Timeline2GUI: A Log2Timeline CSV parser and training scenarios

被引:16
作者
Debinski, Mark [1 ]
Breitinger, Frank [1 ]
Mohan, Parvathy [1 ]
机构
[1] Univ New Haven, Cyber Forens Res & Educ Grp UNHcFREG, Tagliatela Coll Engn, ECECS, 300 Boston Post Rd, West Haven, CT 06516 USA
关键词
Log2Timeline; Timeline; Timestamps; Parser; Timeline2GUI; Training cases; RECONSTRUCTION;
D O I
10.1016/j.diin.2018.12.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Crimes involving digital evidence are getting more complex due to the increasing storage capacities and utilization of devices. Event reconstruction (i.e., understanding the timeline) is an essential step for investigators to understand a case where a prominent tool is Log2Timeline (a tool that creates super timelines which is a combination of several log files and events throughout a system). While these timelines provide great evidence and help to understand a case, they are complex and require tools as well as training scenarios. In this paper we present Timeline2GUI an easy-to-use python implementation to analyze CSV log files create by Log2Timeline. Additionally, we present three training scenarios - beginner, intermediate and advanced - to practice timeline analysis skills as well as familiarity with visualization tools. Lastly, we provide a comprehensive overview of tools. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:34 / 43
页数:10
相关论文
共 29 条
[1]  
[Anonymous], 2014, NIST SPECIAL PUBLICA
[2]  
Buchholz F. P., 2005, DFRWS
[3]  
Carbone Richard, 2011, TECHNICAL REPORT
[4]  
Carvey H, 2015, MICRO MINITIMELINES
[5]  
Carvey H, 2011, HOWTO CREATING MINIT
[6]   An ontology-based approach for the reconstruction and analysis of digital incidents timelines [J].
Chabot, Yoan ;
Bertaux, Aurelie ;
Nicolle, Christophe ;
Kechadi, Tahar .
DIGITAL INVESTIGATION, 2015, 15 :83-100
[7]   A complete formalized knowledge representation model for advanced digital forensics timeline analysis [J].
Chabot, Yoan ;
Bertaux, Aurelie ;
Nicolle, Christophe ;
Kechadi, M-Tahar .
DIGITAL INVESTIGATION, 2014, 11 :S95-S105
[8]  
Chandrawanshi R, 2013, INT J SCI RES ENG TE, V1
[9]  
Chapin B., 2013, TECHNICAL REPORT
[10]  
Eichelberger F, 2014, AUTOMATION REPORT TI