Title :
Cognitive-Maps Based Investigation of Digital Security Incidents
Author :
Rekhis, Slim ; Krichene, Jihene ; Boudriga, Noureddine
Author_Institution :
CN&S Res. Lab., Univ. of the 7th of November at Carthage, Tunis
Abstract :
Investigation of security incidents is of great importance as it allows to trace back the actions taken by the intruders. In this paper we develop a formal technique for digital investigation based on the use of Incident Response Probabilistic Cognitive Maps. Three main issues are addressed here: (1) construction and extraction of plausible known attack scenarios, (2) construction of hypothetical scenarios and their validation using a logic-based formalism, and (3) selection of optimal counter-measures addressing the detected attacks.
Keywords :
formal logic; probability; security of data; digital security incident investigation; incident response probabilistic cognitive map; logic-based formalism; optimal counter-measure; Collaboration; Computer crime; Computer viruses; Digital forensics; Information analysis; Information security; Manuals; Petri nets; Radio link; Software libraries; Digital investigation; Incident Response Probabilistic Cognitive Maps; attack scenarios identification; countermeasures selection; hypothetical scenarios validation;
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering, 2008. SADFE '08. Third International Workshop on
Conference_Location :
Oakland, CA
Print_ISBN :
978-0-7695-3171-7
DOI :
10.1109/SADFE.2008.20