节点文献

基于入侵容忍的网络取证系统设计

Design of Network Forensic System Based on Intrusion Tolerance

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张有东江波王建东

【Author】 ZHANG You-dong1,JIANG Bo1,WANG Jian-dong2(1.Department of Computer Engineering,Huaiyin Institute of Technology,Huaian 223003;2.Institute of Information Science and Technology,Nanjing University of Aeronautics and Astronautics,Nanjing 210016)

【机构】 淮阴工学院计算机工程系南京航空航天大学信息科学与技术学院 淮安223003淮安223003南京210016

【摘要】 现有的网络取证系统假设当发生入侵行为时系统仍然处于可靠的工作状态,未考虑系统状态变化对取证的影响。该文提出一个具有入侵容忍能力的网络取证系统INFS,分析了该原型系统的入侵容忍机制、基于SMP的取证控制机制和安全传输机制,以及取证agent、攻击回溯agent的工作机理,讨论了对应于不同系统状态的取证分析方法,提出了协同取证技术。

【Abstract】 All the present network forensic systems assume that the system is still working on reliable state when intrusion occurs,and the effect of system state changes is not considered.This paper proposes a network forensic system with intrusion tolerance ability,INFS.Mechanisms and modules of this prototype system are presented,such as intrusion tolerance,forensic control based on SMP,security transition,forensic agent,attack trace agent and so on.This paper discusses different forensic analysis methods corresponding to different states,and brings forward the concept of cooperating forensic.

【基金】 江苏省高校自然科学基金资助项目(06KJD520019)
  • 【文献出处】 计算机工程 ,Computer Engineering , 编辑部邮箱 ,2007年19期
  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】234
节点文献中: 

本文链接的文献网络图示:

本文的引文网络