DocumentCode :
3697137
Title :
A Decentralized Framework for Geolocation-Based Pre-Incident Network Forensics
Author :
Robert Koch;Mario Golling;Lars Stiemert;Volker Eiseler;Frank Tietze;Gabi Dreo Rodosek
Author_Institution :
Dept. of Comput. Sci., Univ. der Bundeswehr Munchen, Neubiberg, Germany
fYear :
2015
Firstpage :
1210
Lastpage :
1218
Abstract :
Throughout the last couple of years network forensics has gained higher importance due to the ever-growing quantity and quality of attacks. In contrast to conventional network forensics which relies on a central approach, both legal as well as technical guidelines nowadays favor a decentralized approach since aspects like privacy, limited data manipulation possibilities and scalability are addressed superiorly there. In this regard, however, present (decentralized) solutions are all in the need of an improvement especially in the area of protection against manipulation, i.e., falsification of relevant forensics data particularly in case of sophisticated attacks. Following the idea of strategic pre-incident preparation, this publication presents a decentralized approach, which, in advance, selectively collects data based on the suspiciousness of the connection to facilitate a (possible) investigation. To this end, we present an agent-based framework including prototype and evaluation that particularly uses Geolocation to fulfill this task.
Keywords :
"Forensics","Geology","IP networks","Security","Distributed databases"
Publisher :
ieee
Conference_Titel :
High Performance Computing and Communications (HPCC), 2015 IEEE 7th International Symposium on Cyberspace Safety and Security (CSS), 2015 IEEE 12th International Conferen on Embedded Software and Systems (ICESS), 2015 IEEE 17th International Conference on
Type :
conf
DOI :
10.1109/HPCC-CSS-ICESS.2015.233
Filename :
7336333
Link To Document :
بازگشت