INTEGRATED PROACTIVE FORENSICS MODEL IN NETWORK INFORMATION SECURITY

Gojko Grubor, Ivan Barać · 2014

In many cases, web application security cannot provide the required level of security.Proactive collection of network data from all of the network layers in real time and their forensic analysis can help to uncover information about the internal or external attacks and to prevent potential damages.The best way is to combine application and system monitoring and perform centralized traffic monitoring to correlate events.The data collected in such manner can be used to detect traffic anomalies and improve network intrusion detection.Tracing traffic at multiple levels could potentially provide more information about the intrusion features.Analysis of these centralized log data has become an important research area in proactive network security.Any attacks should be detected as soon as possible by monitoring system, to take appropriate corrective measures in timely manner.In this paper deferent types of network events and data sources are described and their integration into centralized log management infrastructure in proactive forensic architecture is researched.The authors of this paper proposed an integrated proactive digital forensic (IPDF) model for internal and external attacks and its contribution to overall network security in context of high -volume network traffic, big data and virtualized cloud computing environment.

Read the paper · More papers on PaperTik