25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

NAPIER UNIVERSITY<br />

SCHOOL OF COMPUTING<br />

PROJECT DIARY<br />

Student: Barrie Codona<br />

Supervisor: <strong>Bill</strong> <strong>Buchanan</strong><br />

Date: 9 th November 2007 Last diary date: 2 nd November 2007<br />

Objectives:<br />

1. Investigate <strong>the</strong> structure <strong>of</strong> NTFS to allow <strong>the</strong> by-passing <strong>of</strong> <strong>the</strong> operating system<br />

2. Investigate <strong>the</strong> possibility <strong>of</strong> modifying <strong>the</strong> contents <strong>of</strong> <strong>the</strong> hard disc while <strong>the</strong> event service is<br />

still running.<br />

3. Investigate <strong>the</strong> possibilities <strong>of</strong> modifying <strong>the</strong> contents <strong>of</strong> <strong>the</strong> MFT. (Getting it to point to ano<strong>the</strong>r<br />

file).<br />

4. Begin development <strong>of</strong> a system that will create a real time back up <strong>of</strong> <strong>the</strong> event logs.<br />

Progress:<br />

1. It was discovered that NTFS uses a system called <strong>the</strong> Master File System (MFT). This is contained<br />

on <strong>the</strong> root directory <strong>of</strong> <strong>the</strong> boot drive, its file name is $MFT. The MFT is a relation database that<br />

contains various information about all <strong>the</strong> files on <strong>the</strong> drive.<br />

2. Using ‘Directory Snoop’ to examine <strong>the</strong> MFT. This provides some information on <strong>the</strong> sectors <strong>of</strong><br />

<strong>the</strong> event log files. Unfortunately this test did not return <strong>the</strong> results that were hoped for, however it<br />

has given some insight on how <strong>the</strong> event service works.<br />

3. Based upon <strong>the</strong> results from <strong>the</strong> last test, it has been concluded that even if it were possible to<br />

modify <strong>the</strong> MFT <strong>and</strong> get it to point to a new file, <strong>the</strong> system would overwrite <strong>the</strong> contents <strong>of</strong> <strong>the</strong> file<br />

with <strong>the</strong> contents it has in memory when <strong>the</strong> computer was shutdown. Perhaps <strong>the</strong> memory could<br />

be modified in a similar way to <strong>the</strong> disc.<br />

4. Contained within <strong>the</strong> Week 6 Weekly Report is an initial design specification <strong>of</strong> what <strong>the</strong><br />

application might do.<br />

Supervisor’s Comments:<br />

Version 2<br />

Napier University

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!