25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Barrie Codona, BSc (Hons) Network Computing, 2007<br />

5.3.4. Decrypting Messages…………………….……………………. 46<br />

5.3.5. Saving to Disk………………….………..……………..…….… 47<br />

5.4. <strong>Log</strong> Reader…………………………….………….……………..….…. 47<br />

5.4.1. Opening File…………………………….……………………... 47<br />

5.4.2. Decoding XML…………………..……….………………..….. 48<br />

5.4.3. HMAC Checksum………………..………..……………….….. 49<br />

5.5. Conclusions………………………………...………..…………….…… 49<br />

6. <strong>Evaluation</strong>…………………………………..…….…………..………………. 51<br />

6.1. Introduction………………………………….…………..………..…… 51<br />

6.2. Initial Testing………………………………………..…..……….…….. 51<br />

6.3. Maintenance………………………………………...……..…………… 52<br />

6.4. Experiment 1 – Performance……………………………….….….…… 53<br />

6.5. Experiment 2 – Accuracy…………………..………………………….. 59<br />

6.6. Experiment 3 – Security……………………….………………………. 61<br />

6.7. Experiment 4 – Conformance…………………..……………………… 65<br />

6.8. Conclusions………………………….…………...…………….……… 66<br />

7. Conclusions <strong>and</strong> Fur<strong>the</strong>r Work..……………………..………………….….. 68<br />

7.1. Conclusions…………………………………………………………….. 68<br />

7.2. Fur<strong>the</strong>r Work..………………………………………………………….. 69<br />

8. References………………………..…………………………..………………... 70<br />

9. Appendices………………………..….………………………………………... 73<br />

9.1. Appendix A: Diary Sheets<br />

9.2. Appendix B: Preliminary Gantt Chart<br />

9.3. Appendix C: Client Code<br />

9.4. Appendix D: Server Code<br />

9.5. Appendix E: <strong>Event</strong> Viewer Code<br />

9.6. Appendix F: Tester Application<br />

9.7. Appendix G: Processor Monitor<br />

9.8. Appendix H: HMAC Brute Force Cracker<br />

9.9. Appendix I: <strong>Windows</strong> <strong>Event</strong> <strong>Log</strong> Tests<br />

5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!