Skip to main content
QUICK REVIEW

[论文解读] Intensional Cyberforensics

Serguei A. Mokhov|arXiv (Cornell University)|Dec 2, 2013
Digital and Cyber Forensics参考文献 302被引用 8
一句话总结

本文提出 Forensic Lucid,一种基于 Lucid 的新型可内含性编程语言方言,用于通过多维分层上下文和可内含性逻辑建模网络取证调查。该语言支持基于演绎推理的事件重建回溯,整合证据与证人陈述的可信度因子,并为分布式评估提供形式化操作语义,为数字取证提供一种上下文感知、逻辑驱动的替代方案,相较于有限状态自动机模型,其表达能力与可追溯性均得到提升。

ABSTRACT

This work focuses on the application of intensional logic to cyberforensic analysis and its benefits and difficulties are compared with the finite-state-automata approach. This work extends the use of the intensional programming paradigm to the modeling and implementation of a cyberforensics investigation process with backtracing of event reconstruction, in which evidence is modeled by multidimensional hierarchical contexts, and proofs or disproofs of claims are undertaken in an eductive manner of evaluation. This approach is a practical, context-aware improvement over the finite state automata (FSA) approach we have seen in previous work. As a base implementation language model, we use in this approach a new dialect of the Lucid programming language, called Forensic Lucid, and we focus on defining hierarchical contexts based on intensional logic for the distributed evaluation of cyberforensic expressions. We also augment the work with credibility factors surrounding digital evidence and witness accounts, which have not been previously modeled. The Forensic Lucid programming language, used for this intensional cyberforensic analysis, formally presented through its syntax and operational semantics. In large part, the language is based on its predecessor and codecessor Lucid dialects, such as GIPL, Indexical Lucid, Lucx, Objective Lucid, and JOOIP bound by the underlying intensional programming paradigm.

研究动机与目标

  • 为解决现有有限状态自动机(FSA)模型在网络安全取证分析中的局限性,提出一种更具表达性、上下文感知的框架。
  • 利用基于可内含性逻辑的多维分层上下文,对数字证据与调查主张进行建模。
  • 通过演绎推理形式化事件重建过程,使基于证据的主张可被形式化证明或证伪。
  • 将证据与证人陈述的可信度因子正式整合进取证推理系统,弥补以往形式化取证模型中常被忽视的不足。
  • 开发并实现 Forensic Lucid 作为 Lucid 的新方言,扩展通用可内含性编程系统(GIPSY),以支持分布式网络取证推理。

提出的方法

  • 采用可内含性逻辑,将证据与调查主张表示为动态、上下文依赖的表达式。
  • 设计 Forensic Lucid 作为领域特定语言方言,基于 Lucid 及其前身,具备形式化语法与操作语义。
  • 利用分层上下文建模取证数据的多维特性,包括时间、位置与系统状态。
  • 应用演绎求值策略,追溯因果链,验证或反驳调查假设。
  • 使用 Dempster–Shafer 理论集成可信度建模,评估证据与证人陈述的可信度。
  • 在 GIPSY 框架中扩展出编译器、运行时系统与集群实验环境,以支持取证表达式的分布式执行。

实验结果

研究问题

  • RQ1与有限状态自动机相比,可内含性逻辑如何提升网络取证调查的表达能力与可追溯性?
  • RQ2为建模多维取证上下文并支持事件回溯,需要哪些形式化语言构造?
  • RQ3如何将数字证据与证人陈述的可信度因子正式整合进取证推理系统?
  • RQ4在将 Lucid 扩展用于网络取证应用时,关键的设计与实现挑战是什么?
  • RQ5Forensic Lucid 语言如何实现取证表达式的分布式、上下文感知求值?

主要发现

  • Forensic Lucid 通过多维分层上下文成功建模了数字证据与调查主张,实现了精确且可追溯的取证推理。
  • 该语言通过演绎求值支持事件回溯,使基于证据的主张可被形式化证明或证伪。
  • 利用 Dempster–Shafer 理论,对证据与证人陈述的可信度因子进行了正式建模,增强了取证结论中的可信度评估。
  • 在 GIPSY 框架中实现 Forensic Lucid,使取证表达式可在集群环境中实现分布式执行。
  • 通过与 MARF 和 MARFCAT 的集成,系统在取证场景下的数据挖掘与模式识别方面展现出可行性与表达能力。
  • 该方法为 FSA 模型提供了一种实用且形式化的替代方案,显著增强了对上下文感知、动态取证分析的支持。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。