2014
DOI: 10.1007/s10207-014-0249-6
|View full text |Cite
|
Sign up to set email alerts
|

Automated inference of past action instances in digital investigations

Abstract: As the amount of digital devices suspected of containing digital evidence increases, case backlogs for digital investigations are also increasing in many organizations. To ensure timely investigation of requests, this work proposes the use of signature-based methods for automated action instance approximation to automatically reconstruct past user activities within a compromised or suspect system. This work specifically explores how multiple instances of a user action may be detected using signaturebased metho… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
12
0

Year Published

2016
2016
2021
2021

Publication Types

Select...
4
3
2

Relationship

1
8

Authors

Journals

citations
Cited by 22 publications
(12 citation statements)
references
References 13 publications
0
12
0
Order By: Relevance
“…The cause and effect nature of event reconstruction has been studied, and James and Gladyshev [13] have defined action instances, a state transition model where an action produces a trace. If traces can be identified, then actions can be implied because of the causal nature of certain state transitions on computer systems.…”
Section: Related Workmentioning
confidence: 99%
“…The cause and effect nature of event reconstruction has been studied, and James and Gladyshev [13] have defined action instances, a state transition model where an action produces a trace. If traces can be identified, then actions can be implied because of the causal nature of certain state transitions on computer systems.…”
Section: Related Workmentioning
confidence: 99%
“…A number of techniques have been employed to streamline the current digital forensic process, including efficient workflow management [11], DFaaS [12,13], triage [14,4] and automation [9,15]. However, significant resources are being wasted with the current processing model; both in terms of the computer and manpower overheads.…”
Section: B Expedited Digital Forensic Processingmentioning
confidence: 99%
“…The backlogs have grown due to a number of factors including the volume of cases requiring analysis, the number of devices per case, the volume of data on each device, and the limited availability of skilled experts (Quick & Choo, 2014). Automated techniques are in continuous development to aid investigators, but due to the sensitive nature of this work, the ultimate inferences and decisions will always be made by skilled human experts (James & Gladyshev, 2015).…”
Section: Introductionmentioning
confidence: 99%