...
首页> 外文期刊>International journal of communications, network, and system sciences >Forensic Investigation in Communication Networks Using Incomplete Digital Evidences
【24h】

Forensic Investigation in Communication Networks Using Incomplete Digital Evidences

机译:使用不完整的数字证据对通信网络进行取证调查

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Security incidents targeting information systems have become more complex and sophisticated, and intruders might evade responsibility due to the lack of evidence to convict them. In this paper, we develop a system for Digital Forensic in Networking, called DigForNet, which is useful to analyze security incidents and explain the steps taken by the attackers. DigForNet combines intrusion response team knowledge with formal tools to identify the attack scenarios that have occurred and show how the system behaves for every step in the scenario. The attack scenarios construction is automated and the hypothetical concept is introduced within DigForNet to alleviate missing data related to evidences or investigator knowledge. DigForNet system supports the investigation of attack scenarios that integrate anti-investigation attacks. To exemplify the proposal, a case study is proposed.
机译:针对信息系统的安全事件变得更加复杂和复杂,由于缺乏定罪的证据,入侵者可能逃避责任。在本文中,我们开发了一个名为DigForNet的网络数字取证系统,该系统可用于分析安全事件并解释攻击者所采取的步骤。 DigForNet将入侵响应团队的知识与正式工具相结合,以识别已发生的攻击情况,并显示系统在此情况下每一步的行为。攻击场景的构建是自动化的,并且在DigForNet中引入了假想概念,以减轻与证据或调查人员知识有关的丢失数据。 DigForNet系统支持对集成了反调查攻击的攻击方案进行调查。为了举例说明该提议,提出了一个案例研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号