Chapter 16 REMOTE FORENSIC ANALYSIS OF PROCESS CONTROL SYSTEMS
نویسندگان
چکیده
Forensic analysis can help maintain the security of process control systems: identifying the root cause of a system compromise or failure is useful for mitigating current and future threats. However, forensic analysis of control systems is complicated by three factors. First, live analysis must not impact the performance and functionality of a control system. Second, the analysis should be performed remotely as control systems are typically positioned in widely dispersed locations. Third, forensic techniques and tools must accommodate proprietary or specialized control system hardware, software, applications and protocols. This paper explores the use of a popular digital forensic tool, EnCase Enterprise, for conducting remote forensic examinations of process control systems. Test results in a laboratory-scale environment demonstrate the feasibility of conducting remote forensic analyses on live control systems.
منابع مشابه
Trace metal analysis by laser ablation-inductively coupled plasma-mass spectrometry and x-ray K-edge densitometry of forensic samples
.................................... ............................................................. vi CHAPTER 1. GENERAL INTRODUCTION ...................................................... 1 The History of Elemental Analysis ...................................................................... 1 ICP-MS ...............................................................................................
متن کاملChapter 4 REMOTE UPLOAD OF EVIDENCE OVER MOBILE AD HOC NETWORKS
In this work, we report on one aspect of an autonomous robot-based digital evidence acquisition system that we are developing. When forensic investigators operate within a hostile environment they may use remotely operated unmanned devices to gather digital evidence. These systems periodically upload the evidence to a remote central server using a mobile ad hoc network. In such cases, large pie...
متن کاملWindows Forensic Analysis DVD Toolkit, 2nd edition. By Harlan Carvey
The first edition of Harlan Carvey's text on Windows forensics quickly became a standard as an example of both a quality professional reference and a source of a font of practical information on the subject. The second edition promises to continue in that tradition. The quality contributions that Carvey makes on many professional listservs is but a harbin-ger of what can be found in his book, a...
متن کاملA study of post-mortem degradation of teeth to advance forensic DNA analysis as a tool for human identification
................................................................................................................................ iv Declaration ............................................................................................................................. v Acknowledgements ...............................................................................................................
متن کاملRemote Access Forensics for VNC and RDP on Windows Platform
There has been a greater implementation of remote access technologies in recent years. Many organisations are adapting remote technologies such as Virtual Network Computing (VNC) and remote desktop (RDP) applications as customer support application. They use these applications to remotely configure computers and solve computer and network issues of the client on spot. Therefore, the system admi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2014