Proactive Forensics Method Based on Intrusion Detection System

WANG Yi-miao,PENG Hong,CHEN Long
DOI: https://doi.org/10.3969/j.issn.1001-3695.2007.05.086
2007-01-01
Abstract:So it is costly to be evidence as a whole.A proactive forensics method was proposed to reduce the huge amount of data and reserve valuable evidence according to IDS alerts.The method was viable and reach a good trade-off performance,between possible evidence and cost.
What problem does this paper attempt to address?