• DocumentCode
    3773651
  • Title

    Detecting Falsified Timestamps in Evidence Graph via Attack Graph

  • Author

    Yuqiang Zhang;Jingsha He;Jing Xu

  • Author_Institution
    Coll. of Comput. Sci., Beijing Univ. of Technol., Beijing, China
  • Volume
    2
  • fYear
    2015
  • Firstpage
    369
  • Lastpage
    374
  • Abstract
    Network forensics investigations aims to find a chain of evidences that helps reconstructing the alleged attack scenario. This often requires the check of timestamps of the logs to reconstruct the event. Yet, it is relatively easy for criminals to tamper with the event logs, which results in the evidence graph with falsified timestamps and hence hinders the event reconstruction. The aim of this work paper is to propose an algorithm detects these falsified timestamps and re-creates the true evidence graph. Our algorithm relies on attack graphs of the system environment which models known vulnerability sequences that were exploited to launch the attack. We demonstrate the effectiveness and performance of our algorithm via a possible attack scenario in a network environment running a file server and a database server.
  • Keywords
    Computational intelligence
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Design (ISCID), 2015 8th International Symposium on
  • Print_ISBN
    978-1-4673-9586-1
  • Type

    conf

  • DOI
    10.1109/ISCID.2015.111
  • Filename
    7469152