Network forensics based on fuzzy logic and expert system

被引:42
|
作者
Liao, Niandong [1 ]
Tian, Shengfeng [1 ]
Wang, Tinghua [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing 100044, Peoples R China
关键词
Network forensics; Expert system; Fuzzy logic; Intrusion detection system; Vulnerability scanning; SAFETY CULTURE; MODELS; CLASSIFIER;
D O I
10.1016/j.comcom.2009.07.013
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network forensics is a research area that finds the malicious users by collecting and analyzing the intrusion or infringement evidence of computer crimes such as hacking. In the past, network forensics was only used by means of investigation. However, nowadays, due to the sharp increase of network traffic, not all the information captured or recorded will be useful for analysis or evidence. The existing methods and tools for network forensics show only simple results. The administrators have difficulty in analyzing the state of the damaged system without expert knowledge. Therefore, we need an effective and automated analyzing system for network forensics. In this paper, we firstly guarantee the evidence reliability as far as possible by collecting different forensic information of detection sensors. Secondly, we propose an approach based on fuzzy logic and expert system for network forensics that can analyze computer crimes in network environment and make digital evidences automatically. At the end of the paper, the experimental comparison results between our proposed method and other popular methods are presented. Experimental results show that the system can classify most kinds of attack types (91.5% correct classification rate on average) and provide analyzable and comprehensible information for forensic experts. (C) 2009 Elsevier B.V. All rights reserved.
引用
收藏
页码:1881 / 1892
页数:12
相关论文
共 50 条
  • [1] A fuzzy logic based expert system as a network forensics
    Kim, JS
    Kim, DG
    Noh, BN
    [J]. 2004 IEEE INTERNATIONAL CONFERENCE ON FUZZY SYSTEMS, VOLS 1-3, PROCEEDINGS, 2004, : 879 - 884
  • [2] A fuzzy expert system for network forensics
    Kim, JS
    Kim, M
    Noh, BN
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2004, PT 1, 2004, 3043 : 175 - 182
  • [3] How Expert is EXPERT for Fuzzy Logic-Based System!
    Bhole, Kalyani
    Agashe, Sudhir
    Wadgaonkar, Jagannath
    [J]. INTERNATIONAL PROCEEDINGS ON ADVANCES IN SOFT COMPUTING, INTELLIGENT SYSTEMS AND APPLICATIONS, ASISA 2016, 2018, 628 : 29 - 36
  • [4] A fuzzy-logic based expert system for cupola furnaces
    Kuppuswamy, S
    Abdelrahman, M
    [J]. PROCEEDINGS OF THE THIRTY-SIXTH SOUTHEASTERN SYMPOSIUM ON SYSTEM THEORY, 2004, : 304 - 308
  • [5] Towards an Expert System for the Field of Neurology Based on Fuzzy Logic
    Josefiok, Mirco
    Sauer, Juergen
    [J]. KI 2015: ADVANCES IN ARTIFICIAL INTELLIGENCE, 2015, 9324 : 333 - 340
  • [6] Fuzzy Logic Based Expert System for Students' Performance Evaluation
    Meenakshi
    Nagar, Pankaj
    [J]. 2015 2ND INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT (INDIACOM), 2015, : 803 - 808
  • [7] Fuzzy Logic Based Expert System for the Treatment of Mobile Tooth
    Mago, Vijay Kumar
    Mago, Anjali
    Sharma, Poonam
    Mago, Jagmohan
    [J]. SOFTWARE TOOLS AND ALGORITHMS FOR BIOLOGICAL SYSTEMS, 2011, 696 : 607 - 614
  • [8] A fuzzy logic based handwritten numeral recognition expert system
    Sadok, MM
    Alouani, AT
    [J]. PROCEEDINGS OF THE TWENTY-NINTH SOUTHEASTERN SYMPOSIUM ON SYSTEM THEORY, 1997, : 34 - 38
  • [9] Expert system using fuzzy Petri nets in computer forensics
    Hwang, Hyun-Uk
    Kim, Min-Soo
    Noh, Bong-Nam
    [J]. ADVANCES IN HYBRID INFORMATION TECHNOLOGY, 2007, 4413 : 312 - 322
  • [10] Loosely Coupled Navigation System Based On Expert System Using Fuzzy Logic
    Kalach, Genady G.
    Romanov, Alexey M.
    Tripolskiy, Pavel E.
    [J]. PROCEEDINGS OF THE XIX IEEE INTERNATIONAL CONFERENCE ON SOFT COMPUTING AND MEASUREMENTS (SCM 2016), 2016, : 167 - 169