【24h】

A Cooperative Multi-agent Approach to Computer Forensics

机译:计算机取证的合作多功能方法

获取原文

摘要

This article proposes the use of a collaborative multi-agent approach to develop a toolkit to assist the experts during the forensic examination process: MADIK - a Multi-Agent Digital Investigation ToolKit. The use of a multi-agent approach has been proved adequate, specially regarding the cooperative action of the autonomous specialized agents: HashSetAgent, FilePathAgent, TimelineAgent, FileSignatureAgent. Also the distributed nature of the multi-agent approach allows for better usage of computational resources, since agents can operate autonomously in different machines and environments. As part of our work, we have defined a four layer multi-agent architecture, as a metaphor to the organizational hierarchy levels, which is divided in strategic, tactical, perational and specialist levels. The proposed architecture was the base to the development of the toolkit, which was developed with a blackboard approach, implemented over the Java Agent DEvelopment Framework - JADE, using Java Expert System Shell - JESS. We have done some experiments with MADIK using real data and the results are encouraging. This paper focuses on the benefits of using the multi-agent approach to aid in the forensic examination process, specially regarding the cooperative action of the autonomous specialized agents, which we deem as a flexible and promising possibility that should be further exploredin the computer forensics scenario.
机译:本文提出使用协作的多智能经纪人方法来开发工具包,以协助专家在法医检查过程中:Madik - 一个多代理商数字调查工具包。已经证明了多智能经纪人方法的使用,特别是关于自治专业代理商的合作行动:Hashsetagent,FilesignAgent,Filesignatureagent。此外,多代理方法的分布性质允许更好地使用计算资源,因为代理可以在不同的机器和环境中自主运行。作为我们工作的一部分,我们已经定义了一个四层多代理体系结构,作为组织层次级别的隐喻,其分为战略,战术,理性和专业水平。拟议的体系结构是Toolkit的开发的基础,它是通过黑板方法开发的,通过Java代理开发框架 - jead,使用Java专家系统shell - Jess。我们使用真实数据与Madik进行了一些实验,结果令人鼓舞。本文侧重于利用多档方法援助法医检查过程的益处,特别是关于自主专业代理商的合作行动,我们认为应该进一步探索计算机取证方案的灵活性和有希望的可能性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号