GrAALF: Supporting graphical analysis of audit logs for forensics

SOFTWARE IMPACTS(2021)

引用 2|浏览10
暂无评分
摘要
System-level logs play a critical role in computer forensics. They capture interactions between programs and users in detail. However, a typical computer generates more than 2.5 million system events hourly, making finding malicious activities in such logs compute and time-intensive. We introduce GrAALF a graphical system for efficiently loading, storing, processing, querying, and displaying system events for computer forensics. In comparison to similar systems, GrAALF offers the flexibility of storage, intuitive querying, and the tracing power for longer sequences of events in real-time to help identify attacks. GrAALF is a robust solution for analysis to support computer forensics.
更多
查看译文
关键词
Cyber forensics, Provenance tracking, Graphical analysis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要