On a network forensics model for information security
Zusammenfassung
The employment of a patchwork of nonintegrated security products can only provide incomplete coverage, which cannot give the total panorama of the network misuse behavior. Network forensics is a new approach for the incident investigation and emergence response, which also enhance the network security from a different point of view. However, the current network forensics system is confused with the network monitor system or sniffer system. It always is misconstrued to an only network traffic capture system. In this paper, we for the first time discuss the concept model of network forensics system, which can give guidance for the implementation of network forensics system and the formalization of the network forensics procedure, which is a principle element of the recognition between the law enforcement participation. Particularly, some novel approaches for network forensics system are discussed for the first time, such as network forensics server, network forensics protocol and standardization, and so on.
- Vollständige Referenz
- BibTeX
Wei, R.,
(2004).
On a network forensics model for information security.
In:
Doroshenko, A. E., Halpin, T. A., Liddle, S. W. & Mayr, H. C.
(Hrsg.),
Information systems technology and its applications, 3rd international conference ISTA'2004.
Bonn:
Gesellschaft für Informatik e.V..
(S. 229-234).
@inproceedings{mci/Wei2004,
author = {Wei, Rei},
title = {On a network forensics model for information security},
booktitle = {Information systems technology and its applications, 3rd international conference ISTA'2004},
year = {2004},
editor = {Doroshenko, Anatoly E. AND Halpin, Terry A. AND Liddle, Stephen W. AND Mayr, Heinrich C.} ,
pages = { 229-234 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
author = {Wei, Rei},
title = {On a network forensics model for information security},
booktitle = {Information systems technology and its applications, 3rd international conference ISTA'2004},
year = {2004},
editor = {Doroshenko, Anatoly E. AND Halpin, Terry A. AND Liddle, Stephen W. AND Mayr, Heinrich C.} ,
pages = { 229-234 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
| Dateien | Groesse | Format | Anzeige | |
|---|---|---|---|---|
| GI.Band.48-18.pdf | 49.73Kb | Öffnen |
Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken
Mehr Information
ISBN: 3-88579-377-6
ISSN: 1617-5468
Datum: 2004
Sprache:
(en)
(en)
Typ: Text/Conference Paper

