Skip to main content

Research Repository

Advanced Search

Exploring DTrace as an Incident Response Tool for Unix Systems

Duin, Joe; Mckeown, Sean; Abubakar, Mwrwan

Authors

Joe Duin



Abstract

Critical National Infrastructure (CNI) is often the target of sophisticated and sustained cyber attacks perpetrated by advanced threat actors with considerable resources. These attacks can lead to interruptions in core services such as energy and water supplies, transportation, healthcare, and telecommunications. The effective and swift remediation of such attacks is contingent on the respective Digital Forensics and Incident Response (DFIR) professionals possessing the appropriate tooling and resources for the target environments. However, the Unix systems which often run critical infrastructure are poorly accommodated in comparison to their Windows and Linux counterparts. This paper seeks to expand the options available to DFIR analysts on Unix systems by exploring the potential for DTrace to serve as an Incident Response utility. DTrace is included in many Unix operating systems by default, while also having support for Linux, Windows and macOS, making it a useful pre-packaged solution. We explore the utility of DTrace, and the visibility it provides into the OS and kernel, through a variety of proof-of-concept case studies based on tactics and techniques in the MITRE ATT&CK framework. We find that DTrace’s functionality lends itself well to a real-time monitoring and probing solution for Unix systems, which could potentially form the basis of an Endpoint Detection and Response (EDR) solution to revolutionise Incident Response on such platforms.

Citation

Duin, J., Mckeown, S., & Abubakar, M. (2024, June). Exploring DTrace as an Incident Response Tool for Unix Systems. Presented at Cyber Science 2024, Edinburgh, Scotland

Presentation Conference Type Conference Paper (published)
Conference Name Cyber Science 2024
Start Date Jun 27, 2024
End Date Jun 28, 2024
Acceptance Date Apr 30, 2024
Online Publication Date Apr 23, 2025
Publication Date 2025
Deposit Date Jul 12, 2024
Publicly Available Date Apr 24, 2026
Publisher Springer
Peer Reviewed Peer Reviewed
Pages 169-193
Series Title Springer Proceedings in Complexity
Series ISSN 2213-8692
Book Title Proceedings of the International Conference on Cybersecurity, Situational Awareness and Social Media
ISBN 978-981-96-0400-5
DOI https://doi.org/10.1007/978-981-96-0401-2_10
Public URL http://researchrepository.napier.ac.uk/Output/3709433
Publisher URL https://link.springer.com/book/9789819604005

Files

This file is under embargo until Apr 24, 2026 due to copyright reasons.

Contact repository@napier.ac.uk to request a copy for personal use.







You might also like



Downloadable Citations