Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Analysis and Evaluation of the Windows Event Log - Bill Buchanan
Analysis and Evaluation of the Windows Event Log - Bill Buchanan
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
NAPIER UNIVERSITY<br />
SCHOOL OF COMPUTING<br />
PROJECT DIARY<br />
Student: Barrie Codona<br />
Supervisor: <strong>Bill</strong> <strong>Buchanan</strong><br />
Date: 9 th November 2007 Last diary date: 2 nd November 2007<br />
Objectives:<br />
1. Investigate <strong>the</strong> structure <strong>of</strong> NTFS to allow <strong>the</strong> by-passing <strong>of</strong> <strong>the</strong> operating system<br />
2. Investigate <strong>the</strong> possibility <strong>of</strong> modifying <strong>the</strong> contents <strong>of</strong> <strong>the</strong> hard disc while <strong>the</strong> event service is<br />
still running.<br />
3. Investigate <strong>the</strong> possibilities <strong>of</strong> modifying <strong>the</strong> contents <strong>of</strong> <strong>the</strong> MFT. (Getting it to point to ano<strong>the</strong>r<br />
file).<br />
4. Begin development <strong>of</strong> a system that will create a real time back up <strong>of</strong> <strong>the</strong> event logs.<br />
Progress:<br />
1. It was discovered that NTFS uses a system called <strong>the</strong> Master File System (MFT). This is contained<br />
on <strong>the</strong> root directory <strong>of</strong> <strong>the</strong> boot drive, its file name is $MFT. The MFT is a relation database that<br />
contains various information about all <strong>the</strong> files on <strong>the</strong> drive.<br />
2. Using ‘Directory Snoop’ to examine <strong>the</strong> MFT. This provides some information on <strong>the</strong> sectors <strong>of</strong><br />
<strong>the</strong> event log files. Unfortunately this test did not return <strong>the</strong> results that were hoped for, however it<br />
has given some insight on how <strong>the</strong> event service works.<br />
3. Based upon <strong>the</strong> results from <strong>the</strong> last test, it has been concluded that even if it were possible to<br />
modify <strong>the</strong> MFT <strong>and</strong> get it to point to a new file, <strong>the</strong> system would overwrite <strong>the</strong> contents <strong>of</strong> <strong>the</strong> file<br />
with <strong>the</strong> contents it has in memory when <strong>the</strong> computer was shutdown. Perhaps <strong>the</strong> memory could<br />
be modified in a similar way to <strong>the</strong> disc.<br />
4. Contained within <strong>the</strong> Week 6 Weekly Report is an initial design specification <strong>of</strong> what <strong>the</strong><br />
application might do.<br />
Supervisor’s Comments:<br />
Version 2<br />
Napier University