首页|基于因果关系的反取证擦除技术检测模型

基于因果关系的反取证擦除技术检测模型

扫码查看
在现代网络攻击中,攻击者常常利用各种反取证技术来掩盖他们的踪迹.反取证技术中的数据擦除的危害性较大,攻击者可以使用这种攻击来删除或破坏数据,从而达到销毁攻击证据、扰乱取证过程的目的.由于擦除活动自身的隐蔽性使其很难被察觉,因此利用基于因果关系的溯源技术,提出了一种反擦除数据检测模型.模型根据警报信息生成警报溯源图,并通过攻击行为特征为图中的每条路径计算异常分数,通过进一步筛选和聚合计算,最终生成攻击路径.实验结果表明,该模型可以较好地实现反取证擦除活动的溯源跟踪,并能提高反数据擦除攻击活动和正常活动之间的辨识度.
An anti-forensic detection model based on causality calculation
In modern network attacks,attackers often use various anti-forensics techniques to conceal their tracks.The harm of data erasure in anti-forensics technology is significant.Attackers can use this attack to delete or destroy data,thereby destroying attack evidence and disrupting the forensics process.Due to the concealment of the erasure activity itself,it is difficult to detect.This paper proposes an anti-forensics check module(AFCM)using causal relationship based traceability technology.The model gen-erates an alert traceability graph based on alert information,and calculates anomaly scores for each path in the graph through attack behavior characteristics.Through further filtering and aggregation calcula-tions,the attack path is ultimately generated.The experimental results show that this model can effec-tively achieve traceability tracking of anti-forensics erasure activities and improve the identification be-tween anti data erasure attack activities and normal activities.

anti-forensicsattack traceabilitycausal relationshipnetwork securitydata wiping

杜放、焦健、焦立博

展开 >

北京信息科技大学计算机学院,北京 100101

反取证 攻击溯源 因果关系 网络安全 数据擦除

国家自然科学基金

62202059

2024

计算机工程与科学
国防科学技术大学计算机学院

计算机工程与科学

CSTPCD北大核心
影响因子:0.787
ISSN:1007-130X
年,卷(期):2024.46(7)