A Formalization of Digital Forensics

A Formalization of Digital Forensics
复制标题

数字取证的形式化

DOI:
--
复制
发表时间:
2004
期刊:
International Journal of Digital Evidence
影响因子:
--
通讯作者:
A. Krings
A. Krings
中科院分区:
--
文献类型:
--
作者:
Ryan Leigland;A. Krings

文献摘要

被引文献

相似文献

在入侵联网计算机系统的情况下,使用法医调查程序来检测攻击的范围或性质。在许多情况下,所采用的法医程序是以非正式的方式构建的,这可能会阻碍调查的有效性或完整性。我们提出了一个分析和构建取证程序的形式化模型,展示了形式化的优势。将给出模型的数学描述,演示要素的结构和它们之间的关系。该模型突出了取证程序的定义和更新、攻击覆盖的识别以及跨不同平台的可移植性。取证模型应用于一个关注Linux和OS X的真实场景。
Forensic investigative procedures are used in the case of an intrusion into a networked computer system to detect the scope or nature of the attack. In many cases, the forensic procedures employed are constructed in an informal manner that can impede the effectiveness or integrity of the investigation. We propose a formal model for analyzing and constructing forensic procedures, showing the advantages of formalization. A mathematical description of the model will be presented demonstrating the construction of the elements and their relationships. The model highlights definitions and updating of forensic procedures, identification of attack coverage, and portability across different platforms. The forensic model is applied in a real-world scenario with focus on Linux and OS X.