Network Forensics

Network Forensics
复制标题

网络取证

DOI:
--
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
B. Laurie
B. Laurie
中科院分区:
--
文献类型:
--
作者:
B. Laurie

文献摘要

被引文献

相似文献

该词典将法医学定义为“在刑事或民事法庭上利用科学和技术调查和确立事实”。然而,我更感兴趣的是计算机世界中常见的用法:使用计算机受到攻击后留下的证据来确定攻击是如何进行的以及攻击者做了什么。取证的标准方法是查看在攻击发生后可以检索到什么,但这还有很多需要改进的地方。第一个也是最明显的问题是,成功的攻击者往往会竭尽全力确保他们掩盖自己的踪迹。第二,不成功的攻击往往被忽视,即使被注意到,也几乎没有信息可用于帮助诊断。
The dictionary defines forensics as “the use of science and technology to investigate and establish facts in criminal or civil courts of law.” I am more interested, however, in the usage common in the computer world: using evidence remaining after an attack on a computer to determine how the attack was carried out and what the attacker did. The standard approach to forensics is to see what can be retrieved after an attack has been made, but this leaves a lot to be desired. The first and most obvious problem is that successful attackers often go to great lengths to ensure that they cover their trails. The second is that unsuccessful attacks often go unnoticed, and even when they are noticed, little information is available to assist with diagnosis.