Logo des Repositoriums
 

Forensic zero-knowledge event reconstruction on filesystem metadata

dc.contributor.authorKälber, Sven
dc.contributor.authorDewald, Andreas
dc.contributor.authorIdler, Steffen
dc.contributor.editorKatzenbeisser, Stefan
dc.contributor.editorLotz, Volkmar
dc.contributor.editorWeippl, Edgar
dc.date.accessioned2019-01-25T14:17:27Z
dc.date.available2019-01-25T14:17:27Z
dc.date.issued2014
dc.description.abstractCriminal investigations today can hardly be imagined without the forensic analysis of digital devices, regardless of whether it is a desktop computer, a mobile phone, or a navigation system. This not only holds true for cases of cybercrime, but also for traditional delicts such as murder or blackmail, and also private corporate investigations rely on digital forensics. This leads to an increasing number of cases with an ever-growing amount of data, that exceeds the capacity of the forensic experts. To support investigators to work more efficiently, we introduce a novel approach to automatically reconstruct events that previously occurred on the examined system and to provide a quick overview to the investigator as a starting point for further investigation. In contrast to the few existing approaches, our solution does not rely on any previously profiled system behavior or knowledge about specific applications, log files, or file formats. We further present a prototype implementation of our so-called zero knowledge event reconstruction approach, that solely tries to make sense of characteristic structures in file system metadata such as fileand folder-names and timestamps.en
dc.identifier.isbn978-3-88579-622-0
dc.identifier.pissn1617-5468
dc.identifier.urihttps://dl.gi.de/handle/20.500.12116/20054
dc.language.isoen
dc.publisherGesellschaft für Informatik e.V.
dc.relation.ispartofSicherheit 2014 – Sicherheit, Schutz und Zuverlässigkeit
dc.relation.ispartofseriesLecture Notes in Informatics (LNI) - Proceedings, Volume P-254
dc.titleForensic zero-knowledge event reconstruction on filesystem metadataen
dc.typeText/Conference Paper
gi.citation.endPage343
gi.citation.publisherPlaceBonn
gi.citation.startPage331
gi.conference.date19.-21. März 2014
gi.conference.locationWien, Österreich
gi.conference.sessiontitleRegular Research Papers

Dateien

Originalbündel
1 - 1 von 1
Lade...
Vorschaubild
Name:
331.pdf
Größe:
232.87 KB
Format:
Adobe Portable Document Format