{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:21:43Z","timestamp":1760242903665,"version":"build-2065373602"},"reference-count":33,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2016,11,10]],"date-time":"2016-11-10T00:00:00Z","timestamp":1478736000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>As the Internet becomes larger in scale, more complex in structure and more diversified in traffic, the number of crimes that utilize computer technologies is also increasing at a phenomenal rate. To react to the increasing number of computer crimes, the field of computer and network forensics has emerged. The general purpose of network forensics is to find malicious users or activities by gathering and dissecting firm evidences about computer crimes, e.g., hacking. However, due to the large volume of Internet traffic, not all the traffic captured and analyzed is valuable for investigation or confirmation. After analyzing some existing network forensics methods to identify common shortcomings, we propose in this paper a new network forensics method that uses a combination of network vulnerability and network evidence graph. In our proposed method, we use vulnerability evidence and reasoning algorithm to reconstruct attack scenarios and then backtrack the network packets to find the original evidences. Our proposed method can reconstruct attack scenarios effectively and then identify multi-staged attacks through evidential reasoning. Results of experiments show that the evidence graph constructed using our method is more complete and credible while possessing the reasoning capability.<\/jats:p>","DOI":"10.3390\/fi8040054","type":"journal-article","created":{"date-parts":[[2016,11,10]],"date-time":"2016-11-10T10:51:39Z","timestamp":1478775099000},"page":"54","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Network Forensics Method Based on Evidence Graph and Vulnerability Reasoning"],"prefix":"10.3390","volume":"8","author":[{"given":"Jingsha","family":"He","sequence":"first","affiliation":[{"name":"Faculty of Information Technology &amp; Beijing Engineering Research Center for IoT Software and Systems, Beijing University of Technology, Beijing 100124, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5002-3484","authenticated-orcid":false,"given":"Chengyue","family":"Chang","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology &amp; Beijing Engineering Research Center for IoT Software and Systems, Beijing University of Technology, Beijing 100124, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"He","sequence":"additional","affiliation":[{"name":"College of Computer and Information Technology, China Three Gorges University, Yichang 443002, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad","family":"Pathan","sequence":"additional","affiliation":[{"name":"Faculty of Information Technology &amp; Beijing Engineering Research Center for IoT Software and Systems, Beijing University of Technology, Beijing 100124, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2016,11,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1016\/j.diin.2007.06.013","article-title":"Analyzing Multiple Logs for Forensic Evidence","volume":"4","author":"Arasteh","year":"2007","journal-title":"Digit. Investig."},{"key":"ref_2","first-page":"1184","article-title":"A Real-time Network Intrusion Forensics Method Based on Evidence Reasoning Network","volume":"5","author":"Tian","year":"2014","journal-title":"Chin. J. Comput."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1016\/j.jnca.2016.03.005","article-title":"Network Forensics: Review, Taxonomy, and Open Challenges","volume":"66","author":"Khan","year":"2016","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_4","unstructured":"Wang, W. (2010). A Graph Oriented Approach for Network Forensic Analysis. [Ph.D. Thesis, Iowa State University]."},{"key":"ref_5","unstructured":"MIT Lincoln Laboratory LLDOS Dataset. Available online: http:\/\/www.ll.mit.edu\/ideval\/data\/2000data.html."},{"key":"ref_6","first-page":"35","article-title":"Network Forensics and Traffic Monitoring","volume":"13","author":"Ranum","year":"1997","journal-title":"Comput. Secur. J."},{"key":"ref_7","unstructured":"Palmer, G. (2001, January 7\u20138). A Road Map for Digital Forensic Research; Digital Forensic Research Workshop. Proceedings of the Digital Forensic Research Conference, Utica, NY, USA."},{"key":"ref_8","unstructured":"Bayuk, J. (2011). Cyber Forensics, Humana Publishers."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Pilli, E.S., Joshi, R.C., and Niyogi, R. (2011, January 25\u201326). Data Reduction by Identification and Correlation of TCP\/IP Attack Attributes for Network Forensics. Proceedings of the International Conference & Workshop on Emerging Trends in Technology, Mumbai, India.","DOI":"10.1145\/1980022.1980085"},{"key":"ref_10","unstructured":"Clegg, R.G., Withall, M.S., Moore, A.W., Phillips, I.W., Parish, D.J., Rio, M., Landa, R., Haddadi, H., Kyriakopoulos, K., and Auge, J. (2013). Challenges in the Capture and Dissemination of Measurements from High- Speed Networks, arXiv preprint."