25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Barrie Codona, BSc (Hons) Network Computing, 2007<br />

4.9 Conclusion<br />

Figure 19: Tester application<br />

This chapter has identified <strong>the</strong> main components <strong>of</strong> s<strong>of</strong>tware that will be developed as<br />

part <strong>of</strong> this project. All <strong>the</strong> components <strong>of</strong> <strong>the</strong> system will be created using C# <strong>and</strong><br />

<strong>the</strong> .NET framework, as <strong>the</strong>y provide <strong>Event</strong> logging, Performance monitoring <strong>and</strong><br />

encryption classes, which this application makes extensive use <strong>of</strong>.<br />

Based upon <strong>the</strong> research that was done in <strong>the</strong> Literature Review <strong>and</strong> <strong>Evaluation</strong> <strong>of</strong> <strong>the</strong><br />

<strong>Windows</strong> <strong>Event</strong> <strong>Log</strong> chapters it was decided that <strong>the</strong> application would use clientserver<br />

architecture. The client would be <strong>the</strong> event logger <strong>and</strong> <strong>the</strong> server would be <strong>the</strong><br />

data archiving system. All <strong>the</strong> communications that take place will be encrypted <strong>and</strong><br />

all <strong>the</strong> event s that are generated will be hashed.<br />

Also, a method for testing <strong>the</strong> performance, security <strong>and</strong> accuracy <strong>of</strong> <strong>the</strong> system was<br />

proposed. A program that would assist in <strong>the</strong> testing <strong>of</strong> <strong>the</strong> application was also<br />

designed; its main purpose is to generate a larger number <strong>of</strong> events in a very short<br />

period <strong>of</strong> time. This is to simulate <strong>the</strong> level <strong>of</strong> traffic that would be present on a<br />

corporate sever.<br />

40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!