首页    期刊浏览 2024年07月06日 星期六
登录注册

文章基本信息

  • 标题:Internet Forensics Framework Based-on Clustering
  • 本地全文:下载
  • 作者:Imam Riadi ; Jazi Eko Istiyanto ; Ahmad Ashari
  • 期刊名称:International Journal of Advanced Computer Science and Applications(IJACSA)
  • 印刷版ISSN:2158-107X
  • 电子版ISSN:2156-5570
  • 出版年度:2013
  • 卷号:4
  • 期号:12
  • DOI:10.14569/IJACSA.2013.041217
  • 出版社:Science and Information Society (SAI)
  • 摘要:Internet network attacks are complicated and worth studying. The attacks include Denial of Service (DoS). DoS attacks that exploit vulnerabilities found in operating systems, network services and applications. Indicators of DoS attacks, is when legitimate users cannot access the system. This paper proposes a framework for Internet based forensic logs that aims to assist in the investigation process to reveal DoS attacks. The framework in this study consists of several steps, among others : logging into the text file and database as well as identifying an attack based on the packet header length. After the identification process, logs are grouped using k-means clustering algorithm into three levels of attack (dangerous, rather dangerous and not dangerous) based on port numbers and tcpflags of the package. Based on the test results the proposed framework can be grouped into three level attacks and found the attacker with a success rate of 89,02%, so, it can be concluded that the proposed framework can meet the goals set in this research.
  • 关键词:thesai; IJACSA; thesai.org; journal; IJACSA papers; framework; forensics; Internet; log; clustering; Denial of Service
国家哲学社会科学文献中心版权所有