• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Chang, Cheng-Yue (Chang, Cheng-Yue.) | He, Jing-Sha (He, Jing-Sha.) (Scholars:何泾沙)

Indexed by:

CPCI-S

Abstract:

In this article, we propose a novel method that uses vulnerability evidence reasoning in network forensics analysis. Central to our method is the evidence graph model to support evidence presentation and reasoning. Based on the evidence graph, we propose a network forensics method that built the evidence graph on the basis of the network system vulnerabilities and environmental information. At the same time, the proposed method can realize the reconstruction of attack scenarios with high efficiency and with the capability of identifying multi-staged at-tacks through evidence reasoning. Results of the experiment that we conducted would show that the proposed method is complete and credible with certain reasoning ability, which can be a powerful tool for rapid and effective network forensic analysis.

Keyword:

vulnerability evidence reasoning evidence graph network forensics event vector

Author Community:

  • [ 1 ] [Chang, Cheng-Yue]Beijing Univ Technol, Sch Software Engn, Beijing 100124, Peoples R China
  • [ 2 ] [Chang, Cheng-Yue]Beijing Univ Technol, Beijing Engn Res Ctr IoT Software & Syst, Beijing 100124, Peoples R China

Reprint Author's Address:

  • [Chang, Cheng-Yue]Beijing Univ Technol, Sch Software Engn, Beijing 100124, Peoples R China

Show more details

Related Keywords:

Source :

PROCEEDINGS OF THE 2016 INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND INFORMATION SYSTEMS

ISSN: 2352-538X

Year: 2016

Volume: 52

Page: 245-249

Language: English

Cited Count:

WoS CC Cited Count: 0

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 4

Online/Total:215/10662634
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.