计算机科学 ›› 2009, Vol. 36 ›› Issue (11): 65-67.

• 计算机网络与信息安全 • 上一篇    下一篇

一种自适应的动态取证机制

陈琳,李之棠,高翠霞   

  1. (华中科技大学计算机学院 武汉430074);(华中科技大学网络中心 武汉430074)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家自然科学基金(60573120)资助。

Self-adaptive Mechanism of Dynamic Forensics

CHEN Lin,LI Zhi-tang,GAO Cui-xia   

  • Online:2018-11-16 Published:2018-11-16

摘要: 随着网络入侵技术和计算机犯罪技术的发展,动态取证变得越来越重要。利用入侵检测系统和蜜罐来实现入侵取证的方法在取证的实时性方面有很大优势,但这些方法没有过多考虑系统被入侵时证据可靠性以及系统可靠 性的问题,而且取证的时机难以掌握。提出了一种自适应的动态取证方法,该方法采用入侵检测系统作为取证触发器,利用影子蜜罐对疑似攻击进行确认和进一步观察分析,自适应调整取证过程,获取关键证据,最后采用有限状态机对该机制进行建模,并对该机制中的状态转换时机、影子蜜罐、证据安全存储等关键技术进行描述。利用该机制来实现动态取证,可以使得取证过程更可控,可以减少不必要的证据量,并增强系统的容侵性。

关键词: 动态取证,影子蜜罐,自适应,有限状态机

Abstract: With the development of intrusion and computer crime technologies,dynamic forensics is becoming more and more important. Dynamic forensics based on intrusion detection and honeypot technologies has great advantage in realtime performance,whcrcas these methods arc defective in overcoming the difficulty of evidence and system reliability,and hard to seize the opportunity of investigation. A self-adaptive mechanwasm was proposed which used intrusion detection system as forensics trigger and shadow honeypot was used to verify the suspicious attack, observe and analyze the attack activities further more to gather key evidences. And then the finite state machine model of this mechanism was illuminated and key technologies such as shadow honeypot, state transition opportunity and evidence security storage method were described. The dynamic forensics system with this mechanism can tolerate intrusion in a certain degree and get the investigation process under control. Moreover, the amount of unnecessary evidences can be reduced obviously.

Key words: Dynamic forensics, Shadow honeypot, Self-adaptive, Finite state machine

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!