An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
7.7. ADDING ADD<strong>IT</strong>IONAL DATA: LOG FILES 63<br />
7.7 Add<strong>in</strong>g additional data: Log les<br />
As mentioned <strong>in</strong> section 4.2.3.3 one might want to have additional data <strong>in</strong><br />
the ontology. As an example log les are added.<br />
At rst a new RDFS le is created which describes the data <strong>in</strong> the logs<br />
and species the new type log:LogFile. In the specication a property is<br />
necessary that connects the log le to the associated fs:FileSystemObject.<br />
Next it may conta<strong>in</strong> a list of log entries. The k<strong>in</strong>d of data these entries must<br />
conta<strong>in</strong> depends on the k<strong>in</strong>d of log les that are considered. The result<strong>in</strong>g<br />
structure may look like gure 7.2. To be able to nd all log les a property<br />
log:hasLogEntry<br />
log:file<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
rdfs:doma<strong>in</strong><br />
rdfs:range<br />
log:LogEntry<br />
log:LogFile<br />
fs:FileSystemObject<br />
Figure 7.2: Example <strong>for</strong> Log.rdfs<br />
sw:hasLogFile with rdf:range log:LogFile and rdf:doma<strong>in</strong> sw:Kernel<br />
is added to Software.rdfs. The new Software.rdfs looks similar to gure<br />
7.3.<br />
sw:hasResource<br />
sw:hasLogFile<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
rdfs:doma<strong>in</strong><br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
sw:Resource<br />
sw:Kernel<br />
log:LogFile<br />
sw:processlist<br />
rdfs:range<br />
pro:ProcessList<br />
Figure 7.3: Software.rdfs with LogFile