Using Hypothesis Generation in Event Profiling for Digital Forensic Investigations

نویسندگان

  • Lei Pan
  • Nisar Khan
  • Lynn Margaret Batten
چکیده

The traditional manual approach to the investigation of digital data is no longer feasible as the amount of data which can be saved on hard drives grows out of control. In addition, it is usually necessary to consider data across extensive networks of devices in order to obtain a realistic picture of an investigation and ensure that no evidence is overlooked. The need for an automated approach to forensic digital investigation has therefore been recognized for some years, and several authors have developed frameworks in this direction. The aim of this paper is to enhance and move beyond current work by focusing on hypothesis generation in the later part of the analysis phase. In doing so, we present, for the first time in this context, a formal definition of the word ‘hypothesis’ and also present an extensive case study to illustrate its usefulness and the method of hypothesis generation and analysis. The scientific approach taken here to hypothesis generation directly supports the investigation procedure and also promotes its acceptance by a court of law.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Hypothesis Generation and Testing in Event Profiling for Digital Forensic Investigations

The need for an automated approach to forensic digital investigation has been recognized for some years, and several authors have developed frameworks in this direction. The aim of this paper is to assist the forensic investigator with the generation and testing of hypotheses in the analysis phase. In doing so, the authors present a new architecture which facilitates the move to automation of t...

متن کامل

Using Relationship-Building in Event Profiling for Digital Forensic Investigations

In a forensic investigation, computer profiling is used to capture evidence and to examine events surrounding a crime. A rapid increase in the last few years in the volume of data needing examination has led to an urgent need for automation of profiling. In this paper, we present an efficient, automated event profiling approach to a forensic investigation for a computer system and its activity ...

متن کامل

A framework for post-event timeline reconstruction using neural networks

Digital forensic analysis Neural networks a b s t r a c t Post-event timeline reconstruction plays a critical role in forensic investigation and serves as a means of identifying evidence of the digital crime. We present an artificial neural networks based approach for post-event timeline reconstruction using the file system activities. A variety of digital forensic tools have been developed dur...

متن کامل

A Cost-Effective Model for Digital Forensic Investigations

Because of the way computers operate, every discrete event potentially leaves a digital trace. These digital traces must be retrieved during a digital forensic investigation to prove or refute an alleged crime. Given resource constraints, it is not always feasible (or necessary) for law enforcement to retrieve all the related digital traces and to conduct comprehensive investigations. This pape...

متن کامل

Sensitivity Analysis of Bayesian Networks Used in Forensic Investigations

Research on using Bayesian networks to enhance digital forensic investigations has yet to evaluate the quality of the output of a Bayesian network. The evaluation can be performed by assessing the sensitivity of the posterior output of a forensic hypothesis to the input likelihood values of the digital evidence. This paper applies Bayesian sensitivity analysis techniques to a Bayesian network m...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012