首页> 外文会议>International Conference on Advances in Social Networks Analysis and Mining >Towards a unified agent-based approach for real time computer forensic evidence collection
【24h】

Towards a unified agent-based approach for real time computer forensic evidence collection

机译:走向基于统一的代理方法,实时计算机取证证据收集

获取原文

摘要

In this paper we present preliminary results for a real time computer forensics agent that logs computer activity on a Windows computer system for subsequent forensic investigation. The agent, which is developed using the .NET 2010 framework includes six modules. Each module is dedicated to keep track and record a specific category of user activities. For instance, the Windows Event Watcher logs the Windows OS events and the Removable Devices Detector logs any external devices that are plugged in or removed from a system. Currently, the aforementioned two modules are implemented and tested with carefully designed scenarios using Windows XP and Windows 7 operating systems.
机译:在本文中,我们为实时计算机取证代理提出了初步结果,该代理在Windows计算机系统上记录计算机活动以进行后续法医调查。使用.NET 2010框架开发的代理包括六个模块。每个模块都专用于跟踪并记录特定的用户活动类别。例如,Windows事件观察器记录Windows OS事件,可移动设备检测器会记录插入或从系统中删除的任何外部设备。目前,使用Windows XP和Windows 7操作系统的仔细设计方案来实现和测试上述两种模块。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号