A Formalization of Digital Forensics
A Formalization of Digital Forensics
复制标题
数字取证的形式化
DOI:
--
复制
发表时间:
2004
期刊:
影响因子:
--
通讯作者:
A. Krings
中科院分区:
文献类型:
--
作者:
Ryan Leigland;A. Krings
Forensic investigative procedures are used in the case of an intrusion into a networked computer system to detect the scope or nature of the attack. In many cases, the forensic procedures employed are constructed in an informal manner that can impede the effectiveness or integrity of the investigation. We propose a formal model for analyzing and constructing forensic procedures, showing the advantages of formalization. A mathematical description of the model will be presented demonstrating the construction of the elements and their relationships. The model highlights definitions and updating of forensic procedures, identification of attack coverage, and portability across different platforms. The forensic model is applied in a real-world scenario with focus on Linux and OS X.