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Kaushik, A.K., Pilli, E.S., and Joshi, R.C. (2010, January 1). Network Forensic System for Port Scanning Attack. Proceedings of the 2010 IEEE 2nd International Advanced Computing Conference, Patiala, India.","DOI":"10.1109\/IADCC.2010.5422935"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"158","DOI":"10.1016\/j.diin.2013.02.001","article-title":"Real-time digital forensics and triage","volume":"10","author":"Roussev","year":"2013","journal-title":"Digit. Investig."},{"key":"ref_13","first-page":"1","article-title":"Identifying Significant Features for Network Forensic Analysis Using Artificial Intelligent Techniques","volume":"4","author":"Mukkamala","year":"2003","journal-title":"Int. J. Digit. Evid."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.future.2016.02.005","article-title":"Unifying Intrusion Detection and Forensic Analysis via Provenance Awareness","volume":"61","author":"Xie","year":"2016","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"376","DOI":"10.1016\/j.cose.2011.02.002","article-title":"Logic-based Approach for Digital Forensic Investigation in Communication","volume":"30","author":"Rekhis","year":"2011","journal-title":"Comput. Secur."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Settanni, G., Skopik, F., and Shovgenya, Y. (2016). A Collaborative Cyber Incident Management System for European Interconnected Critical Infrastructures. J. Inf. Secur. Appl.","DOI":"10.1016\/j.jisa.2016.05.005"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2015.09.009","article-title":"A Review of Cyber Security Risk Assessment Methods for SCADA Systems","volume":"56","author":"Cherdantseva","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"137","DOI":"10.1016\/j.jnca.2016.01.008","article-title":"A Survey on Data Leakage Prevention Systems","volume":"62","author":"Alneyadi","year":"2016","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1471","DOI":"10.1016\/j.comcom.2013.05.005","article-title":"A Scalable Network Forensics Mechanism for Stealthy Self-propagating Attacks","volume":"36","author":"Chen","year":"2013","journal-title":"Comput. Commun."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"180","DOI":"10.1016\/j.cose.2016.01.002","article-title":"Causality Reasoning about Network Events for Detecting Stealthy Malware Activities","volume":"58","author":"Zhang","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Ammann, P., Wijesekera, D., and Kaushik, S. (2002, January 18\u201322). Scalable, Graph-based Network Vulnerability Analysis. Proceedings of the 9th ACM Conference on Computer and Communications Security, Washington, DC, USA.","DOI":"10.1145\/586110.586140"},{"key":"ref_22","first-page":"230","article-title":"AIA: Attack Intention Analysis Algorithm Based on D-S Theory with Causal Technique for Network Forensics\u2014A Case Study","volume":"9","author":"Rasmi","year":"2011","journal-title":"Int. J. Digit. Content Technol. Appl."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"403","DOI":"10.1007\/978-3-642-22191-0_35","article-title":"Attack Intention Analysis Model for Network Forensics","volume":"Volume 180","author":"Zain","year":"2011","journal-title":"Software Engineering and Computer Systems"},{"key":"ref_24","first-page":"181","article-title":"Relating Admissibility Standards for Digital Evidence to Attack Scenario Reconstruction","volume":"9","author":"Liu","year":"2014","journal-title":"J. Digit. Forensics Secur. Law."},{"key":"ref_25","first-page":"1","article-title":"A Graph Based Approach toward Network Forensics Analysis","volume":"12","author":"Wang","year":"2008","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_26","first-page":"1","article-title":"Toward Defining the Intersection of Forensics and Information Technology","volume":"4","author":"Hall","year":"2005","journal-title":"Int. J. Digit. Evid."},{"key":"ref_27","unstructured":"Casey, E. (2011). Digital Evidence and Computer Crime: Forensic Science, Computers, and the Interne, Academic Publishers. [3rd ed.]."},{"key":"ref_28","unstructured":"Boser, B.E., Guyon, I.M., and Vapnik, V.N. (1996, January 1). A Training Algorithm for Optimal Margin Classifiers. Proceedings of the 5th Annual Workshop on Computational Learning Theory, New York, USA."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1145\/1961189.1961199","article-title":"Libsvm: A Library for Support Vector Machines","volume":"2","author":"Chang","year":"2011","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"ref_30","unstructured":"KDD-CUP-99 Task. Available online: http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/task.html."},{"key":"ref_31","unstructured":"National Vulnerability Database. Available online: https:\/\/nvd.nist.gov\/."},{"key":"ref_32","unstructured":"Common Vulnerabilities and Exposures. Available online: http:\/\/cve.mitre.org\/."},{"key":"ref_33","unstructured":"Common Vulnerability Scoring System. Available online: http:\/\/www.first.org\/cvss."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/8\/4\/54\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:35:13Z","timestamp":1760211313000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/8\/4\/54"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,11,10]]},"references-count":33,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2016,12]]}},"alternative-id":["fi8040054"],"URL":"https:\/\/doi.org\/10.3390\/fi8040054","relation":{},"ISSN":["1999-5903"],"issn-type":[{"type":"electronic","value":"1999-5903"}],"subject":[],"published":{"date-parts":[[2016,11,10]]}}}