{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T07:02:17Z","timestamp":1776322937091,"version":"3.50.1"},"reference-count":4,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2004,6,1]],"date-time":"2004-06-01T00:00:00Z","timestamp":1086048000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2004,6]]},"abstract":"<jats:p>The dictionary defines forensics as \u201cthe use of science and technology to investigate and establish facts in criminal or civil courts of law.\u201d I am more interested, however, in the usage common in the computer world: using evidence remaining after an attack on a computer to determine how the attack was carried out and what the attacker did. The standard approach to forensics is to see what can be retrieved after an attack has been made, but this leaves a lot to be desired. The first and most obvious problem is that successful attackers often go to great lengths to ensure that they cover their trails. The second is that unsuccessful attacks often go unnoticed, and even when they are noticed, little information is available to assist with diagnosis.<\/jats:p>","DOI":"10.1145\/1016978.1016982","type":"journal-article","created":{"date-parts":[[2005,1,26]],"date-time":"2005-01-26T16:33:14Z","timestamp":1106757194000},"page":"50-56","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Network Forensics"],"prefix":"10.1145","volume":"2","author":[{"given":"Ben","family":"Laurie","sequence":"first","affiliation":[{"name":"A.L. Digital"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2004,6]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"1\n  .  For more on the Slapper story see my rant: Security: Why do I bother? O'Reilly Network; http:\/\/ www.oreillynet.com\/pub\/wlg\/2004.  1. For more on the Slapper story see my rant: Security: Why do I bother? O'Reilly Network; http:\/\/ www.oreillynet.com\/pub\/wlg\/2004."},{"key":"e_1_2_1_2_1","unstructured":"2\n  .  The Coroner's Toolkit; see: http:\/\/www.porcupine.org\/ forensics\/tct.html.  2. The Coroner's Toolkit; see: http:\/\/www.porcupine.org\/ forensics\/tct.html."},{"key":"e_1_2_1_3_1","unstructured":"3\n  .  Scheidler B. syslog-ng. http:\/\/www.balabit.com\/ products\/syslog_ng\/.  3. Scheidler B. syslog-ng. http:\/\/www.balabit.com\/ products\/syslog_ng\/."},{"key":"e_1_2_1_4_1","unstructured":"4\n  .  Bird T. and Ranum M. Loganalysis.org http:\/\/www.loganalysis.org\/.  4. Bird T. and Ranum M. Loganalysis.org http:\/\/www.loganalysis.org\/."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1016978.1016982","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1016978.1016982","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:31:00Z","timestamp":1750264260000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1016978.1016982"}},"subtitle":["Good detective work means paying attention before, during, and after the attack."],"short-title":[],"issued":{"date-parts":[[2004,6]]},"references-count":4,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2004,6]]}},"alternative-id":["10.1145\/1016978.1016982"],"URL":"https:\/\/doi.org\/10.1145\/1016978.1016982","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2004,6]]},"assertion":[{"value":"2004-06-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}