Sciweavers

AUSFORENSICS
2003

ECF - Event Correlation for Forensics

13 years 5 months ago
ECF - Event Correlation for Forensics
The focus of the research described in this paper is on the nature of the event information provided in commonly available computer and other logs and the extent to which it is possible to correlate such event information despite its heterogeneous nature and origins. The strategic purpose of the research has been to develop a means by which a consolidated repository of such information can be constituted and then queried in order to provide an investigator with post hoc event correlation for forensics purposes (ECF). The paper provides an account of the log processing techniques utilized, and the nature of the database and query engine that have been developed in our current prototype and two examples of scenarios investigated and identified by the current prototype. Keywords Event correlation, computer forensics, logs, events, heterogeneous event logs
George M. Mohay, Kevin Chen, Andrew Clark
Added 31 Oct 2010
Updated 31 Oct 2010
Type Conference
Year 2003
Where AUSFORENSICS
Authors George M. Mohay, Kevin Chen, Andrew Clark
Comments (0)