...
首页> 外文期刊>Digital investigation >A survey and research challenges of anti-forensics: Evaluation of game-theoretic models in simulation of forensic agents' behaviour
【24h】

A survey and research challenges of anti-forensics: Evaluation of game-theoretic models in simulation of forensic agents' behaviour

机译:反上取证的调查与研究挑战:对法医代理行为模拟的游戏理论模型评价

获取原文
获取原文并翻译 | 示例
           

摘要

Digital forensic investigators' aim is identifying, collecting and presenting reliable, accurate, and admissible evidence in court. However, anti-forensics manipulate, obfuscate, hide, and remove the remaining piece of evidence in a compromised system. Anti-forensics interrupt investigation procedures; thus, the investigators require specific defensive strategies (counter-anti-forensics) against antiforensics. This paper mounts a survey to explore existing anti-forensic research, and constitute a taxonomy on behaviour of anti-forensics and another taxonomy on further research tasks of anti-forensics.The knowledge of interactions between forensic agents' (an investigator and an attacker) in a forensic environment helps the investigator to evaluate the existing counter-anti-forensics, and enables him/her to design and develop more advanced counter-anti-forensics. Therefore, in this paper, first, we formulate a set of characteristics to model interactions between the attacker and the investigator (players) in a realistic forensic environment. Next, we propose a game-theoretic approach to model the players' interactions. The attacker uses anti-forensics (i.e. rootkits) and the investigator employs counter-antiforensics (i.e. anti-rootkits). We select and evaluate a set of game-theoretic models and algorithms to simulate the players' interactions. Results of the evaluation show that a gradient play algorithm has satisfactory performance, among the selected game-theoretic models and algorithms to simulate the interactions in the forensic environment. The gradient play algorithm identifies the investigator's most stable and desired strategies after spending 10.0E-4 s and consuming 5.8 KB. (C) 2020 Elsevier Ltd. All rights reserved.
机译:数字法医调查员的目标是在法庭上识别,收集和呈现可靠,准确和可接受的证据。但是,在受损系统中操纵,混淆,隐藏和删除剩余证据的反对。反上取证中断调查程序;因此,调查人员需要针对抗足病症的特定防御策略(反抗类药物)。本文安装了一项调查探讨了现有的反法医研究,并构成了对反上取证的行为和另一个分类物的分类,以及关于反对学的进一步研究任务的分类。法医代理人(调查员和攻击者)之间的相互作用。在法医环境中,有助于调查人员评估现有的反抗证,并使他/她能够设计和开发更先进的反抗取证。因此,在本文中,首先,我们制定一组特征来在现实的法医环境中模拟攻击者和调查员(球员)之间的相互作用。接下来,我们提出了一种模拟玩家互动的游戏理论方法。攻击者使用抗真菌(即Rootkits),研究者采用反抗真菌剂(即抗rootkits)。我们选择并评估一组游戏理论模型和算法以模拟播放器的交互。评估结果表明,梯度播放算法具有令人满意的性能,在所选择的游戏理论模型和算法中,以模拟法医环境中的交互。梯度播放算法在支出10.0E-4 S和消耗5.8 kB后识别调查员最稳定和最稳定的策略。 (c)2020 elestvier有限公司保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号