Eliciting file relationships using metadata based associations for digital forensics

被引:0
|
作者
Sriram Raghavan
S. V. Raghavan
机构
[1] Secure Cyber Space,Department of Computer Science & Engineering
[2] Indian Institute of Technology Madras,undefined
关键词
Metadata; Metadata association; Metadata family; File relationship; Association group; Association index;
D O I
10.1007/s40012-014-0046-4
中图分类号
学科分类号
摘要
In the conventional system of analysis that is concerned with digital forensics, content is analyzed to describe the state of files in digital evidence and ascertain their relevance. Such content analysis is carried out using “searching”. When searching a file or for a file, use of keywords is the norm. When the exact words are not known, one may use regular expression search which uses a more flexible language for describing a set of keywords that fit a pattern. During analysis, there is also a need to identify all types of associations that exist between the files to answer the six fundamental questions of what, when, where, how, who and why. If the keywords and pattern have limited scope, an examiner often has very little to go on. Metadata contains information that represents the state of a file, even if partially. Besides, metadata based search is amenable to automation by virtue of the ubiquitous nature of metadata. During analysis, metadata can be used to ascertain the nature of digital photographs that were processed using software and identify digitally generated images that resemble original photographs. Metadata can also be used to identify word processing documents that were derived from other documents and stored as a duplicate or after modification in such a way that traditional techniques cannot detect. Often what is needed is the ability to identify section(s) of the evidence where relevant information appears to reside. Metadata based matches give rise to file relationships that encapsulate the event sequence among related files aiding in the discovery. This paper proposes a method to automatically identify associations among the files in digital evidence at the syntactic and semantic levels using metadata. We apply this method to identify metadata associations from collections of image files and word processing documents and elicit inter-file relationships for the purpose of identifying interesting or relevant files from large file collections in digital evidence. We demonstrate that the file relationships identified using metadata help in the identification of doctored photographs and copied documents.
引用
收藏
页码:49 / 64
页数:15
相关论文
共 50 条
  • [1] On the role of file system metadata in digital forensics
    Buchholz, Florian
    Spafford, Eugene
    Digital Investigation, 2004, 1 (04) : 298 - 309
  • [2] The Value of Metadata in Digital Forensics
    Alanazi, Fahad
    Jones, Andrew
    2015 European Intelligence and Security Informatics Conference (EISIC), 2015, : 182 - 182
  • [3] Effectiveness of file-based deduplication in digital forensics
    Neuner, Sebastian
    Schmiedecker, Martin
    Weippl, Edgar
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (15) : 2876 - 2885
  • [4] Analytics using metadata associations for digital investigations
    Sriram Raghavan
    S. V. Raghavan
    CSI Transactions on ICT, 2017, 5 (3) : 315 - 338
  • [5] File Type Identification for Digital Forensics
    Karampidis, Konstantinos
    Papadourakis, Giorgos
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2016, 2016, 249 : 266 - 274
  • [6] A File Carving Algorithm for Digital Forensics
    Park, Deok-Gyu
    Park, Sang-Joon
    Lee, Jong-Chan
    No, Si-Young
    Shin, Seong-Yoon
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2009, PT I, 2009, 5592 : 615 - 626
  • [7] Taking advantages of a disadvantage: Digital forensics and steganography using document metadata
    Castiglione, