Event Abstration in a Forensic Timeline


연구 분야: Analysis



학회: International Conference for Information and Communication Technologies


초록

Event abstraction is a process of extracting main events from a large set of data, allowing investigators to identify patterns, connections, and anomalies in event logs that may reveal further evidence of malicious activity. In this paper, we investigate the use of event abstraction in a forensic timeline. This work applies the Drain method, a tree-based abstraction approach, and demonstrates its efficiency in producing accurate event abstraction. It also discusses the challenges faced by investigators in event abstraction and its analysis in a forensic timeline. Finally, this paper presents case studies of web server attacks and creates their event abstraction from a forensic timeline.


Author Profile
Hudan Studiawan

Department of Informatics Insitut Teknologi Sepuluh Nopember Surabaya Indonesia

Indonesia

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Indonesia
사이트 Springer
좋아요 수 0

연관 논문 목록 (132건)