Title
Creating Integrated Evidence Graphs for Network Forensics.
Abstract
Probabilistic evidence graphs can be used to model network intrusion evidence and the underlying dependencies to support network forensic analysis. The graphs provide a means for linking the probabilities associated with different attack paths with the available evidence. However, current work focused on evidence graphs assumes that all the available evidence can be expressed using a single, small evidence graph. This paper presents an algorithm for merging evidence graphs with or without a corresponding attack graph. The application of the algorithm to a file server and database server attack scenario yields an integrated evidence graph that shows the global scope of the attack. The global graph provides a broader context and better understandability than multiple local evidence graphs.
Year
DOI
Venue
2013
10.1007/978-3-642-41148-9_16
ADVANCES IN DIGITAL FORENSICS IX
Keywords
Field
DocType
Network forensics,probabilistic evidence graphs,attack graphs
Graph,File server,Intrusion,Network forensics,Computer science,Computer security,Theoretical computer science,Probabilistic logic,Database server,Merge (version control),Attack graph
Conference
Volume
ISSN
Citations 
410
1868-4238
3
PageRank 
References 
Authors
0.50
8
3
Name
Order
Citations
PageRank
Changwei Liu1416.92
Anoop Singhal2576168.78
Duminda Wijesekera31464141.54