首页> 外文会议>IEEE Symposium on Computers and Communications >Events and causal factors charting of kernel traces for root cause analysis
【24h】

Events and causal factors charting of kernel traces for root cause analysis

机译:绘制内核跟踪的事件和因果图以进行根本原因分析

获取原文

摘要

Constructing an events and causal factors chart can assist investigators in conducting an in-depth investigation and identifying the root causes of incidents. We regard kernel traces as one of the potential evidence sources for forensic readiness, and propose a systematic approach to construct an events and causal factors chart from kernel traces by employing layers of abstraction. Through employing graphical elements to represent kernel traces and applying clustering techniques to reduce the trace volume, the proposed approach can alleviate the complexity and quantity problems in kernel traces. Moreover, the proposed approach is helpful in improving the readability and understand-ability of kernel traces, facilitating effective communication of the investigation findings, and providing flexibility in depth of investigation.
机译:构造事件和因果图可以帮助调查人员进行深入调查并确定事件的根本原因。我们将内核跟踪作为法医准备的潜在证据来源之一,并提出了一种系统的方法,通过使用抽象层从内核跟踪构造事件和因果图。通过使用图形元素来表示内核跟踪并应用聚类技术来减少跟踪量,所提出的方法可以缓解内核跟踪中的复杂性和数量问题。此外,提出的方法有助于提高内核跟踪的可读性和可理解性,促进调查结果的有效沟通,并提供调查深度的灵活性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号