官术网_书友最值得收藏!

Digital forensic goals

The main object in the digital forensic analysis is the digital device related to the security incident under investigation. The digital device was either used to commit a crime, to target an attack, or is a source of information for the analyst. The goals of the analysis phase in the digital forensics process differ from one case to another. It can be used to support or refute assumptions against individuals or entities, or it can be used to investigate information security incidents locally on the system or over a network.

Consider analyzing a compromised system, the goals of the digital forensics, as a whole, are to answer these questions:

  • What happened to the system under analysis?
  • How was it compromised?

During the analysis too, the analyst could answer some other questions based on their findings, such as the following:

  • Who is the attacker? This asks whether the analyst could find the attacker IP and/or an IP of the command and control server or in some cases the attacker profile.
  • When did it happen? This asks whether the analyst could ascertain the time of the infection or compromise.
  • Where did it happen? This asks whether the analyst could identify the compromised systems in the network and the possibility of other victims.
  • Why did it happen? This is based on the attacker's activities in the hacked system, the analyst can form an idea of the attacker's motivation, either financial, espionage, or other.
主站蜘蛛池模板: 淮安市| 阳城县| 福安市| 丁青县| 牙克石市| 莱阳市| 东宁县| 高青县| 芜湖市| 田东县| 大渡口区| 凤阳县| 高淳县| 阿瓦提县| 宁明县| 大庆市| 丹凤县| 昭觉县| 新竹市| 萍乡市| 高州市| 通化市| 黑龙江省| 成都市| 蓬溪县| 历史| 手游| 汉川市| 陆河县| 休宁县| 左权县| 乌什县| 榆社县| 小金县| 班戈县| 通榆县| 合山市| 安庆市| 河津市| 普兰店市| 溧阳市|