File integrity monitor scheduling based on file security level classification

5Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Integrity of operating system components must be carefully handled in order to optimize the system security. Attackers always attempt to alter or modify these related components to achieve their goals. System files are common targets by the attackers. File integrity monitoring tools are widely used to detect any malicious modification to these critical files. Two methods, off-line and on-line file integrity monitoring have their own disadvantages. This paper proposes an enhancement to the scheduling algorithm of the current file integrity monitoring approach by combining the off-line and on-line monitoring approach with dynamic inspection scheduling by performing file classification technique. Files are divided based on their security level group and integrity monitoring schedule is defined based on related groups. The initial testing result shows that our system is effective in on-line detection of file modification. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Abdullah, Z. H., Udzir, N. I., Mahmod, R., & Samsudin, K. (2011). File integrity monitor scheduling based on file security level classification. In Communications in Computer and Information Science (Vol. 180 CCIS, pp. 177–189). https://doi.org/10.1007/978-3-642-22191-0_16

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free