A Graph Based Approach Toward Network Forensics Analysis

被引:32
|
作者
Wang, Wei [1 ]
Daniels, Thomas E. [1 ]
机构
[1] Iowa State Univ, Dept Elect & Comp Engn, Ames, IA 50011 USA
关键词
Security; network forensics; evidence graph; hierarchical reasoning;
D O I
10.1145/1410234.1410238
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this article we develop a novel graph-based approach toward network forensics analysis. Central to our approach is the evidence graph model that facilitates evidence presentation and automated reasoning. Based on the evidence graph, we propose a hierarchical reasoning framework that consists of two levels. Local reasoning aims to infer the functional states of network entities from local observations. Global reasoning aims to identify important entities from the graph structure and extract groups of densely correlated participants in the attack scenario. This article also presents a framework for interactive hypothesis testing, which helps to identify the attacker's nonexplicit attack activities from secondary evidence. We developed a prototype system that implements the techniques discussed. Experimental results on various attack datasets demonstrate that our analysis mechanism achieves good coverage and accuracy in attack group and scenario extraction with less dependence on hard-coded expert knowledge.
引用
收藏
页数:33
相关论文
共 50 条
  • [21] A Network Analysis Approach toward Adaptive Overt Narcissism Network
    Runcan, Remus
    Rad, Dana
    Runcan, Patricia
    Maduta, Cristian
    BEHAVIORAL SCIENCES, 2023, 13 (06)
  • [22] Network synchronizability analysis: A graph-theoretic approach
    Chen, Guanrong
    Duan, Zhisheng
    CHAOS, 2008, 18 (03)
  • [23] Analytical Approach to Attack Graph Analysis for Network Security
    Kijsanayothin, Phongphun
    Hewett, Rattikorn
    FIFTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY: ARES 2010, PROCEEDINGS, 2010, : 25 - 32
  • [24] A novel median filtering forensics based on principal component analysis network
    Wang, Xian
    Li, Bing-Zhao
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2019, 11 (02) : 145 - 159
  • [25] Research the Computer Forensics Based on Network
    Hu Jingfang
    Li Busheng
    MANUFACTURING PROCESS AND EQUIPMENT, PTS 1-4, 2013, 694-697 : 2282 - 2285
  • [26] Network Forensics Attack-Analysis Model Based on Similarity of Intention
    Rasmi, Mohammad
    Jantan, Aman
    Ahmed, Abdulghani Ali
    2011 INTERNATIONAL CONFERENCE ON COMPUTER APPLICATION AND EDUCATION TECHNOLOGY (ICCAET 2011), 2011, : 110 - 113
  • [27] A graph-based approach to the sorting network problem
    Choi, SS
    Moon, BR
    PROCEEDINGS OF THE 2001 CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1 AND 2, 2001, : 457 - 464
  • [28] Toward graph classification on structure property using adaptive motif based on graph convolutional network
    Li, Xingquan
    Wu, Hongxi
    JOURNAL OF SUPERCOMPUTING, 2021, 77 (08): : 8767 - 8786
  • [29] Toward graph classification on structure property using adaptive motif based on graph convolutional network
    Xingquan Li
    Hongxi Wu
    The Journal of Supercomputing, 2021, 77 : 8767 - 8786
  • [30] Corporate Network Analysis Based on Graph Learning
    Atan, Emre
    Duymaz, Ali
    Sarisozen, Funda
    Aydin, Ugur
    Koras, Murat
    Akgun, Baris
    Gonen, Mehmet
    MACHINE LEARNING, OPTIMIZATION, AND DATA SCIENCE, LOD 2022, PT I, 2023, 13810 : 268 - 278