Towards proactive computer-system forensics
Towards proactive computer-system forensics
复制标题
迈向主动的计算机系统取证
DOI:
--
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
Bonnie Self
中科院分区:
文献类型:
--
作者:
P. Bradford;Marcus Brown;J. Perdue;Bonnie Self
We examine principles and approaches for proactive computer-system forensics. Proactive computer-system forensics is the design, construction and configuring of systems to make them most amenable to digital forensics analyses in the future. The primary goals of proactive computer-system forensics are system structuring and augmentation for automated data discovery, lead formation, and efficient data preservation. We propose: (1) using the Neyman-Pearson Lemma to proactively build online forensics tests with the best possible critical regions for hypothesis testing, and (2) using classical stopping rules for sequential hypothesis testing to determine which users are deviating from standard usage behavior and should be the focus of more investigative resources. Here the focus is on security breaches by the employees or stakeholders of an organization. The main measurements are event-driven logs of program executions.