【24h】

Secured Proactive Network Forensic Framework

机译:安全积极的网络法医框架

获取原文

摘要

Nowadays, cyber crimes are increasing and have affected large organizations with highly sensitive information. Consequently, the affected organizations spent more resources analyzing the cyber crimes rather than detecting and preventing these crimes. Digital forensics is a process of recovery and investigation of material found in digital devices after the crime happens. Network forensics is a sub-branch of digital forensics relating to the monitoring and analysis of computer network traffic for the purposes of information gathering, legal evidence, or intrusion detection. Network forensics is about finding out how security was breached and taking appropriate measures for the future. The network investigation process can be done either in reactive or in proactive way. Reactive network forensic investigation is a old method and the investigation is done after the crime happened. In this method, the collected data is incomplete and it's difficult to prove in front of the court with the available data. Proactive network forensics is a used in live investigation and is considered as the current method of investigation which is used to investigate the attack with the live data. Since data collection is live, it's easy to prove the case with less time. The classification of data is used which helps to again reduce the time complexity and space complexity. These approaches are utilized in the preliminary analysis of a cyber crime and help improve and accelerate the decision making process. Now a days the hacker are expected to be within the organization, so the encryption over the collected data is used so that only the intended investigator can decrypt and analyze the data with his private key.
机译:如今,网络犯罪正在增加,并影响了具有高度敏感信息的大型组织。因此,受影响的组织花费了更多的资源分析了网络犯罪,而不是检测和预防这些罪行。数字取证是在犯罪发生后的数字设备中发现和调查的过程。网络取证是与信息收集,法律证据或入侵检测的目的的计算机网络流量监测和分析有关的数字取证的子分支。网络取证是关于了解如何违反安全和对未来采取适当措施的措施。网络调查过程可以以反应性或主动的方式进行。反应网络法医调查是一种旧方法,调查发生在犯罪发生后。在这种方法中,收集的数据是不完整的,并且难以在球场前面证明具有可用数据。主动网络取证是在实时调查中使用的,被认为是目前的调查方法,用于调查与实时数据的攻击。由于数据收集较少,因此很容易在更短的时间内证明这种情况。使用数据的分类,有助于再次降低时间复杂度和空间复杂度。这些方法是在网络犯罪的初步分析中,有助于改善和加速决策过程。现在,预计黑客将在组织内,因此使用对收集数据的加密,以便只有预期的调查员可以用私钥解密和分析数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号