Research on Network Forensics Based on Cause and Effect of Time Series

LI Lian-min,CAO Feng,WU Qing-tao,YUN Gang
DOI: https://doi.org/10.3969/j.issn.1009-3044.2010.22.018
2010-01-01
Abstract:With the development of network,more and more network attacks appear.Network forensic is a dynamic security technology.It collects the proofs of intrusion and finds the source of attacks with the active methods,so it can prevent intrusion effectively.As complicationof attack process,the dissertation proposed forensic analysis method based cause and effect of time series.A principled approach for discovering the precursors of attack in multivariate time series obtained from honeypot data variable.The approach is rooted in time series data mining and in the application of the causality test for selecting variables that are likely contain the precursors of attack.These precursors rules relate precursor events extracted from input time series with malicious events extracted from output time series.
What problem does this paper attempt to address?