A quantitative approach to Triaging in Mobile Forensics

被引:27
作者
Marturana, Fabio [1 ]
Me, Gianluigi [1 ]
Berte, Rosamaria [1 ]
Tacconi, Simone [2 ]
机构
[1] Univ Roma Tor Vergata, Dept Comp Sci Syst & Prod, Rome, Italy
[2] Polizia Stato & Comunicaz, Rome, Italy
来源
TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11 | 2011年
关键词
Triaging; Mobile Forensics; Data Mining; Knowledge Analysis; Machine Learning;
D O I
10.1109/TrustCom.2011.75
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Forensic study of mobile devices is a relatively new field, dating from the early 2000s. The proliferation of phones (particularly smartphones) on the consumer market has caused a growing demand for forensic examination of the devices, which could not be met by existing Computer Forensics techniques. As a matter of fact, Law enforcement are much more likely to encounter a suspect with a mobile device in his possession than a PC or laptop and so the growth of demand for analysis of mobiles has increased exponentially in the last decade. Early investigations, moreover, consisted of live analysis of mobile devices by examining phone contents directly via the screen and photographing it with the risk of modifying the device content, as well as leaving many parts of the proprietary operating system inaccessible. The recent development of Mobile Forensics, a branch of Digital Forensics, is the answer to the demand of forensically sound examination procedures of gathering, retrieving, identifying, storing and documenting evidence of any digital device that has both internal memory and communication ability [1]. Over time commercial tools appeared which allowed analysts to recover phone content with minimal interference and examine it separately. By means of such toolkits, moreover, it is now possible to think of a new approach to Mobile Forensics which takes also advantage of "Data Mining" and "Machine Learning" theory. This paper is the result of study concerning cell phones classification in a real case of pedophilia. Based on Mobile Forensics "Triaging" concept and the adoption of self-knowledge algorithms for classifying mobile devices, we focused our attention on a viable way to predict phone usage's classifications. Based on a set of real sized phones, the research has been extensively discussed with Italian law enforcement cybercrime specialists in order to find a viable methodology to determine the likelihood that a mobile phone has been used to commit the specific crime of pedophilia, which could be very relevant during a forensic investigation.
引用
收藏
页码:582 / 588
页数:7
相关论文
共 14 条
[1]  
[Anonymous], 2000, The American Heritage Dictionary of the English Language
[2]  
[Anonymous], 2011, CYBERCRIME ITALIA QU
[3]  
[Anonymous], DATA MINING PRACTICA
[4]  
[Anonymous], 2011, GARTNER SAYS SALES M
[5]  
Bouckaert R.R., 2008, Bayesian Network Classifiers in Weka for Version 3-5-8
[6]  
Cios K.J., 2007, DATA MINING KNOWLEDG, VXV
[7]  
Frank E., 2003, Proceedings of the Conference on Uncertainty in Artificial Intelligence, P249
[8]  
Jansen Wayne., 2007, GUIDELINES CELL PHON
[9]  
Marturana F., ITAIS 2011 8 C IT AI
[10]   The growing need for on-scene triage of mobile devices [J].
Mislan, Richard P. ;
Casey, Eoghan ;
Kessler, Gary C. .
DIGITAL INVESTIGATION, 2010, 6 (3-4) :112-124