首页> 外文会议>International Conference on Principles and Practice of Multi-Agent Systems >Helping Forensic Analysts to Attribute Cyber-Attacks: An Argumentation-Based Reasoner
【24h】

Helping Forensic Analysts to Attribute Cyber-Attacks: An Argumentation-Based Reasoner

机译:帮助取证分析师归因于网络攻击:基于论证的推理

获取原文
获取外文期刊封面目录资料

摘要

Discovering who performed a cyber-attack or from where it originated is essential in order to determine an appropriate response and future risk mitigation measures. In this work, we propose a novel argumentation-based reasoner for analyzing and attributing cyber-attacks that combines both technical and social evidence. Our reasoner helps the digital forensics analyst during the analysis of the forensic evidence by providing to the analyst the possible culprits of the attack, new derived evidence, hints about missing evidence, and insights about other paths of investigation. The proposed reasoner is flexible, deals with conflicting and incomplete evidence, and was tested on real cyber-attacks cases.
机译:发现谁进行了网络攻击或它起源于其起源的地方,以确定适当的反应和未来的风险缓解措施。在这项工作中,我们提出了一种新的基于争论的推理,用于分析和归因于技术和社会证据的网络攻击。我们的推理在通过向分析师提供攻击可能的罪行,新的派生证据,关于缺少证据的可能性以及关于其他路径的洞察力的可能性,有助于分析法医证据。拟议的推理员灵活,涉及相互冲突和不完整的证据,并在真正的网络攻击案件上进行了测试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号