کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
6884526 695681 2015 18 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
An ontology-based approach for the reconstruction and analysis of digital incidents timelines
ترجمه فارسی عنوان
یک رویکرد مبتنی بر هستی شناسی برای بازسازی و تجزیه و تحلیل زمانبندی وقایع دیجیتال
کلمات کلیدی
جرم پزشکی دیجیتال، بازسازی رویداد، هستی شناسی قانونی، استخراج دانش، جمعیت هستی شناسی، تجزیه و تحلیل زمانبندی،
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
Due to the democratisation of new technologies, computer forensics investigators have to deal with volumes of data which are becoming increasingly large and heterogeneous. Indeed, in a single machine, hundred of events occur per minute, produced and logged by the operating system and various software. Therefore, the identification of evidence, and more generally, the reconstruction of past events is a tedious and time-consuming task for the investigators. Our work aims at reconstructing and analysing automatically the events related to a digital incident, while respecting legal requirements. To tackle those three main problems (volume, heterogeneity and legal requirements), we identify seven necessary criteria that an efficient reconstruction tool must meet to address these challenges. This paper introduces an approach based on a three-layered ontology, called ORD2I, to represent any digital events. ORD2I is associated with a set of operators to analyse the resulting timeline and to ensure the reproducibility of the investigation.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 15, December 2015, Pages 83-100
نویسندگان
, , , ,