A comparison of machine learning techniques for file system forensics analysis

被引:20
|
作者
Mohammad, Rami Mustafa A. [1 ]
Alqahtani, Mohammed [1 ]
机构
[1] Imam Abdulrahman Bin Faisal Univ, Dept Comp Informat Syst, Coll Comp Sci & Informat Technol, POB 1982, Dammam, Saudi Arabia
关键词
Digital forensic; File system; Computer crimes; Machine Learning; Log file;
D O I
10.1016/j.jisa.2019.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the remarkable increase in computer crimes - particularly Internet related crimes - digital forensics become an urgent and a timely issue to study. Normally, digital forensics investigation aims to preserve any evidence in its most original form by identifying, collecting, and validating the digital information for the purpose of reconstructing past events. Most digital evidence is stored within the computer's file system. This research investigates and evaluates the applicability of several machine learning techniques in identifying incriminating evidence by tracing historical file system activities in order to determine how these files can be manipulated by different application programs. A dataset defined by a matrix/vector of features related to file system activity during a specific period of time has been collected. Such dataset has been used to train several machine learning techniques. Overall, the considered machine learning techniques show good results when they have been evaluated using a testing dataset containing unseen evidence. However, all algorithms encountered an essential obstacle that could be the main reason as why the experimental results were less than expectation that is the overlaps among the file system activities. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:53 / 61
页数:9
相关论文
共 50 条
  • [31] A Comparison Analysis of Heart Disease Prediction Using Supervised Machine Learning Techniques
    Elhadjamor, Emna Ammar
    Harbaoui, Houda
    2024 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, ISCC 2024, 2024,
  • [32] Machine learning techniques for face analysis
    Datcu, D
    Rothkrantz, LJM
    EUROMEDIA '2005: 11TH ANNUAL EUROMEDIA CONFERENCE, 2005, : 105 - 109
  • [33] Machine learning techniques for sentiment analysis
    Lopez, Jessica Olivares
    Lopez, Abraham Sanchez
    Velazquez, Rogelio Gonzalez
    Diaz, Maria del Carmen Santiago
    Vazquez, Ana Claudia Zenteno
    INTERNATIONAL JOURNAL OF COMBINATORIAL OPTIMIZATION PROBLEMS AND INFORMATICS, 2024, 15 (05): : 6 - 16
  • [34] Unsupervised Machine Learning for Drone Forensics through Flight Path Analysis
    Syed, Naeem
    Khan, Majid Ali
    Mohammad, Nazeeruddin
    Ben Brahim, Ghassen
    Baig, Zubair
    2022 10TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS), 2022,
  • [35] Machine-Learning Forensics: State of the Art in the Use of Machine-Learning Techniques for Digital Forensic Investigations within Smart Environments
    Tageldin, Laila
    Venter, Hein
    APPLIED SCIENCES-BASEL, 2023, 13 (18):
  • [36] Computer Forensics Research and Implementation Based on NTFS File System
    Liu Naiqi
    Wang Zhongshan
    Hao Yujie
    QinKe
    2008 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL 1, PROCEEDINGS, 2008, : 519 - +
  • [37] Learning Process Analysis using Machine Learning Techniques
    Fernandez-Robles, Laura
    Alaiz-Moreton, Hector
    Alfonso-Cendon, Javier
    Castejon-Limas, Manuel
    Panizo-Alonso, Luis
    INTERNATIONAL JOURNAL OF ENGINEERING EDUCATION, 2018, 34 (03) : 981 - 989
  • [38] A Personalized and Scalable Machine Learning-Based File Management System
    Bansal, Veena
    Sati, Dhiraj Kumar
    TEHNICKI GLASNIK-TECHNICAL JOURNAL, 2022, 16 (02): : 288 - 292
  • [39] DESIGN FOR NETWORK FILE FORENSICS SYSTEM BASED ON APPROXIMATE MATCHING
    Xu, Fei
    Liu, Pinxin
    FORENSIC SCIENCE INTERNATIONAL, 2017, 277 : 120 - 120
  • [40] Applying Machine Learning Techniques to a Real Cognitive Network: File Transfer ETAs prediction
    Del Testa, Davide
    Danieletto, Matteo
    Zorzi, Michele
    2015 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2015,