Skip to main navigation Skip to search Skip to main content

I3FS: An in-kernel integrity checker and intrusion detection file system

  • Swapnil Patil
  • , Anand Kashyap
  • , Gopalan Sivathanu
  • , Erez Zadok
  • Stony Brook University

Research output: Contribution to conferencePaperpeer-review

58 Scopus citations

Abstract

Today, improving the security of computer systems has become an important and difficult problem. Attackers can seriously damage the integrity of systems. Attack detection is complex and time-consuming for system administrators, and it is becoming more so. Current integrity checkers and IDSs operate as user-mode utilities and they primarily perform scheduled checks. Such systems are less effective in detecting attacks that happen between scheduled checks. These user tools can be easily compromised if an attacker breaks into the system with administrator privileges. Moreover, these tools result in significant performance degradation during the checks. Our system, called I3FS, is an on-access integrity checking file system that compares the checksums of files in real-time. It uses cryptographic checksums to detect unauthorized modifications to files and performs necessary actions as configured. I3FS is a stackable file system which can be mounted over any underlying file system (like Ext3 or NFS). I3FS's design improves over the open-source Tripwire system by enhancing the functionality, performance, scalability, and ease of use for administrators. We built a prototype of I3FS in Linux. Our performance evaluation shows an overhead of just 4% for normal user workloads.

Original languageEnglish
Pages67-77
Number of pages11
StatePublished - 2004
Event18th Large Installation System Administration Conference, LISA 2004 - Atlanta, United States
Duration: Nov 14 2004Nov 19 2004

Conference

Conference18th Large Installation System Administration Conference, LISA 2004
Country/TerritoryUnited States
CityAtlanta
Period11/14/0411/19/04

Fingerprint

Dive into the research topics of 'I3FS: An in-kernel integrity checker and intrusion detection file system'. Together they form a unique fingerprint.

Cite this