发明名称 A DIGITAL FORENSIC AUDIT SYSTEM FOR ANALYZING USER'S BEHAVIORS
摘要 Disclosed is a digital forensic audit system based on user′s behavior analysis which scans a using trace which is an image recorded in a window system and a file, extracts an event and a document file from the image to analyze a user′s behavior, and visualizes the event and the document file by analyzing the event and the document file. The system includes a document file extracting unit for extracting a document file of a logic level and file attributes; an event extracting unit for extracting an event including a generation time from the image to extract an event from an attribute (hereinafter, referred to as′time attribute′) of a document file related to time; an analysis unit for analyzing the document file or the event based on attribute and time; and a visualizing unit for display the analyzed result (hereinafter, referred to as′analysis result′) on a time-dimension coordinates. According to the digital forensic audit system, various kinds of data stored in storage mediums of computer terminals in a system are simply and easily analyzed and visualized, so that a user behavior can be analyzed. In addition, intentional and illegal breach of confidential information or individual information in the system can be always monitored and proofs can be rapidly obtained when an accident occurs. [Reference numerals] (31) Scanning unit; (32) Document file extracting unit; (33) Event extracting unit; (34) Analysis unit; (35) visualization unit; (36) State extracting unit; (41) Event DB; (42) Document file DB; (43) Analysis result DB
申请公布号 KR20140036444(A) 申请公布日期 2014.03.26
申请号 KR20120102263 申请日期 2012.09.14
申请人 DUZON INFORMATION SECURITY SERVICE 发明人 JANG, TAE HOON;LEE, HONG SUN;GWAK, HYO GEUN;JEON, HONG GYU;KIM, JONG HYUN;YOU, BONG SEOK;BARK, IN HYUN;KIM, JIN HAK;HAM, JONG SEONG
分类号 G06F17/00;G06F3/14;G06F17/21 主分类号 G06F17/00
代理机构 代理人
主权项
地址