论文标题
文件系统元数据的探索性分析,以快速调查安全事件
Exploratory Analysis of File System Metadata for Rapid Investigation of Security Incidents
论文作者
论文摘要
研究网络安全事件需要分析师的深入知识。此外,由于需要分析的大量数据量,整个过程都需要。尽管如今存在各种技术来帮助完成分析的特定任务,但整个过程仍然需要大量的手动活动和专家技能。我们提出了一种方法,可以更有效地分析磁盘快照,并且对专家知识的需求较低。按照以用户为中心的设计方法,我们实施了一个分析工具,以指导分析人员在安全事件调查中。解决方案的生存能力通过与不同安全团队的成员进行的评估来验证。
Investigating cybersecurity incidents requires in-depth knowledge from the analyst. Moreover, the whole process is demanding due to the vast data volumes that need to be analyzed. While various techniques exist nowadays to help with particular tasks of the analysis, the process as a whole still requires a lot of manual activities and expert skills. We propose an approach that allows the analysis of disk snapshots more efficiently and with lower demands on expert knowledge. Following a user-centered design methodology, we implemented an analytical tool to guide analysts during security incident investigations. The viability of the solution was validated by an evaluation conducted with members of different security teams.