A comparison of machine learning techniques for file system forensics analysis

被引:20
|
作者
Mohammad, Rami Mustafa A. [1 ]
Alqahtani, Mohammed [1 ]
机构
[1] Imam Abdulrahman Bin Faisal Univ, Dept Comp Informat Syst, Coll Comp Sci & Informat Technol, POB 1982, Dammam, Saudi Arabia
关键词
Digital forensic; File system; Computer crimes; Machine Learning; Log file;
D O I
10.1016/j.jisa.2019.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the remarkable increase in computer crimes - particularly Internet related crimes - digital forensics become an urgent and a timely issue to study. Normally, digital forensics investigation aims to preserve any evidence in its most original form by identifying, collecting, and validating the digital information for the purpose of reconstructing past events. Most digital evidence is stored within the computer's file system. This research investigates and evaluates the applicability of several machine learning techniques in identifying incriminating evidence by tracing historical file system activities in order to determine how these files can be manipulated by different application programs. A dataset defined by a matrix/vector of features related to file system activity during a specific period of time has been collected. Such dataset has been used to train several machine learning techniques. Overall, the considered machine learning techniques show good results when they have been evaluated using a testing dataset containing unseen evidence. However, all algorithms encountered an essential obstacle that could be the main reason as why the experimental results were less than expectation that is the overlaps among the file system activities. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:53 / 61
页数:9
相关论文
共 50 条
  • [1] File system anti-forensics – types, techniques and tools
    Wani M.A.
    AlZahrani A.
    Bhat W.A.
    Computer Fraud and Security, 2020, 2020 (03): : 14 - 19
  • [2] A survey of machine learning techniques in adversarial image forensics
    Nowroozi, Ehsan
    Dehghantanha, Ali
    Parizi, Reza M.
    Choo, Kim-Kwang Raymond
    COMPUTERS & SECURITY, 2021, 100
  • [3] File system journal forensics
    Swenson, Christopher
    Phillips, Raquel
    Shenoi, Sujeet
    ADVANCES IN DIGITAL FORENSIC III, 2007, 242 : 231 - +
  • [4] File system journal forensics
    University of Tulsa, Tulsa, OK, United States
    IFIP Advances in Information and Communication Technology, (231-244):
  • [5] Decoding HDF5: Machine Learning File Forensics and Data Injection
    Walker, Clinton
    Baggili, Ibrahim
    Wang, Hao
    DIGITAL FORENSICS AND CYBER CRIME, PT 1, ICDF2C 2023, 2024, 570 : 193 - 211
  • [6] Network Forensics Analysis of Cyber Attacks on Computer Systems using Machine Learning Techniques
    Yildiz, Firdevs
    Guel, Batuhan
    Ertam, Fatih
    ACTA INFOLOGICA, 2024, 8 (01): : 34 - 50
  • [7] Characterization of plutonium for nuclear forensics using machine learning techniques
    Kitcher, Evans D.
    Osborn, Jeremy M.
    Chirayath, Sunil S.
    ANNALS OF NUCLEAR ENERGY, 2022, 170
  • [8] Analysis and Implementation of UFS File System Based on Computer Forensics
    Yang Lei
    Gao Qinquan
    Luo Delin
    Wu Shunxiang
    QUANTUM, NANO, MICRO AND INFORMATION TECHNOLOGIES, 2011, 39 : 186 - 191
  • [9] Multimedia file forensics system exploiting file similarity search
    Min-Ja Kim
    Chuck Yoo
    Young-Woong Ko
    Multimedia Tools and Applications, 2019, 78 : 5233 - 5254
  • [10] Multimedia file forensics system exploiting file similarity search
    Kim, Min-Ja
    Yoo, Chuck
    Ko, Young-Woong
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (05) : 5233 - 5254