4.3 Article

Quantifying the association between discrete event time series with applications to digital forensics

Publisher

WILEY
DOI: 10.1111/rssa.12549

Keywords

Discrete events; Forensics; Likelihood ratio; Spatial statistics; Time series

Funding

  1. US National Institute of Standards and Technology [70NANB15H176]
  2. Iowa State University [70NANB15H176]
  3. US National Science Foundation [IIS-1320527]

Ask authors/readers for more resources

We consider the problem of quantifying the degree of association between pairs of discrete event time series, with potential applications in forensic and cybersecurity settings. We focus in particular on the case where two associated event series exhibit temporal clustering such that the occurrence of one type of event at a particular time increases the likelihood that an event of the other type will also occur nearby in time. We pursue a non-parametric approach to the problem and investigate various score functions to quantify association, including characteristics of marked point processes and summary statistics of interevent times. Two techniques are proposed for assessing the significance of the measured degree of association: a population-based approach to calculating score-based likelihood ratios when a sample from a relevant population is available, and a resampling approach to computing coincidental match probabilities when only a single pair of event series is available. The methods are applied to simulated data and to two real world data sets consisting of logs of computer activity and achieve accurate results across all data sets.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.3
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available