2012
DOI: 10.1016/j.diin.2012.05.006
|View full text |Cite
|
Sign up to set email alerts
|

An automated timeline reconstruction approach for digital forensic investigations

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
59
0
1

Year Published

2014
2014
2024
2024

Publication Types

Select...
6
2

Relationship

0
8

Authors

Journals

citations
Cited by 98 publications
(60 citation statements)
references
References 5 publications
0
59
0
1
Order By: Relevance
“…For example, Carrier [11] provides guidelines about the types of hypotheses that should be formulated and the analysis to be performed to verify those hypotheses during a digital investigation. Others [1,8,27,47] have focused on providing a unified representation of heterogeneous log events to automate event reconstruction. Similar to us, all these approaches distinguish between primitive events having a direct mapping to raw log events and complex level events, which can be determined by the occurrence of primitive ones.…”
Section: Related Workmentioning
confidence: 99%
“…For example, Carrier [11] provides guidelines about the types of hypotheses that should be formulated and the analysis to be performed to verify those hypotheses during a digital investigation. Others [1,8,27,47] have focused on providing a unified representation of heterogeneous log events to automate event reconstruction. Similar to us, all these approaches distinguish between primitive events having a direct mapping to raw log events and complex level events, which can be determined by the occurrence of primitive ones.…”
Section: Related Workmentioning
confidence: 99%
“…In (Hargreaves & Patterson, 2012), a system able to automatically reconstruct high-level events using large amount of low-level events extracted by log2timeline or Zeitline is proposed. The authors highlight that the amount of data and the number of events make the visualisation and the analysis of a timeline difficult, especially with the super-timeline approach.…”
Section: Automated Timeline Reconstruction Approachmentioning
confidence: 99%
“…• Processes to reduce the amount of data that investigators have to read by filtering data or summarize the timeline as proposed in (Abbott, Bell, Clark, De Vel, & Mohay, 2006) and (Hargreaves & Patterson, 2012).…”
Section: Future Research Directionsmentioning
confidence: 99%
“…In [6], the authors carry out the event reconstruction by searching sequences of events satisfying the constraints imposed by the evidence in a finite state machine representing the behaviour of the system subject of the investigation. In [5], a system based on patterns is used to produce high-level events from a timeline containing low-level events. However, none of the approaches discussed offers a complete solution to assist investigators in the interpretation and analysis of chronologies.…”
Section: Event Reconstruction Approachesmentioning
confidence: 99%
“…The use of an ontology provides several advantages that will be described in Section III. Regarding the analysis of timeline, existing approaches offer features to correlate events [4] or assist the investigators during the interpretation of the timeline by producing high-level events from low-level events extracted from raw data [5]. The FORE approach introduces a system to identify correlations between events by connecting them with links of cause and effect.…”
Section: Event Reconstruction Approachesmentioning
confidence: 99%