A Complete Formalized Knowledge Representation Model for Advanced Digital Forensics Timeline Analysis

Yoan Chabot 1 Aurélie Bertaux 2 Christophe Nicolle 2 Tahar Kechadi 3
1 Le2i - CheckSem
School of Computer Science and Informatics [Dublin], Le2i - Laboratoire Electronique, Informatique et Image [UMR6303]
Abstract : Having a clear view of events that occurred over time is a difficult objective to achieve in digital investigations (DI). Event reconstruction, which allows investigators to understand the timeline of a crime, is one of the most important step of a DI process. This complex task requires exploration of a large amount of events due to the pervasiveness of new technologies nowadays. Any evidence produced at the end of the investigative process must also meet the requirements of the courts, such as reproducibility, verifiability, validation, etc. For this purpose, we propose a new methodology, supported by theoretical concepts, that can assist investigators through the whole process including the construction and the interpretation of the events describing the case. The proposed approach is based on a model which integrates knowledge of experts from the fields of digital forensics and software development to allow a semantically rich representation of events related to the incident. The main purpose of this model is to allow the analysis of these events in an automatic and efficient way. This paper describes the approach and then focuses on the main conceptual and formal aspects: a formal incident modelization and operators for timeline reconstruction and analysis.
Type de document :
Communication dans un congrès
Fourteenth Annual DFRWS Conference, Aug 2014, Denver, United States. Elsevier, Digital Investigation, 11 (2), pp.S95-S105, Digital Investigation. 〈10.1016/j.diin.2014.05.009〉
Liste complète des métadonnées

https://hal.archives-ouvertes.fr/hal-01199449
Contributeur : Aurélie Bertaux <>
Soumis le : mardi 15 septembre 2015 - 14:19:30
Dernière modification le : vendredi 7 décembre 2018 - 16:50:03

Identifiants

Collections

Citation

Yoan Chabot, Aurélie Bertaux, Christophe Nicolle, Tahar Kechadi. A Complete Formalized Knowledge Representation Model for Advanced Digital Forensics Timeline Analysis. Fourteenth Annual DFRWS Conference, Aug 2014, Denver, United States. Elsevier, Digital Investigation, 11 (2), pp.S95-S105, Digital Investigation. 〈10.1016/j.diin.2014.05.009〉. 〈hal-01199449〉

Partager

Métriques

Consultations de la notice

131