首页 | 本学科首页   官方微博 | 高级检索  
     检索      


A framework for post-event timeline reconstruction using neural networks
Institution:1. Sapienza University of Rome, Dipartimento di Informatica, via Salaria 113, Roma, Italy;2. Cybersecurity Research Department, Nokia Bell Labs, Paris, France;3. Università di Padova, Dipartimento di Matematica, via Trieste 63, Padova, Italy;4. IAC-CNR, via dei Taurini, 19, Roma 00185, Italy;5. Roma Tre University, Maths and Physics Department, Roma, Italy
Abstract:Post-event timeline reconstruction plays a critical role in forensic investigation and serves as a means of identifying evidence of the digital crime. We present an artificial neural networks based approach for post-event timeline reconstruction using the file system activities. A variety of digital forensic tools have been developed during the past two decades to assist computer forensic investigators undertaking digital timeline analysis, but most of the tools cannot handle large volumes of data efficiently. This paper looks at the effectiveness of employing neural network methodology for computer forensic analysis by preparing a timeline of relevant events occurring on a computing machine by tracing the previous file system activities. Our approach consists of monitoring the file system manipulations, capturing file system snapshots at discrete intervals of time to characterise the use of different software applications, and then using this captured data to train a neural network to recognise execution patterns of the application programs. The trained version of the network may then be used to generate a post-event timeline of a seized hard disk to verify the execution of different applications at different time intervals to assist in the identification of available evidence.
Keywords:
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号