Design of Network Forensics Based on Apriori Algorithm
Zhong Xiu-yu · Computer Technology and Development · 2011
Because the traditional computer forensics collects evidence after events,the legal efficiency of evidence is low.Network forensics turns the passive investigation after events to the active defense before events.Network forensics based on Apriori algorithm mines the association of crime events to build crime characteristic database.After gaining and filtering the network data packet,the system carries on protocol analysis to the primary data,the association information between data packets are mined and the association rule records are extracted,and the current user behavior is illegal or not according to match result of the current user behavior records and the crime characteristic rules.In order to guarantee the primitiveness,integrity and legal efficiency of evidence,the system uses encryption transmission to the primary data and uses the SSL encryption authentication safe design to prevent evidence revealed and fabricated.Simulation results show that the application of Apriori algorithm increases illegal invasion detection efficiency and can identify new crime,and the system restructures criminal process completely.