A Graph Based Approach Toward Network Forensics Analysis

被引:32
作者
Wang, Wei [1 ]
Daniels, Thomas E. [1 ]
机构
[1] Iowa State Univ, Dept Elect & Comp Engn, Ames, IA 50011 USA
关键词
Security; network forensics; evidence graph; hierarchical reasoning;
D O I
10.1145/1410234.1410238
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this article we develop a novel graph-based approach toward network forensics analysis. Central to our approach is the evidence graph model that facilitates evidence presentation and automated reasoning. Based on the evidence graph, we propose a hierarchical reasoning framework that consists of two levels. Local reasoning aims to infer the functional states of network entities from local observations. Global reasoning aims to identify important entities from the graph structure and extract groups of densely correlated participants in the attack scenario. This article also presents a framework for interactive hypothesis testing, which helps to identify the attacker's nonexplicit attack activities from secondary evidence. We developed a prototype system that implements the techniques discussed. Experimental results on various attack datasets demonstrate that our analysis mechanism achieves good coverage and accuracy in attack group and scenario extraction with less dependence on hard-coded expert knowledge.
引用
收藏
页数:33
相关论文
共 38 条
  • [1] [Anonymous], 2001, Proceeding of the 2001 ACM Workshop on Data Mining for Security Applications
  • [2] [Anonymous], P 18 INT C N AM FUZZ
  • [3] [Anonymous], 2003, P 10 ACM C COMP COMM, DOI DOI 10.1145/948109.948137
  • [4] [Anonymous], 2005, Managing Cyber Threats: Issues, Approaches and Challenges
  • [5] Carrier B D., 2004, Journal of Forensic Sciences
  • [6] CARVALHO JP, 1999, P 8 INT FUZZ SYST AS
  • [7] CUPPENS F, 2002, P 2002 IEEE S SEC PR
  • [8] Cuppitt J, 2001, ECPA 2001 3 EUR C PR, V1, P7
  • [9] DAIN O, 2001, P 2001 IEEE WORKSH I, P231
  • [10] *DARPA, MIT LINC LAB 2000 DA