Improving Digital Forensic Investigations through Automated User Entity Correlation

Mabrouka Abuhmida, Eric Llewellyn, Glenn Nor*

*Awdur cyfatebol y gwaith hwn

Allbwn ymchwil: Cyfraniad at gyfnodolynErthygladolygiad gan gymheiriaid

Crynodeb

Digital forensic investigation is a time-consuming process, particularly when it comes to manually correlating information between different custodians. Existing methods have been limited in their ability to provide a complete overview of relevant activities and events. In response, this research project has developed a new framework that uses metadata and document entity correlation to identify correlations between custodians. The resulting insights are novel, providing a unique overview of custodian data and a clearer understanding of document content and revisions. Using this framework, digital forensic investigators can extract relevant activity or event-based data, create custom activity or event-based correlation data, and generate event graphs. This approach is an efficient and practical way to generate actionable insights for large-scale investigations.
Iaith wreiddiolSaesneg
Rhif yr erthygl51446
Tudalennau (o-i)991-1001
Nifer y tudalennau12
CyfnodolynInternational Journal for Research in Applied Science & Engineering Technology
Cyfrol11
Rhif cyhoeddiV
Dynodwyr Gwrthrych Digidol (DOIs)
StatwsCyhoeddwyd - 11 Mai 2023

Ôl bys

Gweld gwybodaeth am bynciau ymchwil 'Improving Digital Forensic Investigations through Automated User Entity Correlation'. Gyda’i gilydd, maen nhw’n ffurfio ôl bys unigryw.

Dyfynnu hyn