FsO8 rdf : type fs : File FsO8 fs : containsFSFileName FsFn8 FsO8 fs : childOf FsO3 Partition1 fs : hasFSFileName FsFn9 FsFn9 rdf : type fs : FSFileName FsFn9 fsfn : name " Root Object / Programs / Browser " FsO9 rdf : type fs : File FsO9 fs : containsFSFileName FsFn9 FsO9 fs : childOf FsO4 Partition1 fs : hasFSFileName FsFn10 FsFn10 rdf : type fs : FSFileName FsFn10 fsfn : name " Root Object / Programs / FileExplorer " FsO10 rdf : type fs : File FsO10 fs : containsFSFileName FsFn10 FsO10 fs : childOf FsO4 Listing 6.1: Sample hard disk triples 6.10.2 Random Access Memory Listing 6.2 shows the triples that represent the data from the random access memory. The Process Malware is not visible with the standard tools available in the operating system but it can be found because it is stored in the memory. pro : ProcessList pro : hasProcess Proc0 Proc0 pro : parent Proc0 Proc0 pro : name " Kernel " pro : ProcessList pro : hasProcess Proc1 Proc1 pro : parent Proc0 Proc1 pro : name " Browser " Proc1 pro : hasConnection " www . google . com " pro : ProcessList pro : hasProcess Proc2 Proc2 pro : parent Proc0 Proc2 pro : name " FileExplorer " Proc2 pro : hasResource FsO5 Proc2 pro : hasConnection " www . malicious - server . com "

6.10. EXAMPLE 53 pro : ProcessList pro : hasProcess Proc3 Proc3 pro : parent Proc3 Proc3 pro : name " Malware " Listing 6.2: Sample memory triples 6.10.3 Registry Listing 6.3 shows the triples that represent an excerpt of the data of the registry on the hard disk. The registry data of the memory is not shown as the dierence is only the value of the rewall status. H1 rdf : type reg : Hive H1 reg : root K0 H1 reg : name " Hive1 " K0 rdf : type reg : Key K0 reg : name " Root " K0 reg : hasSubKey K1 K1 rdf : type reg : Key K1 reg : name " Firewall " K1 reg : keystate S1 K1 reg : hasValue V1 S1 rdf : type reg : State S1 rdf : value "S" V1 rdf : type reg : Value V1 reg : type T1 V1 reg : key " Status " V1 reg : value "1" T1 rdf : type reg : ValueType T1 rdf : value " DWORD " Listing 6.3: Sample registry triples

6.10. EXAMPLE 53<br />

pro : ProcessList pro : hasProcess Proc3<br />

Proc3 pro : parent Proc3<br />

Proc3 pro : name " Malware "<br />

List<strong>in</strong>g 6.2: Sample memory triples<br />

6.10.3 Registry<br />

List<strong>in</strong>g 6.3 shows the triples that represent an excerpt of the data of the<br />

registry on the hard disk. The registry data of the memory is not shown as<br />

the dierence is only the value of the rewall status.<br />

H1 rdf : type reg : Hive<br />

H1 reg : root K0<br />

H1 reg : name " Hive1 "<br />

K0 rdf : type reg : Key<br />

K0 reg : name " Root "<br />

K0 reg : hasSubKey K1<br />

K1 rdf : type reg : Key<br />

K1 reg : name " Firewall "<br />

K1 reg : keystate S1<br />

K1 reg : hasValue V1<br />

S1 rdf : type reg : State<br />

S1 rdf : value "S"<br />

V1 rdf : type reg : Value<br />

V1 reg : type T1<br />

V1 reg : key " Status "<br />

V1 reg : value "1"<br />

T1 rdf : type reg : ValueType<br />

T1 rdf : value " DWORD "<br />

List<strong>in</strong>g 6.3: Sample registry triples

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!