首页> 外文OA文献 >Improving Distributed Forensics and Incident Response in Loosely Controlled Networked Environments
【2h】

Improving Distributed Forensics and Incident Response in Loosely Controlled Networked Environments

机译:在松散控制的网络环境中改善分布式取证和事件响应

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Mobile devices and virtualized appliances in the Internet of Things can be end nodes on varying networks owned by different parties over time, while still seamlessly participating in licit or illicit activities. Digital Forensics and Incident Response (DFIR) tools today struggle to perform digital investigations in such loosely controlled networked environments as they face several challenges including: scarcity of resources, availability, trust, privacy, data volumes, velocity and variety. In this paper we analyze the state of research in DFIR in networked environments, identifying the challenges facing DFIR tools particularly in loosely controlled network environments. We present the requirements for a system to address these challenges at the various steps of the typical digital investigation methodology. From this we identify the need for support from Peer to Peer (P2P) overlays and discuss their relative merits and drawbacks in order to identify those that would best support DFIR in loosely controlled networked environments. Finally we incorporate both structured and unstructured P2P overlays in various capacities in our architecture in order to organize devices in loosely controlled networks, using context information, thus enabling efficient capture, analysis and reporting of artifacts of use in digital investigations.
机译:随着时间的推移,物联网中的移动设备和虚拟设备可以成为不同方拥有的不同网络上的终端节点,同时仍可以无缝地参与合法或非法活动。如今,数字取证和事件响应(DFIR)工具难以在如此松散控制的网络环境中进行数字调查,因为它们面临着以下挑战:资源稀缺,可用性,信任,隐私,数据量,速度和多样性。在本文中,我们分析了网络环境中DFIR的研究现状,确定了DFIR工具面临的挑战,特别是在松散控制的网络环境中。我们提出了在典型的数字调查方法的各个步骤中应对这些挑战的系统的要求。由此,我们确定了对等网络(P2P)覆盖的支持需求,并讨论了它们的相对优缺点,以便确定在松散控制的网络环境中最能支持DFIR的那些。最后,我们在架构中以各种能力合并了结构化和非结构化的P2P覆盖图,以便使用上下文信息在松散控制的网络中组织设备,从而能够有效捕获,分析和报告数字调查中使用的工件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号