First International Workshop on Knowledge Discovery and Data Mining (WKDD 2008)
Cooperation Forensic Computing Research
Adelaide, Australia
January 23-January 24
ISBN: 0-7695-3090-7
The network forensic computing is faced with the question of the complex network intrusion analyses. So a new concept of cooperation forensic computing is defined. Through to extend the theory of function dependency, a new method called probability function dependency relationships is proposed. Combined it with the Bayesian network and K2 algorithm, the network forensic computing algorithm called CFA is proposed. For the complex network attack, CFA is able to synthesize the various forensic data resource to reappearance the crime scenario intuitionally and realize the network forensic analysis effectively.