FIRESTORM: Exploring the Need for a Forensic Tool for Pattern Correlation in Windows NT Audit Logs

Atif Ahmad, A.B. Ruighaver · 2002

Computer Forensic investigators have traditionally been concentrating on the extraction of evidence from confiscated computer systems used by suspected offenders. Relatively less emphasis has been placed on the analysis of systems that have experienced a security violation. This paper discusses the need for new forensic tools capable of assisting forensic investigators in analyzing computer security incidents. In an effort to assist the forensic investigator in this process, we explore the need for a new forensic tool, FIRESTORM. We discuss how FIRESTORM would allow an investigator to compress some of the non-relevant details in those patterns that have been identified as possibly relevant, to improve the visualizing of any correlations between these patterns. We have called this technique semantic compression.

Read the paper · More papers on PaperTik