Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Zeitline: a forensic timeline editor
Search Topic:
Uniqs:
236
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Montana agencies fail to scrub PCs »
« Installing the latest KAV Personal  
AuthorAll Replies


BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000

Zeitline: a forensic timeline editor

quote:
The area of event reconstruction in computer forensics deals with analyzing and evaluating data obtained from a system and use it to determine what happened. The data recovery process is a well-covered area within computer forensics, but little work has been done on how to actually analyze and evaluate the data. Only very crude tools, such as mactimes or individual log analyzers, exist. A comprehensive event reconstruction on a system that takes into account data from various sources, such as file MAC times, system logs, firewall logs, and application data, is mostly done manually by the investigator. With storage capacities growing rapidly and systems permanently being connected to global networks more and more, it is not uncommon that the number of events recorded by a system easily goes into the hundreds of thousands.

To provide an investigator a tool that helps him process this large amount of data, we are developing a graphical time line editor. The tool should allow the grouping of events into super-events. The main data structure for the time line analyzer is the event. An event consists of a time span when the event took place, a source to denote the origin of the event, and a description of the event. An event can contain a list of sub-events and can also be part of a super event's sub-list. Starting with events at discrete times that were generated from the system information, events that belong to the same ``action'' can thus be grouped together into event hierarchies. For example, the three events ``access program gcc'', ``access file x'' and ``access library y'' could be grouped together into a super event by an investigator labeled ``compile program x'', which in turn could be part of another super event ``install rootkit z''.

»www.cerias.purdue.edu/homes/fore···line.php
--
$ /bin/whoami
nobody


foxsteve
Premium
join:2001-12-28
Campbell, CA
What do you need? Is it advertisement or do you need information about similar editors?


BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000
I don't need anything. It's the info about a new CERIAS project announced yesterday.
--
$ /bin/whoami
nobody
Forums » Up and Running » Security » SecurityMontana agencies fail to scrub PCs »
« Installing the latest KAV Personal  


Saturday, 05-Dec 06:33:02 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [90] The Bandwidth Hog Does Not Exist
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [79] New Bill Aims To Limit ETFs
· [74] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· DNS options, what are YOU using? [TekSavvy]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Google takes aim at browser redirection [Security]