signature=0333d4ccb60a7c4b83f2c60488a8fc33,Signature Based Detection of User Events for Post-mortem ...

本文介绍了一种新的用户事件重建方法,通过展示如何生成和实施基于签名的分析技术,从系统尸检中收集的低级别痕迹推断出高层次用户行为。传统数字取证分析和由此产生的推断被审视,然后证明这种从低级痕迹到高级事件的自然推断过程可以使用签名匹配技术进行编码。作为概念验证,为三个流行的Windows程序创建并应用了简单的签名。
摘要由CSDN通过智能技术生成

摘要:

This paper introduces a novel approach to user event reconstruction by showing the practicality of generating and implementing signature-based analysis methods to reconstruct high-level user actions from a collection of low-level traces found during a post-mortem forensic analysis of a system. Traditional forensic analysis and the inferences an investigator normally makes when given digital evidence, are examined. It is then demonstrated that this natural process of inferring high-level events from low-level traces may be encoded using signature-matching techniques. Simple signatures using the defined method are created and applied for three popular Windows-based programs as a proof of concept.

展开

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值