A Web Forensic System Based on Semantic Checking
Jianhui Lin · 2008
Computer forensics aimed at determining the relevant causes and effects between the present state of computer system and malicious operation through the measures which could be adopted on the court. This paper proposes an intrusion forensics worked on a WEB server. The forensics system monitor the access to the log files and combine it with the timestamp and other clues in the log file, thus comprehensive operation facts are formed and represented by XML. Through analyzing with a decision tree, intrusion behavior evidence can be abstracted. Especially when a hacker tried to wipe his trace, the system can detect it effectively.