...
首页> 外文期刊>Digital investigation >An Argumentation-Based Reasoner to Assist Digital Investigation and Attribution of Cyber-Attacks
【24h】

An Argumentation-Based Reasoner to Assist Digital Investigation and Attribution of Cyber-Attacks

机译:基于论证的推理,以协助数字调查和归因的网络攻击

获取原文
获取原文并翻译 | 示例
           

摘要

We expect an increase in the frequency and severity of cyber-attacks that comes along with the need for efficient security countermeasures. The process of attributing a cyber-attack helps to construct efficient and targeted mitigating and preventive security measures. In this work, we propose an argumentation-based reasoner (ABR) as a proof-of-concept tool that can help a forensics analyst during the analysis of forensic evidence and the attribution process. Given the evidence collected from a cyber-attack, our reasoner can assist the analyst during the investigation process, by helping him/her to analyze the evidence and identify who performed the attack. Furthermore, it suggests to the analyst where to focus further analyses by giving hints of the missing evidence or new investigation paths to follow. ABR is the first automatic reasoner that can combine both technical and social evidence in the analysis of a cyber-attack, and that can also cope with incomplete and conflicting information. To illustrate how ABR can assist in the analysis and attribution of cyber-attacks we have used examples of cyber-attacks and their analyses as reported in publicly available reports and online literature. We do not mean to either agree or disagree with the analyses presented therein or reach attribution conclusions. (C) 2020 The Author(s). Published by Elsevier Ltd.
机译:我们预计随着有效安全对策的需求,网络攻击的频率和严重程度增加。归因于网络攻击的过程有助于构建有效和有针对性的缓解和预防性的安全措施。在这项工作中,我们提出了一个基于论证的推理(ABR)作为概念验证工具,可以在分析法医证据和归因过程中有助于取证分析师。鉴于从网络攻击中收集的证据,我们的推理能够通过帮助他/她分析谁进行攻击的证据和识别来协助分析师。此外,它建议通过给予缺少证据或新调查途径来关注进一步分析的分析师。 ABR是第一个可以将技术和社会证据组合在对网络攻击分析中的第一个自动推理,并且还可以应对不完整和相互矛盾的信息。为了说明ABR如何协助进行网络攻击的分析和归属,我们使用了在公开的报告和在线文献中报告的网络攻击和分析的例子。我们并不意味着同意或不同意其中提出的分析或达到归因结论。 (c)2020提交人。 elsevier有限公司出版

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号