Joe Duin
Exploring DTrace as an Incident Response Tool for Unix Systems
Duin, Joe; Mckeown, Sean; Abubakar, Mwrwan
Authors
Dr Sean McKeown S.McKeown@napier.ac.uk
Lecturer
Mwrwan Abubakar M.Abubakar@napier.ac.uk
KTP Associate
Abstract
Critical National Infrastructure (CNI) is often the target of sophisticated and sustained cyber attacks perpetrated by advanced threat actors with considerable resources. These attacks can lead to interruptions in core services such as energy and water supplies, transportation, healthcare, and telecommunications. The effective and swift remediation of such attacks is contingent on the respective Digital Forensics and Incident Response (DFIR) professionals possessing the appropriate tooling and resources for the target environments. However, the Unix systems which often run critical infrastructure are poorly accommodated in comparison to their Windows and Linux counterparts. This paper seeks to expand the options available to DFIR analysts on Unix systems by exploring the potential for DTrace to serve as an Incident Response utility. DTrace is included in many Unix operating systems by default, while also having support for Linux, Windows and macOS, making it a useful pre-packaged solution. We explore the utility of DTrace, and the visibility it provides into the OS and kernel, through a variety of proof-of-concept case studies based on tactics and techniques in the MITRE ATT&CK framework. We find that DTrace’s functionality lends itself well to a real-time monitoring and probing solution for Unix systems, which could potentially form the basis of an Endpoint Detection and Response (EDR) solution to revolutionise Incident Response on such platforms.
Citation
Duin, J., Mckeown, S., & Abubakar, M. (2024, June). Exploring DTrace as an Incident Response Tool for Unix Systems. Presented at Cyber Science 2024, Edinburgh, Scotland
Presentation Conference Type | Conference Paper (published) |
---|---|
Conference Name | Cyber Science 2024 |
Start Date | Jun 27, 2024 |
End Date | Jun 28, 2024 |
Acceptance Date | Apr 30, 2024 |
Online Publication Date | Apr 23, 2025 |
Publication Date | 2025 |
Deposit Date | Jul 12, 2024 |
Publicly Available Date | Apr 24, 2026 |
Publisher | Springer |
Peer Reviewed | Peer Reviewed |
Pages | 169-193 |
Series Title | Springer Proceedings in Complexity |
Series ISSN | 2213-8692 |
Book Title | Proceedings of the International Conference on Cybersecurity, Situational Awareness and Social Media |
ISBN | 978-981-96-0400-5 |
DOI | https://doi.org/10.1007/978-981-96-0401-2_10 |
Public URL | http://researchrepository.napier.ac.uk/Output/3709433 |
Publisher URL | https://link.springer.com/book/9789819604005 |
Files
This file is under embargo until Apr 24, 2026 due to copyright reasons.
Contact repository@napier.ac.uk to request a copy for personal use.
You might also like
A forensic analysis of streaming platforms on Android OS
(2022)
Journal Article
InfoScout: An interactive, entity centric, person search tool.
(2016)
Presentation / Conference Contribution
Fast Filtering of Known PNG Files Using Early File Features
(2017)
Presentation / Conference Contribution
Microtargeting or Microphishing? Phishing Unveiled
(2020)
Presentation / Conference Contribution
Forensic Considerations for the High Efficiency Image File Format (HEIF)
(2020)
Presentation / Conference Contribution