GrAALF: Supporting Graphical Analysis of Audit Logs for Forensics

GrAALF: Supporting Graphical Analysis of Audit Logs for Forensics
复制标题

DOI:
10.1016/j.simpa.2021.100068
复制
发表时间:
2019-09
期刊:
Softw. Impacts
影响因子:
--
通讯作者:
Omid Setayeshfar;Christian Adkins;Matthew D. Jones;K. H. Lee;Prashant Doshi
Omid Setayeshfar;Christian Adkins;Matthew D. Jones;K. H. Lee;Prashant Doshi
中科院分区:
其他
文献类型:
--
作者:
Omid Setayeshfar;Christian Adkins;Matthew D. Jones;K. H. Lee;Prashant Doshi

文献摘要

相似文献

系统级日志在计算机取证中起着关键作用。它们详细地捕捉程序和用户之间的交互。然而,一台典型的计算机每小时会产生超过250万个系统事件,因此在此类日志中查找恶意活动需要计算和花费大量时间。我们介绍GrAALF一个图形系统,用于有效地加载、存储、处理、查询和显示计算机取证系统事件。与类似的系统相比,GrAALF提供了存储的灵活性、直观的查询和实时跟踪较长事件序列的能力,以帮助识别攻击。GrAALF是一个强大的分析解决方案,以支持计算机取证。
System-level logs play a critical role in computer forensics. They capture interactions between programs and users in detail. However, a typical computer generates more than 2.5 million system events hourly, making finding malicious activities in such logs compute and time-intensive.We introduce GrAALF a graphical system for efficiently loading, storing, processing, querying, and displaying system events for computer forensics. In comparison to similar systems, GrAALF offers the flexibility of storage, intuitive querying, and the tracing power for longer sequences of events in real-time to help identify attacks.GrAALF is a robust solution for analysis to support computer forensics.