An Abstraction Based Approach for Reconstruction of TimeLine in Digital Forensics

被引:6
作者
Bhandari, Sandeepak [1 ]
Jusas, Vacius [1 ]
机构
[1] Kaunas Univ Technol, Software Engn Dept, Studentu St 50, LT-51368 Kaunas, Lithuania
来源
SYMMETRY-BASEL | 2020年 / 12卷 / 01期
关键词
digital forensics; digital evidence; timeline reconstruction; events and artefacts;
D O I
10.3390/sym12010104
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
Acquiring a clear perspective of events and artefacts that occur over time is a challenging objective to accomplish in digital forensics. Reconstruction of the timeline of events and artefacts, which enables digital investigators to understand the timeline of digital crime and interpret the conclusion in the form of digital evidence, is one of the most paramount and challenging tasks in digital forensics. This challenging task requires the analysis of immense amounts of events because of the explosive growth of the internet, interconnected devices, and innovative technology nowadays. Various approaches have been developed during the last decade, but most of them are not able to handle huge volumes of data, explore evidence, and enhance the understandability of timelines in a competent way to assist the investigator. For this purpose, we introduce a methodology backed by an abstraction concept and forensic tools that can support investigators during the reconstruction, understanding of the timeline of events and artefacts, and interpretation of evidence by tracing the activities performed by users of the typical computer system. The Java programming language is used to implement the proposed methodology, which is object-oriented and follows the symmetry definition in software. Generally, symmetry in software can be viewed as an invariant change that aims to preserve a specific property of the system, namely its structure, behaviour, regularity, similarity, familiarity and uniformity. Similarly, the abstraction-based methodology also permits us to follow the properties of symmetry. For instance, a uniform structure is stipulated for all the sources at the particular level of abstraction, such as the number of fields to be considered to provide the abstract level of timeline. The primary purpose of this approach is to assist with the analysis of the timeline in an optimum way. This paper illustrates the approach and then focuses on conceptual aspects of the methodology. The performed experiment shows that the proposed approach enhanced the analysis of the timeline.
引用
收藏
页数:13
相关论文
共 22 条
  • [1] DESO: Addressing volume and variety in large-scale criminal cases
    Brady, Owen
    Overill, Richard
    Keppens, Jeroen
    [J]. DIGITAL INVESTIGATION, 2015, 15 : 72 - 82
  • [2] Addressing the Increasing Volume and Variety of Digital Evidence Using an Ontology
    Brady, Owen
    Overill, Richard
    Keppens, Jeroen
    [J]. 2014 IEEE JOINT INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (JISIC), 2014, : 176 - 183
  • [3] Carrier B., 2003, OPEN SOURCE DIGITAL
  • [4] Carvey Harlan., 2009, WINDOWS FORENSIC ANA, V2e
  • [5] A complete formalized knowledge representation model for advanced digital forensics timeline analysis
    Chabot, Yoan
    Bertaux, Aurelie
    Nicolle, Christophe
    Kechadi, M-Tahar
    [J]. DIGITAL INVESTIGATION, 2014, 11 : S95 - S105
  • [6] A computer forensic method for detecting timestamp forgery in NTFS
    Cho, Gyu-Sang
    [J]. COMPUTERS & SECURITY, 2013, 34 : 36 - 46
  • [7] Timeline2GUI: A Log2Timeline CSV parser and training scenarios
    Debinski, Mark
    Breitinger, Frank
    Mohan, Parvathy
    [J]. DIGITAL INVESTIGATION, 2019, 28 : 34 - 43
  • [8] Esposito S, 2013, IFIP ADV INF COMM TE, V410, P135
  • [9] Gudjonsson K., 2010, Mastering the Super Timeline With log2timeline
  • [10] An automated timeline reconstruction approach for digital forensic investigations
    Hargreaves, Christopher
    Patterson, Jonathan
    [J]. DIGITAL INVESTIGATION, 2012, 9 : S69 - S79