A comparison of machine learning techniques for file system forensics analysis

被引:20
|
作者
Mohammad, Rami Mustafa A. [1 ]
Alqahtani, Mohammed [1 ]
机构
[1] Imam Abdulrahman Bin Faisal Univ, Dept Comp Informat Syst, Coll Comp Sci & Informat Technol, POB 1982, Dammam, Saudi Arabia
关键词
Digital forensic; File system; Computer crimes; Machine Learning; Log file;
D O I
10.1016/j.jisa.2019.02.009
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the remarkable increase in computer crimes - particularly Internet related crimes - digital forensics become an urgent and a timely issue to study. Normally, digital forensics investigation aims to preserve any evidence in its most original form by identifying, collecting, and validating the digital information for the purpose of reconstructing past events. Most digital evidence is stored within the computer's file system. This research investigates and evaluates the applicability of several machine learning techniques in identifying incriminating evidence by tracing historical file system activities in order to determine how these files can be manipulated by different application programs. A dataset defined by a matrix/vector of features related to file system activity during a specific period of time has been collected. Such dataset has been used to train several machine learning techniques. Overall, the considered machine learning techniques show good results when they have been evaluated using a testing dataset containing unseen evidence. However, all algorithms encountered an essential obstacle that could be the main reason as why the experimental results were less than expectation that is the overlaps among the file system activities. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:53 / 61
页数:9
相关论文
共 50 条
  • [41] TECHNIQUES FOR FILE SYSTEM SIMULATION
    THEKKATH, CA
    WILKES, J
    LAZOWSKA, ED
    SOFTWARE-PRACTICE & EXPERIENCE, 1994, 24 (11): : 981 - 999
  • [42] Comparison of Novel Raman Techniques for Fiber Forensics
    Anderson, Benjamin R.
    Gese, Natalie
    Eilers, Hergen
    Prudenzano, Francesco
    OPTICS, 2023, 4 (03): : 447 - 458
  • [43] Comparison of machine learning techniques for predicting porosity of chalk
    Nourani, Meysam
    Alali, Najeh
    Samadianfard, Saeed
    Band, Shahab S.
    Chau, Kwok-wing
    Shu, Chi-Min
    JOURNAL OF PETROLEUM SCIENCE AND ENGINEERING, 2022, 209
  • [44] Comparison of Machine Learning Techniques for Psychophysiological Stress Detection
    Smets, Elena
    Casale, Pierluigi
    Grossekathofer, Ulf
    Lamichhane, Bishal
    De Raedt, Walter
    Bogaerts, Katleen
    Van Diest, Ilse
    Van Hoof, Chris
    PERVASIVE COMPUTING PARADIGMS FOR MENTAL HEALTH (MINDCARE 2015), 2016, 604 : 13 - 22
  • [45] Comparison of Machine Learning Techniques on Twitter Emotions Classification
    S. Santhosh Baboo
    M. Amirthapriya
    SN Computer Science, 2022, 3 (1)
  • [46] COMPARISON OF MACHINE LEARNING TECHNIQUES FOR PREDICTING NLR PROTEINS
    Nadia
    Gandotra, Ekta
    Kumar, Narendra
    BIOMEDICAL ENGINEERING-APPLICATIONS BASIS COMMUNICATIONS, 2023, 35 (02):
  • [47] Comparison of machine learning techniques for reservoir outflow forecasting
    Garcia-Feal, Orlando
    Gonzalez-Cao, Jose
    Fernandez-Novoa, Diego
    Astray Dopazo, Gonzalo
    Gomez-Gesteira, Moncho
    NATURAL HAZARDS AND EARTH SYSTEM SCIENCES, 2022, 22 (12) : 3859 - 3874
  • [48] Comparison of Machine Learning Techniques on MS Lesion Segmentation
    Dogan, Ahsen Feyza
    Goksel Duru, Dilek
    2019 MEDICAL TECHNOLOGIES CONGRESS (TIPTEKNO), 2019, : 393 - 396
  • [49] Comparison of Machine Learning Techniques for Software Quality Prediction
    Goyal, Somya
    INTERNATIONAL JOURNAL OF KNOWLEDGE AND SYSTEMS SCIENCE, 2020, 11 (02) : 20 - 40
  • [50] A comparison of machine learning techniques for customer churn prediction
    Vafeiadis, T.
    Diamantaras, K. I.
    Sarigiannidis, G.
    Chatzisavvas, K. Ch.
    SIMULATION MODELLING PRACTICE AND THEORY, 2015, 55 : 1 - 9