Research on Effectively Supported Computer Forensic Audit Mechanism

ZENG Jianping,GUO Donghui
DOI: https://doi.org/10.3969/j.issn.1000-3428.2006.06.051
2006-01-01
Abstract:Audit mechanism provides a main way to get the users’ operation record,but there still exists some deficiency in audit mechanism.So a new audit mechanism is proposed based on Markov model.The mechanism can predict the access mode and log files are grouped into three grades according the prediction result,and this can lead to smaller storage and shorter time to get witness.
What problem does this paper attempt to address?