TY - GEN
T1 - Forensic investigation method and tool based on the user behaviour analysis
AU - Son, Namheun
AU - Lee, Sangjin
PY - 2011
Y1 - 2011
N2 - Today, people use a variety of digital devices, and events taking place in them are stored in specific forms mostly including data indicating when each event took place. So far, different methods have been constantly researched and developed to analyse various events, most of which analyse event data unnecessary for a forensic investigation. As a result, investigators should carry out additional work to select data needed for an actual investigation, making the process of analysis more difficult and longer. Besides, since the capacity of storage media gets higher and events become more diversified, such a phenomenon seems gradually worsened. Thus, this paper suggests a timeline-based method of checking 'users' behaviour patterns' at a look by analysing, interpreting and visualizing various user behaviour-based events in a short time, since time information exists in digital devices. Moreover, the range of analyses can be widened since investigators can analyse events through computer and smartphone used most out of all the digital devices, not simply through a single system.
AB - Today, people use a variety of digital devices, and events taking place in them are stored in specific forms mostly including data indicating when each event took place. So far, different methods have been constantly researched and developed to analyse various events, most of which analyse event data unnecessary for a forensic investigation. As a result, investigators should carry out additional work to select data needed for an actual investigation, making the process of analysis more difficult and longer. Besides, since the capacity of storage media gets higher and events become more diversified, such a phenomenon seems gradually worsened. Thus, this paper suggests a timeline-based method of checking 'users' behaviour patterns' at a look by analysing, interpreting and visualizing various user behaviour-based events in a short time, since time information exists in digital devices. Moreover, the range of analyses can be widened since investigators can analyse events through computer and smartphone used most out of all the digital devices, not simply through a single system.
KW - Event based
KW - Smartphone Forensics
KW - Timeline-based
KW - User Behaviour
KW - Visualization
UR - http://www.scopus.com/inward/record.url?scp=84867700577&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84867700577&partnerID=8YFLogxK
M3 - Conference contribution
AN - SCOPUS:84867700577
SN - 9780729806954
T3 - Proceedings of the 9th Australian Digital Forensics Conference
SP - 125
EP - 133
BT - Proceedings of the 9th Australian Digital Forensics Conference
T2 - 9th Australian Digital Forensics Conference
Y2 - 5 December 2011 through 7 December 2011
ER -