Towards Proactive Computer-System Forensics

  • Authors:
  • Phillip G. Bradford;Marcus Brown;Josh Perdue;Bonnie Self

  • Affiliations:
  • -;-;-;-

  • Venue:
  • ITCC '04 Proceedings of the International Conference on Information Technology: Coding and Computing (ITCC'04) Volume 2 - Volume 2
  • Year:
  • 2004

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper examines principles and approaches forproactive computer-system forensics. Proactive computer-systemforensics is the design, construction and configuringof systems to make them most amenable to digital forensicsanalyses in the future. The primary goals of proactivecomputer-system forensics are system structuring andaugmentation for automated data discovery, lead formation,and efficient data preservation. This paper proposes:(1) using the Neyman-Pearson Lemma to proactively buildonline forensics tests with the best possible critical regionsfor hypothesis testing, and (2) using classical stopping rulesfor sequential hypothesis testing to determine which usersare deviating from standard usage behavior and should bethe focus of more investigative resources.Here the focus is on security breaches by the employeesor stakeholders of an organization. The main measurementsare event-driven logs of program executions.