论文标题
敏捷的取证管理
Agile Approach for IT Forensics Management
论文作者
论文摘要
由于复杂性和增强网络的增强,对网络攻击及其事件的法医调查变得越来越困难。尤其是在高级攻击(AT)的情况下,例如不断增加的持久威胁,即敏捷方法是必不可少的。几个系统参与了攻击(多主持攻击)。当前的法医模型和程序在分析此类攻击的过程中显示出大量缺陷。为此,本文介绍了新的花模型,该模型使用敏捷方法并形成了一种新的法医管理方法。这样,满足了ATS的日益增长的挑战。在对此类攻击的法医调查中,由于需要分析的数据量,必须解决大数据问题。拟议的模型通过精确定义需要在早期州需要回答的问题,并仅收集在回答这些问题所需的法院诉讼中可用的证据来满足这一要求。此外,提出了AT的新型花模型,该模型符合研究过程的不同阶段。
The forensic investigation of cyber attacks and IT incidents is becoming increasingly difficult due to increasing complexity and intensify networking. Especially with Advanced Attacks (AT) like the increasing Advanced Persistent Threats an agile approach is indispensable. Several systems are involved in an attack (multi-host attacks). Current forensic models and procedures show considerable deficits in the process of analyzing such attacks. For this purpose, this paper presents the novel flower model, which uses agile methods and forms a new forensic management approach. In this way, the growing challenges of ATs are met. In the forensic investigation of such attacks, big data problems have to be solved due to the amount of data that needs to be analyzed. The proposed model meets this requirement by precisely defining the questions that need to be answered in an early state and collecting only the evidence usable in court proceedings that is needed to answer these questions. Additionally, the novel flower model for AT is presented that meets the different phases of an investigation process.