• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

计算机工程与科学 ›› 2024, Vol. 46 ›› Issue (07): 1229-1236.

• 计算机网络与信息安全 • 上一篇    下一篇

基于因果关系的反取证擦除技术检测模型

杜放,焦健,焦立博   

  1. (北京信息科技大学计算机学院,北京  100101)
  • 收稿日期:2023-10-12 修回日期:2023-11-20 接受日期:2024-07-25 出版日期:2024-07-25 发布日期:2024-07-19
  • 基金资助:
    国家自然科学基金(62202059)

An anti-forensic detection model based on causality calculation

DU Fang,JIAO Jian,JIAO Li-bo   

  1. (Computer School,Beijing Information Science & Technology University,Beijing 100101,China)
  • Received:2023-10-12 Revised:2023-11-20 Accepted:2024-07-25 Online:2024-07-25 Published:2024-07-19

摘要: 在现代网络攻击中,攻击者常常利用各种反取证技术来掩盖他们的踪迹。反取证技术中的数据擦除的危害性较大,攻击者可以使用这种攻击来删除或破坏数据,从而达到销毁攻击证据、扰乱取证过程的目的。由于擦除活动自身的隐蔽性使其很难被察觉,因此利用基于因果关系的溯源技术,提出了一种反擦除数据检测模型。模型根据警报信息生成警报溯源图,并通过攻击行为特征为图中的每条路径计算异常分数,通过进一步筛选和聚合计算,最终生成攻击路径。实验结果表明,该模型可以较好地实现反取证擦除活动的溯源跟踪,并能提高反数据擦除攻击活动和正常活动之间的辨识度。

关键词: 反取证, 攻击溯源, 因果关系, 网络安全, 数据擦除

Abstract: In modern network attacks, attackers often use various anti-forensics techniques to conceal their tracks. The harm of data erasure in anti-forensics technology is significant. Attackers can use this attack to delete or destroy data, thereby destroying attack evidence and disrupting the forensics process. Due to the concealment of the erasure activity itself, it is difficult to detect. This paper proposes an anti-forensics check module (AFCM) using causal relationship based traceability technology. The model generates an alert traceability graph based on alert information, and calculates anomaly scores for each path in the graph through attack behavior characteristics. Through further filtering and aggregation calculations, the attack path is ultimately generated. The experimental results show that this model can effectively achieve traceability tracking of anti-forensics erasure activities and improve the identification between anti data erasure attack activities and normal activities.

Key words: anti-forensics, attack traceability, causal relationship, network security, data wiping