Automated abduction for computer forensics

  • Authors:
  • Andrei Doncescu;Katsumi Inoue

  • Affiliations:
  • LAAS-CNRS UPR 8001, Toulouse, France;National Institute of Informatics, Tokyo, Japan

  • Venue:
  • ATC'06 Proceedings of the Third international conference on Autonomic and Trusted Computing
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes a diagnostic system designed to aid an investigator to determine how a computer intrusion was accomplished. This wants to be a decision support by figuring out how a hacker created an unauthorized computer account. The diagnostic of this system is based on automated abduction. Abduction is inference that begins with data describing some state and produces an explanation of the data. Since abduction is ampliative and plausible reasoning may not be correct. The plausibility of an explication depends on how much better it is than the alternatives, how good it is independent of the alternatives, how reliable the data is. Therefore, abduction is nonmonotonic. To solve the problem of intrusion we consider the relationship between abduction, default logic and circumscription.