CREATING INTEGRATED EVIDENCE GRAPHS FOR NETWORK FORENSICS

被引:0
|
作者
Liu, Changwei [1 ]
Singhal, Anoop [2 ]
Wijesekera, Duminda [1 ]
机构
[1] George Mason Univ, Fairfax, VA 22030 USA
[2] Natl Inst Stand & Technol, Comp Secur Div, Gaithersburg, MD 20899 USA
来源
关键词
Network forensics; probabilistic evidence graphs; attack graphs; ATTACK; GENERATION;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Probabilistic evidence graphs can be used to model network intrusion evidence and the underlying dependencies to support network forensic analysis. The graphs provide a means for linking the probabilities associated with different attack paths with the available evidence. However, current work focused on evidence graphs assumes that all the available evidence can be expressed using a single, small evidence graph. This paper presents an algorithm for merging evidence graphs with or without a corresponding attack graph. The application of the algorithm to a file server and database server attack scenario yields an integrated evidence graph that shows the global scope of the attack. The global graph provides a broader context and better understandability than multiple local evidence graphs.
引用
收藏
页码:227 / 241
页数:15
相关论文
共 50 条
  • [21] Network forensics and challenges for cybersecurity
    Wojciech Mazurczyk
    Krzysztof Szczypiorski
    Hui Tian
    annals of telecommunications - annales des télécommunications, 2014, 69 : 345 - 346
  • [22] An architecture for SCADA network forensics
    Kilpatrick, T.
    Gonzalez, J.
    Chandia, R.
    Papa, M.
    Shenoi, S.
    ADVANCES IN DIGITAL FORENSICS II, 2006, 222 : 273 - +
  • [23] Network forensics on packet fingerprints
    Cho, Chia Yuan
    Lee, Sin Yeung
    Tan, Chung Pheng
    Tan, Yong Tai
    SECURITY AND PRIVACY IN DYNAMIC ENVIRONMENTS, 2006, 201 : 401 - +
  • [24] Network Forensics: Today and Tomorrow
    Shrivastava, Gulshan
    Sharma, Kavita
    Kumari, Reema
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 2234 - 2238
  • [25] Automated, integrated and connected: Creating an interoperable laboratory medicine network in the UK
    Box, S.
    Crees, R.
    Barrow, M.
    CLINICA CHIMICA ACTA, 2022, 530 : S243 - S244
  • [26] Strategies for creating a comprehensive, integrated coastal water quality monitoring network
    Sheehan, L
    CALIFORNIA AND THE WORLD OCEAN '97 - TAKING A LOOK AT CALIFORNIA'S OCEAN RESOURCES: AN AGENDA FOR THE FUTURE, VOLS 1 AND 2, CONFERENCE PROCEEDINGS, 1998, : 1442 - 1442
  • [27] Network Forensics with Neurofuzzy Techniques
    Aguirre Anaya, Eleazar
    Nakano-Miyatake, Mariko
    Perez Meana, Hector Manuel
    2009 52ND IEEE INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOLS 1 AND 2, 2009, : 848 - 852
  • [28] Network Forensics: Notions and Challenges
    Almulhem, Ahmad
    2009 IEEE INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING AND INFORMATION TECHNOLOGY (ISSPIT 2009), 2009, : 463 - 466
  • [29] Network monitoring for security and forensics
    Shanmugasundaram, Kulesh
    Memon, Nasir
    INFORMATION SYSTEMS SECURITY, PROCEEDINGS, 2006, 4332 : 56 - +
  • [30] High School Forensics: An Integrated Program
    Rousse, Thomas A.
    QUARTERLY JOURNAL OF SPEECH, 1942, 28 (02) : 250 - 251