首页> 外国专利> Automated forensics of computer systems using behavioral intelligence

Automated forensics of computer systems using behavioral intelligence

机译:使用行为智能的计算机系统自动取证

摘要

A method for computer system forensics includes receiving an identification of at least one host computer (26) that has exhibited an anomalous behavior, in a computer network (24) comprising multiple host computers. Respective images (68) of the host computers in the network are assembled using image information collected with regard to the host computers. A comparison is made between at least one positive image of the at least one host computer, assembled using the image information collected following occurrence of the anomalous behavior, and one or more negative images assembled using the image information collected with respect to one or more of the host computers not exhibiting the anomalous behavior. Based on the comparison, a forensic indicator of the anomalous behavior is extracted from the positive and negative images.
机译:一种用于计算机系统取证的方法,包括在包括多个主机的计算机网络(24)中接收至少一个表现出异常行为的主机(26)的标识。网络中的主计算机的各个图像(68)使用关于主计算机收集的图像信息进行组装。在至少一台主机的至少一个正图像(使用在发生异常行为之后收集的图像信息进行组装)与一个或多个负图像(使用相对于一个或多个以下信息收集的图像信息进行组装)之间进行比较主机未表现出异常行为。基于比较,从正图像和负图像中提取异常行为的取证指标。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号