首页> 外文OA文献 >Visualization for network forensic analyses: extending the Forensic Log Investigator (FLI)
【2h】

Visualization for network forensic analyses: extending the Forensic Log Investigator (FLI)

机译:网络取证分析的可视化:扩展取证日志调查器(FLI)

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In a network attack investigation, the mountain of information collected from varying sources can be daunting. Investigators face significant challenges in being able to correlate findings from these sources, given difficulties with time synchronization. In addition, it is difficult to obtain summary or overview information for one set of data, much less the entire case. This, in turn, makes it nearly impossible to accurately identify missing information.;Identifying these information gaps is one problem, yet another is filling them in. Investigators must rely on legal processes and requests to obtain the information they need. However, it is extremely important they are aware of cases or events that cross jurisdictional boundaries. Where tools exist to assist in evidence overview, they do not contain the necessary geographic information for investigators to quickly ascertain the location of those involved.;In addition to these difficulties, investigators need to perform several types of analysis on the evidence that has been collected. Several of these analyses cannot typically be performed on data from multiple log files, since they are based on timing data. Furthermore, it is difficult to understand results from these analyses without visual representation, and there are no tools to bring them together in a single frame.;This thesis details the design and implementation of an analysis and visualization extension for the Forensic Log Investigator, or FLI. FLI is a web-based analysis and visualization architecture built on advanced technologies and enterprise infrastructure. This extension assists investigators by providing the ability to correlate evidence and analysis across traditional log file and analysis method boundaries, identify information gaps, and perform analysis in accordance with published evidence handling guidelines.
机译:在网络攻击调查中,从不同来源收集的大量信息可能令人生畏。考虑到时间同步的困难,研究人员在关联这些来源的发现方面面临重大挑战。另外,很难获得一组数据的摘要或概述信息,更不用说整个情况了。反过来,这几乎使准确识别丢失的信息几乎成为不可能。识别这些信息空白是一个问题,另一个问题正在填补。调查人员必须依靠法律程序和请求来获取他们所需的信息。但是,让他们知道跨越管辖范围的案件或事件非常重要。如果存在协助进行证据概述的工具,则它们不包含调查人员用来迅速确定所涉人员位置的必要地理信息。除了这些困难之外,调查人员还需要对收集到的证据进行几种类型的分析。 。这些分析中的一些分析通常基于时序数据,因此通常无法对多个日志文件中的数据进行分析。此外,在没有可视化表示的情况下很难理解这些分析的结果,并且没有将它们整合到一个框架中的工具。;本论文详细介绍了法医记录调查员的分析和可视化扩展的设计和实现,或者FLI。 FLI是基于Web的分析和可视化体系结构,建立在先进技术和企业基础架构之上。此扩展通过提供跨传统日志文件和分析方法边界关联证据和分析,识别信息空白并根据已发布证据处理指南执行分析的功能,为研究人员提供了帮助。

著录项

  • 作者

    Miller, Paul Michael;

  • 作者单位
  • 年度 2008
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号