Current Proceedings on Technology

Current Proceedings on Technology

Asas: agile similarity attack strategy model based on evidence classification for network forensic attack analysis

Yazarlar: Aman Jantan, Mohammad Rasmi

Cilt 1 , Sayı - , 2012 , Sayfalar -

Konular:-

Anahtar Kelimeler:Attack strategy,Network forensic analysis,Cosine similarity,Evidence classification,Cyber crimes    

Özet:     Attack strategies have increasingly become more sophisticated in cyber crime, which makes it extremely difficult to identify an accurate attack strategy. Most attack strategy techniques depend on alert correlation that has a number of limitations such as requiring a larger number of predefined attributes, hard implementation, and at the same time having inadequacy to discover the casual relationships between the related attributes. Determining the attack strategy makes it easier for network forensic investigators to draw a possible comprehensive frame of the criminal case. In addition, it will hopefully make the investigation process even more accurate as to help apprehend the real crime perpetrator. This paper proposes an Agile Similarity Attack Strategy (ASAS) model that estimates the similar evidence between a new criminal case and others. The model uses the classification method based on a relation between attack evidence priorities with evidence group values, presented as a vector. Furthermore, the model uses a cosine similarity as a distance-based similarity measure (Metric Axioms) to improve the quality of decision making. Experiments were performed on real network data traffic from our university research labs where data traffic holds a Teredo attack to evaluate the proposed model. From the similarity metric output observation, ASAS will hopefully help an investigator to predict an attack strategy as an estimation value in order to decrease, time, effort and processing cost.


ATIFLAR
Atıf Yapan Eserler
Henüz Atıf Yapılmamıştır

KAYNAK GÖSTER
BibTex
KOPYALA
@article{2012, title={Asas: agile similarity attack strategy model based on evidence classification for network forensic attack analysis}, volume={1}, number={0}, publisher={Current Proceedings on Technology }, author={Aman Jantan, Mohammad Rasmi}, year={2012} }
APA
KOPYALA
Aman Jantan, Mohammad Rasmi. (2012). Asas: agile similarity attack strategy model based on evidence classification for network forensic attack analysis (Vol. 1). Vol. 1. Current Proceedings on Technology .
MLA
KOPYALA
Aman Jantan, Mohammad Rasmi. Asas: Agile Similarity Attack Strategy Model Based on Evidence Classification for Network Forensic Attack Analysis. no. 0, Current Proceedings on Technology , 2012.