作者
Ahmad Roshidi Amran, Amna Saad
发表日期
2014/1/17
研讨会论文
2014 World Congress on Computer Applications and Information Systems (WCCAIS)
页码范围
1-9
出版商
IEEE
简介
With increasing crimes and attacks being committed online by adversaries from remote sites, it is vital for law enforcement and public security that forensics investigation into the nature and source of these network attacks be effective and successful in bringing the criminals to justice. The network forensics investigation process is complex and processing-intensive such as sifting through network traffic and examining them for evidence, thus it is desirable to approach this task systematically and efficiently with as much structure as is feasible. This paper proposes a model for network forensics analysis that captures appropriately defined adversarial capability and structured by a layered approach to investigation. The former approach eliminates the need to presume on the adversarys behaviour and is independent of specific attack styles, thus is generic; while the latter approach facilitates a more network-intuitive and …
引用总数
20182019202020212022202314211
学术搜索中的文章