Disk Forensics of VxWorks File Systems for Aircraft Security

被引:1
|
作者
Mckeon, Stephen [1 ]
Roberge, Vincent [1 ]
机构
[1] Royal Mil Coll Canada, Elect & Comp Engn Dept, Kingston, ON K7K 7B4, Canada
关键词
Aircraft security; cyber-physical systems (CPSs); digital forensics; embedded systems; file system; operational technology security; real-time systems; DIGITAL FORENSICS;
D O I
10.1109/ICJECE.2023.3298846
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Modern avionics systems exhibit numerous networked electronic components ranging from sensors and actuators to dedicated subsystems, resulting in aircraft capable of processing and responding to information accurately, reliably, and in a timely fashion. Assuring the cyber security of these systems is a continual challenge and an active area of research; in the case where an aircraft has been compromised by a malicious actor, digital forensics can be utilized to investigate what and how the incident occurred. This research answers a simple, yet fundamental question on the security of aircraft: whether useful digital forensic artifacts be obtained from embedded real-time systems on aircraft. The highly reliable file system (HRFS) utilized by VxWorks was analyzed and described to align with the generalized descriptions of file system formats accepted in academia. The Sleuth Kit (TSK), an open-source forensic toolkit, was analyzed and extended to include functionality to support this file system, and a proof-of-concept implementation to obtain digital forensic artifacts from real-time operating systems on aircraft was developed. This research finds that the proposed implementation can perform file analysis and recovery from a VxWorks generated HRFS-formatted file system and can be generalized to show that embedded real-time systems can provide useful digital forensic artifacts.
引用
收藏
页码:278 / 287
页数:10
相关论文
共 50 条
  • [1] Forensics for advanced UNIX file systems
    Eckstein, K
    PROCEEDINGS FROM THE FIFTH IEEE SYSTEMS, MAN AND CYBERNETICS INFORMATION ASSURANCE WORKSHOP, 2004, : 377 - 385
  • [2] Security Breach and Forensics in Intelligent Systems
    Devi, M. S. Girija
    Nene, Manisha J.
    INFORMATION AND COMMUNICATION TECHNOLOGY FOR INTELLIGENT SYSTEMS, ICTIS 2018, VOL 2, 2019, 107 : 349 - 360
  • [3] Implementation of Comtrade distributed wave record based on VxWorks file systems
    Liu, Yi-Qing
    Gao, Wei-Cong
    Sun, Fa-En
    Yuan, Wen-Guang
    Teng, Zhao-Hong
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2011, 39 (04): : 113 - 116
  • [4] Strong security for distributed file systems
    Miller, E
    Long, D
    Freeman, W
    Reed, B
    CONFERENCE PROCEEDINGS OF THE 2001 IEEE INTERNATIONAL PERFORMANCE, COMPUTING, AND COMMUNICATIONS CONFERENCE, 2001, : 34 - 40
  • [5] Security, privacy and forensics in the enterprise information systems
    Gupta, B. B.
    Agrawal, Dharma P.
    ENTERPRISE INFORMATION SYSTEMS, 2021, 15 (04) : 445 - 447
  • [6] Understanding Security Vulnerabilities in File Systems
    Cai, Miao
    Huang, Hao
    Huang, Jian
    APSYS'19: PROCEEDINGS OF THE 10TH ACM SIGOPS ASIA-PACIFIC WORKSHOP ON SYSTEMS, 2019, : 8 - 15
  • [7] Security issues in network file systems
    Izquierdo, A
    Sierra, JM
    Hernández, JU
    Ribagorda, A
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 812 - 820
  • [8] AIRCRAFT SYSTEMS CYBER SECURITY
    De Cerchio, Raymond
    Riley, Chris
    2011 IEEE/AIAA 30TH DIGITAL AVIONICS SYSTEMS CONFERENCE (DASC), 2011,
  • [9] Column: File Cabinet Forensics
    Garfinkel, Simson
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2011, 6 (04) : 7 - 9
  • [10] File system journal forensics
    Swenson, Christopher
    Phillips, Raquel
    Shenoi, Sujeet
    ADVANCES IN DIGITAL FORENSIC III, 2007, 242 : 231 - +