Semantic Representation and Integration of Digital Evidence

被引:14
作者
Dosis, Spyridon [1 ]
Homem, Irvin [1 ]
Popov, Oliver [1 ]
机构
[1] Stockholm Univ, Dept Comp & Syst Sci, S-16440 Stockholm, Sweden
来源
17TH INTERNATIONAL CONFERENCE IN KNOWLEDGE BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS - KES2013 | 2013年 / 22卷
关键词
Digital evidence; Ontology; Semantic Web; Evidence Integration; Knowledge Representation;
D O I
10.1016/j.procs.2013.09.214
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The ever-increasing complexity and sophistication of computer and network attacks challenge society's dependability on digital infrastructure. Digital investigations recover and reconstruct the digital trails of such events and may employ practices from various subfields (computer, network forensics), each with its own set of techniques and tools. Integration of evidence from heterogeneous sources of data (e.g. disk images, network packet captures, logs) is often a manual and time-consuming process relying significantly on the investigator's expertise. In this paper, we propose and develop an approach, based on the Semantic Web framework, for ontologically representing and integrating digital evidence. The presented approach enhances existing forensic analysis techniques by providing partial and eventually full automation of the investigative process. (C) 2013 The Authors. Published by Elsevier B.V.
引用
收藏
页码:1266 / 1275
页数:10
相关论文
共 20 条
[1]   XIRAF - XML-based indexing and querying for digital forensics [J].
Alink, W. ;
Bhoedjang, R. A. F. ;
Boncz, P. A. ;
de Vries, A. P. .
DIGITAL INVESTIGATION, 2006, :S50-S58
[2]  
[Anonymous], 2001, 1 DIG FOR RES WORKSH
[3]  
[Anonymous], 2009, W3C RECOMM
[4]   A second generation computer forensic analysis system [J].
Ayers, Daniel .
DIGITAL INVESTIGATION, 2009, 6 :S34-S42
[5]  
Carrier B., 2003, International Journal of digital evidence, V1, P1
[6]  
Carrier B.D., 2004, PROC DFRWS WORKSHOP, P11, DOI DOI 10.1145/1667053
[7]  
Casey E., 2004, DIGITAL EVIDENCE COM, V3, P279
[8]   Hash based disk imaging using AFF4 [J].
Cohen, Michael ;
Schatz, Bradley .
DIGITAL INVESTIGATION, 2010, 7 :S121-S128
[9]  
Garfinkel S., 2011, DIGIT INVEST, P1
[10]   Digital forensics research: The next 10 years [J].
Garfinkel, Simson L. .
DIGITAL INVESTIGATION, 2010, 7 :S64-S73