Skip to main content

2019 | OriginalPaper | Buchkapitel

Investigating Visualisation Techniques for Rapid Triage of Digital Forensic Evidence

verfasst von : Gavin Hales, Ethan Bayne

Erschienen in: HCI for Cybersecurity, Privacy and Trust

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

This study investigates the feasibility of a tool that allows digital forensics (DF) investigators to efficiently triage device datasets during the collection phase of an investigation. This tool utilises data visualisation techniques to display images found in near real-time to the end user. Findings indicate that participants were able to accurately identify contraband material whilst using this tool, however, classification accuracy dropped slightly with larger datasets. Combined with participant feedback, the results show that the proposed triage method is indeed feasible, and this tool provides a solid foundation for the continuation of further work.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
2.
Zurück zum Zitat Vaughan-Nichols, S.J.: Hard drive technology reaches a turning point. Computer 36, 21–23 (2003). Long. Beach. Calif) Vaughan-Nichols, S.J.: Hard drive technology reaches a turning point. Computer 36, 21–23 (2003). Long. Beach. Calif)
5.
Zurück zum Zitat Her Majesty’s Inspectorate of Constabulary: Online and on the edge: Real risks in a virtual world (2015) Her Majesty’s Inspectorate of Constabulary: Online and on the edge: Real risks in a virtual world (2015)
6.
Zurück zum Zitat Palmer, G.: A road map for digital forensic research. In: First Digital Forensic Research Workshop, Utica, New York, pp. 27–30 (2001) Palmer, G.: A road map for digital forensic research. In: First Digital Forensic Research Workshop, Utica, New York, pp. 27–30 (2001)
7.
Zurück zum Zitat Hales, G.: Visualisation of device datasets to assist digital forensic investigation. In: 2017 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA), IEEE (2017) Hales, G.: Visualisation of device datasets to assist digital forensic investigation. In: 2017 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (Cyber SA), IEEE (2017)
8.
Zurück zum Zitat Angelini, M., Blasilli, G., Catarci, T., Lenti, S., Santucci, G.: Vulnus: visual vulnerability analysis for network security. IEEE Trans. Vis. Comput. Graph. 25, 183–192 (2019)CrossRef Angelini, M., Blasilli, G., Catarci, T., Lenti, S., Santucci, G.: Vulnus: visual vulnerability analysis for network security. IEEE Trans. Vis. Comput. Graph. 25, 183–192 (2019)CrossRef
10.
Zurück zum Zitat Nataraj, L., Manjunath, B.S.: SPAM: signal processing to analyze malware [Applications Corner]. IEEE Signal Process. Mag. 33, 105–117 (2016)CrossRef Nataraj, L., Manjunath, B.S.: SPAM: signal processing to analyze malware [Applications Corner]. IEEE Signal Process. Mag. 33, 105–117 (2016)CrossRef
11.
Zurück zum Zitat Quist, D.A., Liebrock, L.M.: Visualizing compiled executables for malware analysis. In: 2009 6th International Workshop on Visualization for Cyber Security, pp. 27–32. IEEE (2009) Quist, D.A., Liebrock, L.M.: Visualizing compiled executables for malware analysis. In: 2009 6th International Workshop on Visualization for Cyber Security, pp. 27–32. IEEE (2009)
12.
Zurück zum Zitat Bayne, E., Ferguson, R.I., Sampson, A.T.: OpenForensics: a digital forensics GPU pattern matching approach for the 21st century. Digital Invest. 24, S29–S37 (2018)CrossRef Bayne, E., Ferguson, R.I., Sampson, A.T.: OpenForensics: a digital forensics GPU pattern matching approach for the 21st century. Digital Invest. 24, S29–S37 (2018)CrossRef
13.
Zurück zum Zitat Perez, M., et al.: Video pornography detection through deep learning techniques and motion information. Neurocomputing 230, 279–293 (2017)CrossRef Perez, M., et al.: Video pornography detection through deep learning techniques and motion information. Neurocomputing 230, 279–293 (2017)CrossRef
14.
Zurück zum Zitat Platzer, C., Stuetz, M., Lindorfer, M.: Skin sheriff. In: Proceedings of the 2nd International Workshop on Security and Forensics in Communication Systems - SFCS 2014, pp. 45–56. ACM Press, New York (2014) Platzer, C., Stuetz, M., Lindorfer, M.: Skin sheriff. In: Proceedings of the 2nd International Workshop on Security and Forensics in Communication Systems - SFCS 2014, pp. 45–56. ACM Press, New York (2014)
15.
Zurück zum Zitat Mayer, F., Steinebach, M.: Forensic image inspection assisted by deep learning. In: Proceedings of the 12th International Conference on Availability, Reliability and Security - ARES 2017, pp. 1–9. ACM Press, New York (2017) Mayer, F., Steinebach, M.: Forensic image inspection assisted by deep learning. In: Proceedings of the 12th International Conference on Availability, Reliability and Security - ARES 2017, pp. 1–9. ACM Press, New York (2017)
16.
Zurück zum Zitat Potter, M.C.: Meaning in visual search. Science 187, 965–966 (1975)CrossRef Potter, M.C.: Meaning in visual search. Science 187, 965–966 (1975)CrossRef
Metadaten
Titel
Investigating Visualisation Techniques for Rapid Triage of Digital Forensic Evidence
verfasst von
Gavin Hales
Ethan Bayne
Copyright-Jahr
2019
DOI
https://doi.org/10.1007/978-3-030-22351-9_19