• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Zhang, Yuqiang (Zhang, Yuqiang.) | He, Jingsha (He, Jingsha.) (Scholars:何泾沙) | Xu, Jing (Xu, Jing.)

Indexed by:

CPCI-S Scopus

Abstract:

Network forensics investigations aims to find a chain of evidences that helps reconstructing the alleged attack scenario. This often requires the check of timestamps of the logs to reconstruct the event. Yet, it is relatively easy for criminals to tamper with the event logs, which results in the evidence graph with falsified timestamps and hence hinders the event reconstruction. The aim of this work paper is to propose an algorithm detects these falsified timestamps and re-creates the true evidence graph. Our algorithm relies on attack graphs of the system environment which models known vulnerability sequences that were exploited to launch the attack. We demonstrate the effectiveness and performance of our algorithm via a possible attack scenario in a network environment running a file server and a database server.

Keyword:

Evidence graph Network forensic Attack graph Falsified timestamps

Author Community:

  • [ 1 ] [Zhang, Yuqiang]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 2 ] [Xu, Jing]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China
  • [ 3 ] [He, Jingsha]Beijing Univ Technol, Sch Software Engn, Beijing, Peoples R China

Reprint Author's Address:

  • [Zhang, Yuqiang]Beijing Univ Technol, Coll Comp Sci, Beijing 100124, Peoples R China

Show more details

Related Keywords:

Related Article:

Source :

2015 8TH INTERNATIONAL SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE AND DESIGN (ISCID), VOL 2

ISSN: 2165-1701

Year: 2015

Page: 369-374

Language: English

Cited Count:

WoS CC Cited Count: 1

SCOPUS Cited Count: 1

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 0

Online/Total:606/10835672
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.