A comparison of machine learning techniques for file system forensics analysis

被引:20
|
作者
Mohammad, Rami Mustafa A. [1 ]
Alqahtani, Mohammed [1 ]
机构
[1] Imam Abdulrahman Bin Faisal Univ, Dept Comp Informat Syst, Coll Comp Sci & Informat Technol, POB 1982, Dammam, Saudi Arabia
关键词
Digital forensic; File system; Computer crimes; Machine Learning; Log file;
D O I
10.1016/j.jisa.2019.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the remarkable increase in computer crimes - particularly Internet related crimes - digital forensics become an urgent and a timely issue to study. Normally, digital forensics investigation aims to preserve any evidence in its most original form by identifying, collecting, and validating the digital information for the purpose of reconstructing past events. Most digital evidence is stored within the computer's file system. This research investigates and evaluates the applicability of several machine learning techniques in identifying incriminating evidence by tracing historical file system activities in order to determine how these files can be manipulated by different application programs. A dataset defined by a matrix/vector of features related to file system activity during a specific period of time has been collected. Such dataset has been used to train several machine learning techniques. Overall, the considered machine learning techniques show good results when they have been evaluated using a testing dataset containing unseen evidence. However, all algorithms encountered an essential obstacle that could be the main reason as why the experimental results were less than expectation that is the overlaps among the file system activities. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:53 / 61
页数:9
相关论文
共 50 条
  • [21] PAREX: A Novel exFAT Parser for File System Forensics
    Gogia, Gaurav
    Rughani, Parag
    COMPUTACION Y SISTEMAS, 2024, 28 (02): : 421 - 433
  • [22] Comparison of machine learning techniques for target detection
    Jelte Peter Vink
    Gerard de Haan
    Artificial Intelligence Review, 2015, 43 : 125 - 139
  • [23] Comparison of machine learning techniques for target detection
    Vink, Jelte Peter
    de Haan, Gerard
    ARTIFICIAL INTELLIGENCE REVIEW, 2015, 43 (01) : 125 - 139
  • [24] Online Machine Learning Techniques for Coq: A Comparison
    Zhang, Liao
    Blaauwbroek, Lasse
    Piotrowski, Bartosz
    Cerny, Prokop
    Kaliszyk, Cezary
    Urban, Josef
    INTELLIGENT COMPUTER MATHEMATICS (CICM 2021), 2021, 12833 : 67 - 83
  • [25] Comparison of machine learning techniques for spam detection
    Argha Ghosh
    A. Senthilrajan
    Multimedia Tools and Applications, 2023, 82 : 29227 - 29254
  • [26] Comparison of machine learning techniques for spam detection
    Ghosh, Argha
    Senthilrajan, A.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2023, 82 (19) : 29227 - 29254
  • [27] Applications of Machine Learning in Digital Forensics
    Qadir, Sana
    Noor, Basirah
    2021 INTERNATIONAL CONFERENCE ON DIGITAL FUTURES AND TRANSFORMATIVE TECHNOLOGIES (ICODT2), 2021,
  • [28] Code Review Analysis of Software System using Machine Learning Techniques
    Lal, Harsh
    Pahwa, Gaurav
    PROCEEDINGS OF 2017 11TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS AND CONTROL (ISCO 2017), 2017, : 8 - 13
  • [29] Comparison Study of Digital Forensics Analysis Techniques; Findings versus Resources
    Shaaban, Ayman
    Abdelbaki, Nashwa
    9TH INTERNATIONAL CONFERENCE ON EMERGING UBIQUITOUS SYSTEMS AND PERVASIVE NETWORKS (EUSPN-2018) / 8TH INTERNATIONAL CONFERENCE ON CURRENT AND FUTURE TRENDS OF INFORMATION AND COMMUNICATION TECHNOLOGIES IN HEALTHCARE (ICTH-2018), 2018, 141 : 545 - 551
  • [30] Automated Plant Disease Analysis (APDA): Performance Comparison of Machine Learning Techniques
    Akhtar, Asma
    Khanum, Aasia
    Khan, Shoab A.
    Shaukat, Arslan
    2013 11TH INTERNATIONAL CONFERENCE ON FRONTIERS OF INFORMATION TECHNOLOGY (FIT), 2013, : 60 - 65