15.01.2014 Views

An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

7.7. ADDING ADD<strong>IT</strong>IONAL DATA: LOG FILES 63<br />

7.7 Add<strong>in</strong>g additional data: Log les<br />

As mentioned <strong>in</strong> section 4.2.3.3 one might want to have additional data <strong>in</strong><br />

the ontology. As an example log les are added.<br />

At rst a new RDFS le is created which describes the data <strong>in</strong> the logs<br />

and species the new type log:LogFile. In the specication a property is<br />

necessary that connects the log le to the associated fs:FileSystemObject.<br />

Next it may conta<strong>in</strong> a list of log entries. The k<strong>in</strong>d of data these entries must<br />

conta<strong>in</strong> depends on the k<strong>in</strong>d of log les that are considered. The result<strong>in</strong>g<br />

structure may look like gure 7.2. To be able to nd all log les a property<br />

log:hasLogEntry<br />

log:file<br />

rdfs:range<br />

rdfs:doma<strong>in</strong><br />

rdfs:doma<strong>in</strong><br />

rdfs:range<br />

log:LogEntry<br />

log:LogFile<br />

fs:FileSystemObject<br />

Figure 7.2: Example <strong>for</strong> Log.rdfs<br />

sw:hasLogFile with rdf:range log:LogFile and rdf:doma<strong>in</strong> sw:Kernel<br />

is added to Software.rdfs. The new Software.rdfs looks similar to gure<br />

7.3.<br />

sw:hasResource<br />

sw:hasLogFile<br />

rdfs:range<br />

rdfs:doma<strong>in</strong><br />

rdfs:doma<strong>in</strong><br />

rdfs:range<br />

rdfs:doma<strong>in</strong><br />

sw:Resource<br />

sw:Kernel<br />

log:LogFile<br />

sw:processlist<br />

rdfs:range<br />

pro:ProcessList<br />

Figure 7.3: Software.rdfs with LogFile

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!