3.9 Article

An automated timeline reconstruction approach for digital forensic investigations

Journal

DIGITAL INVESTIGATION
Volume 9, Issue -, Pages S69-S79

Publisher

ELSEVIER SCI LTD
DOI: 10.1016/j.diin.2012.05.006

Keywords

Digital forensics; Automation; Timelines; Event reconstruction; Forensic computing; Timestamp; Visualisation

Ask authors/readers for more resources

Existing work on digital forensics timeline generation focuses on extracting times from a disk image into a timeline. Such an approach can produce several million 'low-level' events (e.g. a file modification or a Registry key update) for a single disk. This paper proposes a technique that can automatically reconstruct high-level events (e.g. connection of a USB stick) from this set of low-level events. The paper describes a framework that extracts low-level events to a SQLite backing store which is automatically analysed for patterns. The provenance of any high-level events is also preserved, meaning that from a high-level event it is possible to determine the low-level events that caused its inference, and from those, the raw data that caused the low-level event to be initially created can also be viewed. The paper also shows how such high-level events can be visualised using existing tools. (c) 2012 C. Hargreaves & J. Patterson. Published by Elsevier Ltd. All rights reserved.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.9
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available