DIALOG: A framework for modeling, analysis and reuse of digital forensic knowledge

被引:25
作者
Kahvedzic, Damir [1 ]
Kechadi, Tahar [1 ]
机构
[1] Univ Coll Dublin, Ctr Cybercrime Invest, Dublin, Ireland
关键词
Windows; Registry; Digital; Investigation; Ontology;
D O I
10.1016/j.diin.2009.06.014
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents DIALOG ( Digital Investigation Ontology); a framework for the management, reuse, and analysis of Digital Investigation knowledge. DIALOG provides a general, application independent vocabulary that can be used to describe an investigation at different levels of detail. DIALOG is defined to encapsulate all concepts of the digital forensics field and the relationships between them. In particular, we concentrate on the Windows Registry, where registry keys are modeled in terms of both their structure and function. Registry analysis software tools are modeled in a similar manner and we illustrate how the interpretation of their results can be done using the reasoning capabilities of ontology. (C) 2009 Digital Forensic Research workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S23 / S33
页数:11
相关论文
共 18 条
[1]  
[Anonymous], SMALL SCALE DIGITAL
[2]  
BRICKLEY DAN., 2007, FOAF VOCABULARY SPEC
[3]   The Windows Registry as a forensic resource [J].
Carvey, H .
DIGITAL INVESTIGATION, 2005, 2 (03) :201-205
[4]  
*CYCORP INC, 2009, CYC
[5]  
Farmer D.J., 2009, FORENSIC ANAL WINDOW
[6]   Toward principles for the design of ontologies used for knowledge sharing [J].
Gruber, TR .
INTERNATIONAL JOURNAL OF HUMAN-COMPUTER STUDIES, 1995, 43 (5-6) :907-928
[7]  
*JISC LEG, 2007, CYB OV
[8]  
KAHVEDZIC D, 2008, J DIGITAL FORENSICS, V3
[9]  
KAHVEDZIC D, 2008, SECAU08
[10]  
Lando P., 2007, P 2 INT C SOFTW DAT