연구 분야: Analysis
학회: International Conference for Information and Communication Technologies
Event abstraction is a process of extracting main events from a large set of data, allowing investigators to identify patterns, connections, and anomalies in event logs that may reveal further evidence of malicious activity. In this paper, we investigate the use of event abstraction in a forensic timeline. This work applies the Drain method, a tree-based abstraction approach, and demonstrates its efficiency in producing accurate event abstraction. It also discusses the challenges faced by investigators in event abstraction and its analysis in a forensic timeline. Finally, this paper presents case studies of web server attacks and creates their event abstraction from a forensic timeline.
| 발행 연도 | 2024년 |
|---|---|
| 인용수 | 0 |
| 출판 국가 | Indonesia |
| 사이트 | Springer |
| 좋아요 수 | 0 |