Forensics and Privacy-enhancing Technologies — Logging and Collecting Evidence in Flocks
Olivier
2005
Citation information
M. S. Olivier. “Forensics and Privacy-enhancing Technologies — Logging and Collecting Evidence in Flocks”. In: Advances in Digital Forensics. Ed. by M. Pollitt and S. Shenoi. Springer, 2005, pp. 17–31Abstract
Flocks is a Privacy-enhancing Technology used to hide the Web usage patterns of employees in an organisation against profiling or mere inspection by administrators and other officials. However, Flocks is intended to support identification of senders of malicious requests by means of a legitimate forensics investigation.
The purpose of the paper is twofold. Firstly, it formalises what should be logged for an appropriate forensics investigation. Secondly, exactly what evidence should be explored once a malicious request has been noticed, is considered. It is argued that (i) evidence that would have been collected about a malicious request if the PET were not used, should still be collected, and (ii) evidence that becomes visible by some legitimate means because the PET is used, should be collected. However, information that has not become visible by such legitimate means, but is available because the PET is being used, should not be collected. In the latter case privacy concerns override the fact that a malicious request might be uncovered by investigating more logged information. These positions are defended and formalised using mathematical notation.
Full text
A pre- or postprint of the publication is available at https://mo.co.za/ask/flfor.pdf.Note that a username and password are required to download the full text. (Why?) Please e-mail me and I will send you a username and password.
Definitive version
The definitive version of the paper is available from the publisher.DOI: 10.1007/0-387-31163-7_2
BibTeX reference
@inproceedings(flfor,author={Martin S Olivier},
title={Forensics and Privacy-enhancing Technologies --- Logging and Collecting Evidence in {F}locks},
pages={17--31},
booktitle={Advances in Digital Forensics},
editor={Mark Pollitt and Sujeet Shenoi},
year={2005},
publisher={Springer} )