2009
DOI: 10.1007/978-3-642-04155-6_17
|View full text |Cite
|
Sign up to set email alerts
|

A Cost-Effective Model for Digital Forensic Investigations

Abstract: Because of the way computers operate, every discrete event potentially leaves a digital trace. These digital traces must be retrieved during a digital forensic investigation to prove or refute an alleged crime. Given resource constraints, it is not always feasible (or necessary) for law enforcement to retrieve all the related digital traces and to conduct comprehensive investigations. This paper attempts to address the issue by proposing a model for conducting swift, practical and cost-effective digital forens… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
10
0

Year Published

2010
2010
2018
2018

Publication Types

Select...
5

Relationship

4
1

Authors

Journals

citations
Cited by 8 publications
(10 citation statements)
references
References 4 publications
0
10
0
Order By: Relevance
“…Specifically, if the LR value is relatively large (greater than 1,000) the search for the implied digital evidence should proceed. This would be followed by applying a cost-effective digital forensic investigation model [17] to identify the evidentiary traces and then applying the Bayesian network model [13] with the retrieved traces. On the other hand, if the LR value is found to be relatively small, the evidence does not strongly support the chosen hypotheses.…”
Section: Discussionmentioning
confidence: 99%
“…Specifically, if the LR value is relatively large (greater than 1,000) the search for the implied digital evidence should proceed. This would be followed by applying a cost-effective digital forensic investigation model [17] to identify the evidentiary traces and then applying the Bayesian network model [13] with the retrieved traces. On the other hand, if the LR value is found to be relatively small, the evidence does not strongly support the chosen hypotheses.…”
Section: Discussionmentioning
confidence: 99%
“…Bayesian belief networks have been used to determine if investigations are worth undertaking [9]. Overill and Silomon [10] use the term "digital metaforensics" to quantify the investigation of digital crime cases.…”
Section: Forensic Case Assessment and Triagementioning
confidence: 99%
“…They argue that a preliminary filtering or pre-screening phase could help rank the probable order of evidential strength. Overill, et al [9] emphasize that it is the duty of digital forensic practitioners to retrieve digital traces to prove or refute alleged computer acts. They maintain that, given the resource constraints, it is not always feasible or necessary to retrieve all the related digital traces and to conduct a thorough digital forensic analysis.…”
Section: Forensic Case Assessment and Triagementioning
confidence: 99%
See 1 more Smart Citation
“…Research on applying Bayesian networks to criminal investigations is on the rise [7][8][9]12]. The application of Bayes' theorem and graph theory provides a means to characterize the causal relationships among variables [16].…”
Section: Introductionmentioning
confidence: 99%