کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
10341913 695742 2005 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Generalizing sources of live network evidence
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Generalizing sources of live network evidence
چکیده انگلیسی
This paper suggests combining the capture of network traffic and the collection of data from remote network services into a more general acquisition category of live network evidence sources. These two evidence sources exhibit many similarities, collected data share the same basic characteristics, and the acquisition architectures used for collection are very similar. When viewed from a more abstract perspective they can be described in the same terms. The OSI model's layered approach to networking can be used to help bring these two branches of network evidence together, organizing and reducing the complexity found in live network acquisition. The concept of an acquisition window is also introduced as a fundamental variable in live network acquisition.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 2, Issue 3, September 2005, Pages 193-200
نویسندگان
,