Title :
A transductive scheme based inference techniques for network forensic analysis
Author :
Tian Zhihong ; Jiang Wei ; Li Yang
Author_Institution :
Harbin Inst. of Technol., Harbin, China
Abstract :
Network forensics is a security infrastructure, and becomes the research focus of forensic investigation. However many challenges still exist in conducting network forensics: network has produced large amounts of data; the comprehensibility of evidence extracting from collected data; the efficiency of evidence analysis methods, etc. To solve these problems, in this paper we develop a network intrusion forensics system based on transductive scheme that can detect and analyze efficiently computer crime in networked environments, and extract digital evidence automatically. At the end of the paper, we evaluate our method on a series of experiments on KDD Cup 1999 dataset. The results demonstrate that our methods are actually effective for real-time network forensics, and can provide comprehensible aid for a forensic expert.
Keywords :
computer crime; computer network security; digital forensics; digital evidence; evidence analysis methods; network forensic analysis; network intrusion forensics system; real-time network forensics; security infrastructure; transductive scheme based inference techniques; Algorithm design and analysis; Classification algorithms; Feature extraction; Forensics; Security; Telecommunication traffic; Training; digital evidence; network forensics; security; transductive scheme;
Journal_Title :
Communications, China
DOI :
10.1109/CC.2015.7084411