Effective Management Of Rapid Intervention, Investigation, Analysis And Reporting Processes On Crimes Committed By Computer With New Generation Forensic Informatics Methods

Author:

ALKAN Abdulkerim Oğuzhan1ORCID,DOGRU İbrahim2ORCID,ATACAK İsmail2ORCID

Affiliation:

1. GAZİ ÜNİVERSİTESİ, BİLİŞİM ENSTİTÜSÜ

2. GAZİ ÜNİVERSİTESİ

Abstract

Because of the exponential growth in the volume and speed of attack vectors, the rapid growth of computer crimes, the corporate attack surface and the enormous volumes of data, preventing the cyber-attacks has become very difficult. In terms of forensics, classical forensic methods in a traditional approach which include removing the disk, gettng its image and examining the image takes a lot of time with the increasing amount of data so that this situation leads to make quick intervention too difficult against cyber attack and it takes a lot of time. For example, on average, getting an image of harddisk which include 20 terabyte capacity takes 2 days of time. As a solution, with a special tool (Binalyze AIR) that collects only evidentiary documents getting hash of all evidences (Disk Proof, Proof of Memory, Proof of Scanner, Proof of NTFS, Proof of Log, Proof of Network, Proof of Event Logs, Proof of WMI, Proof of Process Execution, etc.) and collects only the documents that have the quality of evidence, thus this process can be completed in a very short time. It provides effective management of crime scene investigation and fast response to crimes committed by computer, investigation, analysis and reporting processes blocked with traditional forensic methods and offers an innovative solution to the scientific literature. In summary, in this study, the results obtained by using modern forensic techniques (Binalyze AIR and Binalyze Tactical software) are presented in comparison with classical forensic methods.

Publisher

Politeknik Dergisi

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3