Dynamic forensics model based on multi-agent

The innovations of computer forensics technology need to meet the large-scale, distributed development requirements of invasion technology. By comparing the existing domestic and international forensics models, combines the advantages of multiple forensics models and adds new computer technology, a distributed computer dynamic forensics system based on agent technology is designed. The forensics system combines the multiple benefits of agent technology, which can meet the real-time, dynamic, distributed and other needs of computer forensics.

[1]  Simson L. Garfinkel Computer Forensics: Technology, Policy and Countermeasures , 2007 .

[2]  Michael S. Greenberg,et al.  Network Forensics Analysis , 2002, IEEE Internet Comput..

[3]  Shyhtsun Felix Wu,et al.  Intrusion Detection for an On-Going Attack , 1999, Recent Advances in Intrusion Detection.