2014
DOI: 10.1016/j.diin.2014.05.009
|View full text |Cite
|
Sign up to set email alerts
|

A complete formalized knowledge representation model for advanced digital forensics timeline analysis

Abstract: a b s t r a c tHaving a clear view of events that occurred over time is a difficult objective to achieve in digital investigations (DI). Event reconstruction, which allows investigators to understand the timeline of a crime, is one of the most important step of a DI process. This complex task requires exploration of a large amount of events due to the pervasiveness of new technologies nowadays. Any evidence produced at the end of the investigative process must also meet the requirements of the courts, such as … Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
24
0
11

Year Published

2014
2014
2020
2020

Publication Types

Select...
3
3
1

Relationship

2
5

Authors

Journals

citations
Cited by 44 publications
(35 citation statements)
references
References 14 publications
0
24
0
11
Order By: Relevance
“…The use of an ontology allows to have a unified model to represent knowledge, allowing to easily build analysis processes. Finally, the proposed ontology allows to meet the legal requirements and especially the need for reproducibility and traceability (Chabot et al, 2014).…”
Section: Discussionmentioning
confidence: 99%
See 2 more Smart Citations
“…The use of an ontology allows to have a unified model to represent knowledge, allowing to easily build analysis processes. Finally, the proposed ontology allows to meet the legal requirements and especially the need for reproducibility and traceability (Chabot et al, 2014).…”
Section: Discussionmentioning
confidence: 99%
“…The first analysis tool proposed in our approach is a process (based on Chabot et al, 2014) detecting correlation between a pair of events. The correlation is a relationship with a broad semantic that covers causal relationships and other semantic links.…”
Section: Timeline Analysismentioning
confidence: 99%
See 1 more Smart Citation
“…In addition, [6] argue that a formalization of the problem of event reconstruction is necessary to better structure the reconstruction process, facilitate its automation and ensure the completeness of the reconstruction. The SADFC approach answers all these points by providing several mechanisms presented in [8].…”
Section: Event Reconstruction Approachesmentioning
confidence: 99%
“…The proposed knowledge model contains entities representing a crime scene and events occurring during an incident in addition to operators allowing to acquire and manipulate this knowledge. The knowledge model and operators are formalized in [8] and are presented briefly below. Our event reconstruction process starts with the extraction of the footprints from the crime scene using extraction operators.…”
Section: Semantic-based Approach For Event Reconstructionmentioning
confidence: 99%