On Producing Events Timeline for Memory Forensics: An Experimental Study

2020 Seventh International Conference on Information Technology Trends (ITT)(2020)

引用 1|浏览0
暂无评分
摘要
Cybercrimes have risen dramatically recently as a result of the widespread usage of the various digital devices. Digital forensic science has been founded to address cybercrimes aspects. It follows a standard procedure to extract digital evidence and finally get it admitted to courtrooms. Fortunately, many artifacts can be extracted from such devices in convicting cybercriminals and inhibiting their actions. Identifying what a criminal had been doing during a certain time frame can be very informative to the investigative process. Identifying the timestamped events and putting them in a timeline helps achieving the investigative purposes. In this paper, we intend to extract various events out of the system memory and present them in chronological order to be utilized by the investigators. We design and investigate several scenarios and show that user activities that happen during a specific time frame can be correlated and summarized in a useful timeline.
更多
查看译文
关键词
Memory Forensics,Event Extraction,Timeline,Digital Evidence
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要