Skip to main navigation Skip to search Skip to main content

A real-time network intrusion forensics method based on evidence reasoning network

  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Based on the analysis of problems about the existing network intrusion forensics systems, this paper proposed a real-time network intrusion forensics method according to the evidence reasoning network (NetForensic). This method connected the concept of vulnerability correlation with the field of network intrusion forensics. It built the evidence reasoning network on the basis of the network system vulnerabilities and environmental information. At the same time, NetForensic realized the attack scenario reconstruction and with high efficiency in use of the reasoning ability of multi-staged attacks provided by the evidence reasoning network. Experimental data shows that NetForensic has supplied a complete and credible chain of evidence and it also has the capacity for real-time reasoning. All of these provide a strong guarantee for the rapid and effective evidence investigation.

Original languageEnglish
Pages (from-to)1184-1194
Number of pages11
JournalJisuanji Xuebao/Chinese Journal of Computers
Volume37
Issue number5
DOIs
StatePublished - May 2014
Externally publishedYes

Keywords

  • Evidence chain
  • Evidence reasoning network
  • Information security
  • Intrusion forensics
  • Network security
  • Vulnerability

Fingerprint

Dive into the research topics of 'A real-time network intrusion forensics method based on evidence reasoning network'. Together they form a unique fingerprint.

Cite this