2004
DOI: 10.1016/j.diin.2004.03.001
|View full text |Cite
|
Sign up to set email alerts
|

Finite state machine approach to digital event reconstruction

Abstract: This paper presents a rigorous method for reconstructing events in digital systems. It is based on the idea, that once the system is described as a finite state machine, its state space can be explored to determine all possible scenarios of the incident. To formalize evidence, the evidential statement notation is introduced. It represents the facts conveyed by the evidence as a series of witness stories that restrict possible computations of the finite state machine. To automate event reconstruction, a generic… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
69
0

Year Published

2007
2007
2021
2021

Publication Types

Select...
4
3
2

Relationship

0
9

Authors

Journals

citations
Cited by 82 publications
(69 citation statements)
references
References 1 publication
(1 reference statement)
0
69
0
Order By: Relevance
“…The event reconstruction method in [20] describes the compromised system as a finite state machine (FSM). Then, in order to determine all possible scenarios of the incident, it backtraces transitions from the state in which the system was discovered.…”
Section: Miscellaneous Event Reconstruction Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…The event reconstruction method in [20] describes the compromised system as a finite state machine (FSM). Then, in order to determine all possible scenarios of the incident, it backtraces transitions from the state in which the system was discovered.…”
Section: Miscellaneous Event Reconstruction Methodsmentioning
confidence: 99%
“…Correlationbased event reconstruction methods try to find some correlations among low-level pieces of evidence. Moreover, there are some miscellaneous event reconstruction methods in the literature [6,9,10,[20][21][22].…”
Section: Literature Reviewmentioning
confidence: 99%
“…Event reconstruction in digital forensics has been defined in terms of finite state machines by Gladyshev and Patel [40]. However, it less formally refers to a process that can "convert the state of the [digital] objects into the events that caused the state" [17].…”
Section: Timeline/event Reconstructionmentioning
confidence: 99%
“…Gladyshev and Patel [16] propose a finite state machine (FSM) approach to formalize hypothesis generation of an incident in digital investigations. Formalization is done through defining the event reconstruction problem as finding all possible explanations for a given evidential statement with respect to the FSM.…”
Section: B Event Reconstructionmentioning
confidence: 99%