首页> 外文OA文献 >Application of intrusion detection system in automatic evidence collection using digital forensics
【2h】

Application of intrusion detection system in automatic evidence collection using digital forensics

机译:入侵检测系统在数字取证自动取证中的应用

摘要

In network security, Intrusion Detection System (IDS) is one of the popular and effective mechanism to secure the network. The aim of IDS is to offer a layer of protection against unauthorized (or malicious) uses of systems by sensing the vulnerability in the system or misuse of a security policy, and alerts system administrator to an ongoing (or recent) attack. IDSs function is limited to detect the intrusion and respond to administrator about the intrusion by monitoring the system continuously. IDS is not able to preserve evidence about the intrusion, which makes it difficult to see the damage in the system and gather information about the attack and hence make it impossible to catch the intruder. Although evidence can be collected from IDS’s and system log files, but integrity, reliability, and completeness of such evidence are doubtful as log files can also be altered by intruder. In order to preserve evidence in its original form we have proposed “Application of Intrusion Detection System in automatic Evidence Collection using Digital Forensics”. In our model whenever an intrusion is detected, IDS notify the administrator by sending an alert as well as activate the digital forensic tool to capture the current state of the system. This captured system image contains all the information of the system of the time when attack was taking place. Hence such image can be used as evidence in legal proceeding. We used both signature based IDS and anomaly based IDS in the work and observe that signature based IDS is not able to detect novel threats while anomaly based IDS is able to detect such threats.
机译:在网络安全中,入侵检测系统(IDS)是保护网络安全的流行且有效的机制之一。 IDS的目的是通过感知系统中的漏洞或滥用安全策略来提供一层保护,以防止未经授权(或恶意)使用系统,并警告系统管理员正在进行的(或最近的)攻击。 IDS的功能仅限于检测入侵并通过持续监视系统来就入侵对管理员做出响应。 IDS无法保存有关入侵的证据,这使得很难看到系统中的损坏并难以收集有关攻击的信息,因此无法捕获入侵者。尽管可以从IDS和系统日志文件中收集证据,但是这些证据的完整性,可靠性和完整性令人怀疑,因为入侵者还可以更改日志文件。为了保留原始形式的证据,我们提出了“入侵检测系统在使用数字取证的自动证据收集中的应用”。在我们的模型中,只要检测到入侵,IDS就会通过发送警报以及激活数字取证工具来捕获系统当前状态来通知管理员。捕获的系统映像包含发生攻击时的系统的所有信息。因此,这种图像可以用作法律程序中的证据。我们在工作中同时使用了基于签名的IDS和基于异常的IDS,并观察到基于签名的IDS不能检测到新颖的威胁,而基于异常的IDS可以检测到此类威胁。

著录项

  • 作者

    Jain A K;

  • 作者单位
  • 年度 2014
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号