DocumentCode :
3085386
Title :
Distributed agent-based real time network intrusion forensics system architecture design
Author :
Ren, Wei ; Jin, Hai
Author_Institution :
Dept. of Comput. Sci., Zhongnan Univ. of Econ. & Law, Wuhan, China
Volume :
1
fYear :
2005
fDate :
28-30 March 2005
Firstpage :
177
Abstract :
Network forensics is a new approach for the network security, because the firewall and IDS cannot always stop and discover the misuse in the network. Once the system is compromised, the forensics and investigation always after the attacks and lose some useful instant evidence. The integrated analysis of the log and audit system and network traffic can lead to an efficient navigation of the traffic. The current network forensics approaches only focus on the network traffic capture and traffic replay, which always result in the performance bottleneck or forensics analysis difficulties. However, the adaptive capture without lose the potential sensitive traffic and real time investigation are seldom discussed. In this paper, we discuss the frameworks of distributed agent-based real time network intrusion forensics system, which is deployed in local area network environment. Some novel approaches for network forensics are discussed for the first time, such as network forensics server, network forensics database, network forensics agents, forensics data integration and active real time network forensic.
Keywords :
real-time systems; security of data; software agents; audit system; distributed agent-based real time system; network intrusion forensics system; network security; network traffic; Computer architecture; Computerized monitoring; Data security; Forensics; Grid computing; Intrusion detection; Network servers; Protection; Real time systems; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Information Networking and Applications, 2005. AINA 2005. 19th International Conference on
ISSN :
1550-445X
Print_ISBN :
0-7695-2249-1
Type :
conf
DOI :
10.1109/AINA.2005.164
Filename :
1423489
Link To Document :
بازگشت