The Experts below are selected from a list of 222 Experts worldwide ranked by ideXlab platform
Yiorgos Makris - One of the best experts on this subject based on the ideXlab platform.
-
Hardware-based workload Forensics: Process reconstruction via TLB monitoring
2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 2016Co-Authors: Liwei Zhou, Yiorgos MakrisAbstract:We introduce a hardware-based methodology for performing workload execution Forensics in microProcessors. More specifically, we discuss the on-chip instrumentation required for capturing the operational profile of the Translation Lookaside Buffer (TLB), as well as an off-line machine learning approach which uses this information to identify the executed Processes and reconstruct the workload. Unlike workload Forensics methods implemented at the operating system (OS) and/or hypervisor level, whose data logging and monitoring mechanisms may be compromised through software attacks, this approach is implemented directly in hardware and is, therefore, immune to such attacks. The proposed method is demonstrated on an experimentation platform which consists of a 32-bit x86 architecture running Linux operating system, implemented in the Simics simulation environment. Experimental results using the Mibench workload benchmark suite reveal an overall workload identification accuracy of 96.97% at an estimated logging rate of only 5.17 KB/sec.
-
HOST - Hardware-based workload Forensics: Process reconstruction via TLB monitoring
2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 2016Co-Authors: Liwei Zhou, Yiorgos MakrisAbstract:We introduce a hardware-based methodology for performing workload execution Forensics in microProcessors. More specifically, we discuss the on-chip instrumentation required for capturing the operational profile of the Translation Lookaside Buffer (TLB), as well as an off-line machine learning approach which uses this information to identify the executed Processes and reconstruct the workload. Unlike workload Forensics methods implemented at the operating system (OS) and/or hypervisor level, whose data logging and monitoring mechanisms may be compromised through software attacks, this approach is implemented directly in hardware and is, therefore, immune to such attacks. The proposed method is demonstrated on an experimentation platform which consists of a 32-bit x86 architecture running Linux operating system, implemented in the Simics simulation environment. Experimental results using the Mibench workload benchmark suite reveal an overall workload identification accuracy of 96.97% at an estimated logging rate of only 5.17 KB/sec.
Liwei Zhou - One of the best experts on this subject based on the ideXlab platform.
-
Hardware-based workload Forensics: Process reconstruction via TLB monitoring
2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 2016Co-Authors: Liwei Zhou, Yiorgos MakrisAbstract:We introduce a hardware-based methodology for performing workload execution Forensics in microProcessors. More specifically, we discuss the on-chip instrumentation required for capturing the operational profile of the Translation Lookaside Buffer (TLB), as well as an off-line machine learning approach which uses this information to identify the executed Processes and reconstruct the workload. Unlike workload Forensics methods implemented at the operating system (OS) and/or hypervisor level, whose data logging and monitoring mechanisms may be compromised through software attacks, this approach is implemented directly in hardware and is, therefore, immune to such attacks. The proposed method is demonstrated on an experimentation platform which consists of a 32-bit x86 architecture running Linux operating system, implemented in the Simics simulation environment. Experimental results using the Mibench workload benchmark suite reveal an overall workload identification accuracy of 96.97% at an estimated logging rate of only 5.17 KB/sec.
-
HOST - Hardware-based workload Forensics: Process reconstruction via TLB monitoring
2016 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 2016Co-Authors: Liwei Zhou, Yiorgos MakrisAbstract:We introduce a hardware-based methodology for performing workload execution Forensics in microProcessors. More specifically, we discuss the on-chip instrumentation required for capturing the operational profile of the Translation Lookaside Buffer (TLB), as well as an off-line machine learning approach which uses this information to identify the executed Processes and reconstruct the workload. Unlike workload Forensics methods implemented at the operating system (OS) and/or hypervisor level, whose data logging and monitoring mechanisms may be compromised through software attacks, this approach is implemented directly in hardware and is, therefore, immune to such attacks. The proposed method is demonstrated on an experimentation platform which consists of a 32-bit x86 architecture running Linux operating system, implemented in the Simics simulation environment. Experimental results using the Mibench workload benchmark suite reveal an overall workload identification accuracy of 96.97% at an estimated logging rate of only 5.17 KB/sec.
Damir Delija - One of the best experts on this subject based on the ideXlab platform.
