摘要:This paper details the design of a host-based intrusion detection system and describes the desired characteristics of an Intrusion Detection Data Source (IDDS). Further, this paper provides features that make an IDS technology a useful as an evidence acquisition tool. An explanation is provided of admissibility and weight, the two determinants in the legal acceptability of evidence of IDSs as sources of legal evidence, including preservation of evidence, continuity of evidence and transparency of forensic method
关键词:Intrusion Detection System; Evidence; Digital forensic