25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Barrie Codona, BSc (Hons) Network Computing, 2007<br />

1.3 Aims <strong>and</strong> Objectives<br />

The aim <strong>of</strong> this project is:<br />

1. To develop a solution that addresses <strong>the</strong> flaws in <strong>the</strong> <strong>Windows</strong> event logging<br />

service.<br />

To achieve <strong>the</strong> aim, <strong>the</strong> following objectives <strong>of</strong> this project are to:<br />

1. Investigate current research that is occurring in <strong>the</strong> field <strong>of</strong> <strong>Event</strong> <strong>Log</strong><br />

Management <strong>and</strong> Digital Forensics.<br />

2. Produce an analysis <strong>of</strong> <strong>the</strong> weaknesses in <strong>the</strong> <strong>Windows</strong> event log.<br />

3. Design a suitable piece <strong>of</strong> s<strong>of</strong>tware using an appropriate methodology.<br />

4. Evaluate using a proven methodology.<br />

1.4 Thesis Structure<br />

Chapter 1<br />

Chapter 2<br />

Chapter 3<br />

Chapter 4<br />

Chapter 5<br />

Chapter 6<br />

Introduction. This chapter will present some background information<br />

<strong>and</strong> define <strong>the</strong> aims <strong>and</strong> objectives for <strong>the</strong> project.<br />

Literature Review. This chapter will investigate <strong>the</strong> current research<br />

that is occurring in <strong>the</strong> field <strong>of</strong> <strong>Event</strong> <strong>Log</strong> Management <strong>and</strong> Digital<br />

Forensics.<br />

<strong>Windows</strong> <strong>Event</strong> <strong>Log</strong>. This chapter provides an investigation into <strong>the</strong><br />

<strong>Windows</strong> <strong>Event</strong> logging service.<br />

Design. This chapter will provide an overview <strong>of</strong> <strong>the</strong> proposed<br />

s<strong>of</strong>tware prototype that is to be developed.<br />

Implementation. This chapter will introduce <strong>the</strong> prototyped s<strong>of</strong>tware<br />

that has been developed <strong>and</strong> a series <strong>of</strong> tests that will be designed to<br />

ensure that <strong>the</strong> s<strong>of</strong>tware fulfils <strong>the</strong> requirements.<br />

<strong>Evaluation</strong>. This chapter presents <strong>the</strong> tested results <strong>of</strong> <strong>the</strong> prototyped<br />

system that has been previously developed.<br />

11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!