检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:申月莉
机构地区:[1]太原工业学院计算机工程系,山西太原030008
出 处:《洛阳师范学院学报》2016年第8期62-67,共6页Journal of Luoyang Normal University
摘 要:本文用于实现一种基于Windows主机日志的取证分析方法.提出了基于Event ID分类模型的冗余数据清理技术、基于FP_Growth的日志分析算法PFP_Growth、基于模拟攻击的格式化规则匹配方法以及基于规则库与属性跟踪的场景重构方法.经过实验证明了PFP_Growth算法在日志分析方面的高效性和重构方法的有效性.A scheme based on scene reconstruction of host log is realized. Associated with a redundant data cleaning technology based on EventID classification model, a FP_Growth-dependent log analysis algorithm PFP_ Growth, a formatting rules matching method based on simulation attack, as well as a scene reconstruction avenue based on the rule database and attributes tacking are proposed. Additionally, on the one hand, the efficiency of both the PFP_Growth and the FP_Growth algorithm are compared simultaneously, validating the high efficiency of the former; on the other hand, the effectiveness of the proposed scheme is verified experimentally. The reconstructed invasion scenes proved evidences for the intrusion.
关 键 词:计算机取证 PFP_Growth算法 格式化规则匹配 场景重构
分 类 号:TP391[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.148.250.110