کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456453 695718 2011 7 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Detecting data theft using stochastic forensics
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Detecting data theft using stochastic forensics
چکیده انگلیسی

We present a method to examine a filesystem and determine if and when files were copied from it. We develop this method by stochastically modeling filesystem behavior under both routine activity and copying, and identifying emergent patterns in MAC timestamps unique to copying. These patterns are detectable even months afterwards. We have successfully used this method to investigate data exfiltration in the field. Our method presents a new approach to forensics: by looking for stochastically emergent patterns, we can detect silent activities that lack artifacts.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 8, Supplement, August 2011, Pages S71–S77
نویسندگان
,