首页> 外国专利> Associating network and storage activities for forensic analysis

Associating network and storage activities for forensic analysis

机译:关联网络和存储活动以进行法医分析

摘要

An improved technique for performing forensic investigations in an electronic system includes capturing and associating multiple streams of information. The streams include a network stream and a storage stream. The network stream includes a record of network activities. The storage stream includes a record of storage activities. In some examples, the storage stream includes both disk activities and memory activities, including both reads and writes. Records of the captured streams are stored in a data storage array and are associated by applying a common timing reference to the records. A comprehensive history is thus obtained, with both network and storage activities coordinated in time, to enable examination and tracing of suspect or malicious occurrences across network and storage domains. The improved technique can be used in both physical and virtual computing environments and affords particular advantages in virtual and cloud environments where forensic analysis has proven to be difficult.
机译:在电子系统中执行取证调查的一种改进技术包括捕获和关联多个信息流。这些流包括网络流和存储流。网络流包括网络活动的记录。存储流包括存储活动的记录。在一些示例中,存储流包括磁盘活动和存储器活动,包括读取和写入。捕获的流的记录存储在数据存储阵列中,并通过对记录应用通用的时序参考来关联它们。这样就获得了全面的历史记录,并及时协调了网络和存储活动,从而可以跨网络和存储域检查和跟踪可疑或恶意事件。改进的技术可以在物理和虚拟计算环境中使用,并且在证明取证分析很困难的虚拟和云环境中具有特殊优势。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号