首页> 外国专利> A Digital Forensic Audit System for Analyzing Useramp;rsquo;s Behaviors

A Digital Forensic Audit System for Analyzing Useramp;rsquo;s Behaviors

机译:用于分析用户行为的数字取证审计系统

摘要

Disclosed is a digital forensic audit system based on user′s behavior analysis which scans a using trace which is an image recorded in a window system and a file, extracts an event and a document file from the image to analyze a user′s behavior, and visualizes the event and the document file by analyzing the event and the document file. The system includes a document file extracting unit for extracting a document file of a logic level and file attributes; an event extracting unit for extracting an event including a generation time from the image to extract an event from an attribute (hereinafter, referred to as ′time attribute′) of a document file related to time; an analysis unit for analyzing the document file or the event based on attribute and time; and a visualizing unit for display the analyzed result (hereinafter, referred to as ′analysis result′) on a time-dimension coordinates. According to the digital forensic audit system, various kinds of data stored in storage mediums of computer terminals in a system are simply and easily analyzed and visualized, so that a user behavior can be analyzed. In addition, intentional and illegal breach of confidential information or individual information in the system can be always monitored and proofs can be rapidly obtained when an accident occurs.;COPYRIGHT KIPO 2014;[Reference numerals] (31) Scanning unit; (32) Document file extracting unit; (33) Event extracting unit; (34) Analysis unit; (35) visualization unit; (36) State extracting unit; (41) Event DB; (42) Document file DB; (43) Analysis result DB
机译:公开了一种基于用户行为分析的数字取证审计系统,该系统扫描使用迹线(窗口系统中记录的图像和文件),从图像中提取事件和文档文件,以分析用户行为,通过分析事件和文档文件来可视化事件和文档文件。该系统包括文档文件提取单元,用于提取逻辑级别和文件属性的文档文件;以及事件提取单元,用于从图像中提取包括生成时间的事件,以从与时间有关的文档文件的属性(以下称为“时间属性”)中提取事件。分析单元,用于基于属性和时间来分析文档文件或事件;可视化单元,用于在时间维度坐标上显示分析结果(以下称为“分析结果”)。根据数字取证审计系统,可以简单,容易地分析和可视化存储在系统中计算机终端的存储介质中的各种数据,从而可以分析用户行为。此外,在发生事故时,可以始终监视系统中机密信息或个人信息的有意和非法破坏,并可以迅速获取证据。; COPYRIGHT KIPO 2014; [参考数字](31)扫描单元; (32)文件档案提取单元; (33)事件提取单元; (34)分析单位; (35)可视化单元; (三十六)国家提取单位; (41)事件数据库; (42)文件文件DB; (43)分析结果数据库

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号