-
overview of mac system security and its impact on digital Forensics Process
International Convention on Information and Communication Technology Electronics and Microelectronics, 2020Co-Authors: D Sladovic, D Topolcic, Damir DelijaAbstract:Nowadays there are 3 main operating systems used, and Mac OS is one of them. Until now Apple published many iterations of their operating system and with that introduced many new features that are related to system security. Even though security-related changes go unnoticed, in the world of digital Forensics this presents a challenge. Today encryption can be implemented on both, hardware and software level, which can make imaging Mac OS difficult. Besides, security which is meant to protect, user data is also used by criminals to restrict access to their computers. This paper will focus on the differences and problems that occur while creating a forensic image and extracting data from Mac OS. On top of that this paper will depict the impact devices equipped with “T1” or “T2” security chip have on digital forensic Process and remediation methods.
-
MIPRO - Overview of Mac system security and its impact on digital Forensics Process
2020 43rd International Convention on Information Communication and Electronic Technology (MIPRO), 2020Co-Authors: D Sladovic, D Topolcic, Damir DelijaAbstract:Nowadays there are 3 main operating systems used, and Mac OS is one of them. Until now Apple published many iterations of their operating system and with that introduced many new features that are related to system security. Even though security-related changes go unnoticed, in the world of digital Forensics this presents a challenge. Today encryption can be implemented on both, hardware and software level, which can make imaging Mac OS difficult. Besides, security which is meant to protect, user data is also used by criminals to restrict access to their computers. This paper will focus on the differences and problems that occur while creating a forensic image and extracting data from Mac OS. On top of that this paper will depict the impact devices equipped with “T1” or “T2” security chip have on digital forensic Process and remediation methods.
Stefanos Gritzalis - One of the best experts on this subject based on the ideXlab platform.
-
CRiSIS - A Meta-model for Assisting a Cloud Forensics Process
Lecture Notes in Computer Science, 2016Co-Authors: Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos GritzalisAbstract:Cloud Forensics introduce Processes for resolving incidents occurring in cloud computing environments. However, designing cloud services capable to assist a cloud investigation Process is of vital importance and recent research efforts concentrate on these directions. In addition, digital Forensics methods cannot support a cloud investigation since cloud environments introduce many differences compared to traditional IT environments. This paper moves current research one step further by identifying the major concepts, actors and their relationships that participating in a cloud Forensics Process through the introduction of a new meta-model. The paper presents a running example as well for better understanding the suggested concepts.
-
a meta model for assisting a cloud Forensics Process
Conference on Risks and Security of Internet and Systems, 2015Co-Authors: Stavros Simou, Christos Kalloniatis, Haralambos Mouratidis, Stefanos GritzalisAbstract:Cloud Forensics introduce Processes for resolving incidents occurring in cloud computing environments. However, designing cloud services capable to assist a cloud investigation Process is of vital importance and recent research efforts concentrate on these directions. In addition, digital Forensics methods cannot support a cloud investigation since cloud environments introduce many differences compared to traditional IT environments. This paper moves current research one step further by identifying the major concepts, actors and their relationships that participating in a cloud Forensics Process through the introduction of a new meta-model. The paper presents a running example as well for better understanding the suggested concepts.
D Sladovic - One of the best experts on this subject based on the ideXlab platform.
-
overview of mac system security and its impact on digital Forensics Process
International Convention on Information and Communication Technology Electronics and Microelectronics, 2020Co-Authors: D Sladovic, D Topolcic, Damir DelijaAbstract:Nowadays there are 3 main operating systems used, and Mac OS is one of them. Until now Apple published many iterations of their operating system and with that introduced many new features that are related to system security. Even though security-related changes go unnoticed, in the world of digital Forensics this presents a challenge. Today encryption can be implemented on both, hardware and software level, which can make imaging Mac OS difficult. Besides, security which is meant to protect, user data is also used by criminals to restrict access to their computers. This paper will focus on the differences and problems that occur while creating a forensic image and extracting data from Mac OS. On top of that this paper will depict the impact devices equipped with “T1” or “T2” security chip have on digital forensic Process and remediation methods.
-
MIPRO - Overview of Mac system security and its impact on digital Forensics Process
2020 43rd International Convention on Information Communication and Electronic Technology (MIPRO), 2020Co-Authors: D Sladovic, D Topolcic, Damir DelijaAbstract:Nowadays there are 3 main operating systems used, and Mac OS is one of them. Until now Apple published many iterations of their operating system and with that introduced many new features that are related to system security. Even though security-related changes go unnoticed, in the world of digital Forensics this presents a challenge. Today encryption can be implemented on both, hardware and software level, which can make imaging Mac OS difficult. Besides, security which is meant to protect, user data is also used by criminals to restrict access to their computers. This paper will focus on the differences and problems that occur while creating a forensic image and extracting data from Mac OS. On top of that this paper will depict the impact devices equipped with “T1” or “T2” security chip have on digital forensic Process and remediation methods.