|
Announcements
Center for Information Protection Conferences and Workshops My Links
Other Links
|
Paper: Principles-Driven Forensic Analysis
Citation
PaperAbstractIt is possible to enhance our understanding of what has happened on a computer system by using forensic techniques that do not require prediction of the nature of the attack, the skill of the attacker, or the details of the system resources or objects affected. These techniques address five fundamental principles of computer forensics. These principles include recording data about the entire operating system, particularly user space events and environments, and interpreting events at different layers of abstraction, aided by the context in which they occurred. They also deal with modeling the recorded data as a multi-resolution, finite state machine so that results can be established to a high degree of certainty rather than merely inferred.Copyright Notice© ACM, 2005. This is the author’s version of the work. It is posted here by permission of ACM for your personal use. Not for redistribution. The definitive version was published in Proceedings of the 2005 Workshop on New Security Paradigms, Sep. 2005, and is available at http://doi.acm.org/10.1145/1146269.1146291. |
|
| Last updated on Saturday, July 5, 2008 at 10:43:22AM PDT |