Improving performance of Forensics Investigation with Parallel Coordinates Visual Analytics

被引:0
作者
Wang, Wen Bo [1 ]
Huang, Mao Lin [2 ,3 ]
Lu, Liang Fu [1 ]
Zhang, Jinson [1 ]
机构
[1] Univ Technol, Fac Engn & IT, Sydney, NSW, Australia
[2] Tianjin Univ, Sch Comp Software, Tianjin 300072, Peoples R China
[3] Univ Technol, Sch Software, Sydney, NSW, Australia
来源
2014 IEEE 17th International Conference on Computational Science and Engineering (CSE) | 2014年
关键词
Computer Forensics; Digital Evidence; Visuaization Techniques; parallel coordinates; Red-Black Tree; COMPUTER FORENSICS; TREE STRUCTURE; VISUALIZATION; SEARCH;
D O I
10.1109/CSE.2014.337
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Computer forensics investigators aim to analyse and present facts through the examination of digital evidences in short times. As the volume of suspicious data is becoming large, the difficulties of catching the digital evidence in a legally acceptable time are high. This paper proposes an effective method for reducing investigation time redundancy to achieve the normalization of data on hard disk drives (HDD) for computer forensics. We use visualization techniques, parallel coordinates, to analyse data instead of using data analysis algorithms only, and also choose a Red-Black tree structure to de-duplicate data. It reduces the time complexity, including the time spent of searching data, adding data as well as deleting data. We show the advantages of our approach; moreover, we demonstrate how this method can enhance the efficiency and quality of computer forensics task.
引用
收藏
页码:1838 / 1843
页数:6
相关论文
共 31 条
[1]  
[Anonymous], 2009, Parallel Coordinates, DOI DOI 10.1007/978-0-387-68628-8
[2]  
[Anonymous], 2011, Pei. data mining concepts and techniques
[3]  
Baryamureeba V., 2004, P 4 DIG FOR C
[4]  
Brian C., 2003, INT J DIGITAL EVIDEN, V2
[5]  
Chad A.S., 2012, INNOVATIVE APPROACHE
[6]   The parallel coordinate plot in action: design and use for geographic visualization [J].
Edsall, RM .
COMPUTATIONAL STATISTICS & DATA ANALYSIS, 2003, 43 (04) :605-619
[7]  
Finsterwalder R., 1991, SYS, V119, P122
[8]  
Garber Lee, 2001, IEEE Computer MagazineJanuary
[9]  
Grochowski E., 1996, MAGNETICS IEEE T, V32, P1850
[10]  
Hanke S., 1999, PERFORMANCE CONCURRE