在分析现有网络入侵取证系统所存在问题的基础上,提出了一种基于证据推理网络的实时网络入侵取证方法NetForensic,将弱点关联性的概念引入网络入侵取证领域,根据网络系统的弱点知识和环境信息构建了证据推理网络,利用证据推理网络所提供的多阶段攻击推理能力,NetForensic实现了高效实时攻击流程重构。实验数据表明,NetForensic给出的证据链完整可信,且具备实时推理的能力,为快速有效的调查取证提供了有力保证。
Based on the analysis of problems about the existing network intrusion forensicssystems,this paper proposed a real-time network intrusion forensics method according to theevidence reasoning network (NetForensic).This method connected the concept of vulnerabilitycorrelation with the field of network intrusion forensics.It built the evidence reasoning networkon the basis of the network system vulnerabilities and environmental information.At the sametime,NetForensic realized the attack scenario reconstruction and with high efficiency in use of thereasoning ability of multi-staged attacks provided by the evidence reasoning network.Experimentaldata shows that NetForensic has supplied a complete and credible chain of evidence and it also hasthe capacity for real-time reasoning.All of these provide a strong guarantee for the rapid andeffective evidence investigation.