Insight into Event Tracing for Windows
- The core logging and tracing facility in Windows operating system is called Event Tracing for Windows (ETW). Data sources providing events for ETW are instrumented all over the operating system. That means most hard- and software assets in a Windows system are instrumented with ETW and so are able to contribute low-level information. ETW can be used by developers and administrators to getThe core logging and tracing facility in Windows operating system is called Event Tracing for Windows (ETW). Data sources providing events for ETW are instrumented all over the operating system. That means most hard- and software assets in a Windows system are instrumented with ETW and so are able to contribute low-level information. ETW can be used by developers and administrators to get low-level information about operating system's activity. We describe existing tools to interact with the ETW faciltity and evaluate them based on defined criteria. Based on relevant application scenarios, we show the richness of informational content for debugging or detecting security incidents with ETW. The widely used instrumentation of ETW in the operating system and its application results also in security risks according to confidentiality. Based on common ETW providers we show the impact to confidentiality what ETW offers an adversary. At the end we evaluate solutions and approaches for a customizable telemetry infrastructure using ETW in large-scale environments.…
Document Type: | Bachelor Thesis |
---|---|
Zitierlink: | https://opus.hs-offenburg.de/3410 | Bibliografische Angaben |
Title (English): | Insight into Event Tracing for Windows |
Author: | Thomas Schlabach |
Advisor: | Andreas Schaad, Aleksander Milenkoski |
Year of Publication: | 2019 |
Date of final exam: | 2019/07/29 |
Publishing Institution: | Hochschule Offenburg |
Granting Institution: | Hochschule Offenburg |
Contributing Corporation: | Enno Rey Netzwerke GmbH (ERNW) |
Place of publication: | Offenburg |
Page Number: | viii, 61 |
Language: | English | Inhaltliche Informationen |
Institutes: | Fakultät Medien und Informationswesen (M+I) (bis 21.04.2021) |
Institutes: | Abschlussarbeiten / Bachelor-Studiengänge / UNITS |
DDC classes: | 000 Allgemeines, Informatik, Informationswissenschaft |
Tag: | Event Tracing for Windows; Logging; Telemetry; Windows | Formale Angaben |
Open Access: | Closed Access |
Licence (German): | Urheberrechtlich geschützt |
SWB-ID: | 1729086772 |