目前国内外缺乏综合数据提炼能力的日志搜索和分析系统,也还没有专门同时为安全审计与计算机取证目的设计的日志保护和分析工具,针对这一现状,分析并提出了一种日志综合分析平台,以支持网络审计与计算机取证。描述了这种安全日志文件系统的构建、采集、管理和保护,可以做到审计与取证的联动分析,形成了一个高可信审计与取证能力的基本通用模型。最后给出了系统实现的界面和系统的性能分析。
The log search and analysis system is lack of comprehensive data mining,and also there is no specific log protect and analysis system for both security audit and computer forensics on home and abroad.Aiming at this situation,a comprehensive log analysis platform on support of the security audit and computer forensics is presented.The build,acquisition,management and protection of a security log file system is described,which implements the linkage analysis of security audit and computer forensics.A high-confidence basic general model in support of security audit and computer forensics is formed.The system interface and system performance analysis are given.