Towards proactive computer-system forensics

Towards proactive computer-system forensics
复制标题

迈向主动的计算机系统取证

DOI:
--
复制
发表时间:
2004
期刊:
International Conference on Information Technology
影响因子:
--
通讯作者:
Bonnie Self
Bonnie Self
中科院分区:
--
文献类型:
--
作者:
P. Bradford;Marcus Brown;J. Perdue;Bonnie Self

文献摘要

被引文献

相似文献

我们研究了主动计算机系统取证的原则和方法。主动计算机系统取证是系统的设计,构造和配置,使其在未来最适合数字取证分析。主动计算机系统取证的主要目标是系统结构化和增强,以实现自动数据发现、线索形成和有效的数据保存。我们建议:(1)使用Neyman-Pearson引理来主动构建在线取证测试,其中具有用于假设检验的最佳可能临界区域,以及(2)使用用于顺序假设检验的经典停止规则来确定哪些用户偏离了标准使用行为,并且应该成为更多调查资源的焦点。这里的重点是组织的员工或利益相关者的安全漏洞。主要的度量是程序执行的事件驱动日志。
We examine principles and approaches for proactive computer-system forensics. Proactive computer-system forensics is the design, construction and configuring of systems to make them most amenable to digital forensics analyses in the future. The primary goals of proactive computer-system forensics are system structuring and augmentation for automated data discovery, lead formation, and efficient data preservation. We propose: (1) using the Neyman-Pearson Lemma to proactively build online forensics tests with the best possible critical regions for hypothesis testing, and (2) using classical stopping rules for sequential hypothesis testing to determine which users are deviating from standard usage behavior and should be the focus of more investigative resources. Here the focus is on security breaches by the employees or stakeholders of an organization. The main measurements are event-driven logs of program executions.