...
首页> 外文期刊>ACM transactions on information and system security >A Graph Based Approach Toward Network Forensics Analysis
【24h】

A Graph Based Approach Toward Network Forensics Analysis

机译:基于图的网络取证分析方法

获取原文
获取原文并翻译 | 示例

摘要

In this article we develop a novel graph-based approach toward network forensics analysis. Central to our approach is the evidence graph model that facilitates evidence presentation and automated reasoning. Based on the evidence graph, we propose a hierarchical reasoning framework that consists of two levels. Local reasoning aims to infer the functional states of network entities from local observations. Global reasoning aims to identify important entities from the graph structure and extract groups of densely correlated participants in the attack scenario. This article also presents a framework for interactive hypothesis testing, which helps to identify the attacker's nonexplicit attack activities from secondary evidence. We developed a prototype system that implements the techniques discussed. Experimental results on various attack datasets demonstrate that our analysis mechanism achieves good coverage and accuracy in attack group and scenario extraction with less dependence on hard-coded expert knowledge.
机译:在本文中,我们开发了一种新颖的基于图的网络取证分析方法。我们的方法的核心是证据图模型,该模型有助于证据显示和自动推理。基于证据图,我们提出了一个由两个层次组成的层次推理框架。本地推理旨在从本地观察中推断网络实体的功能状态。全局推理旨在从图结构中识别重要实体,并在攻击场景中提取出紧密相关的参与者组。本文还提供了交互式假设测试的框架,该框架有助于从辅助证据中识别攻击者的非显式攻击活动。我们开发了实现所讨论技术的原型系统。在各种攻击数据集上的实验结果表明,我们的分析机制在攻击组和场景提取中具有良好的覆盖率和准确性,而对硬编码专家知识的依赖则较少。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号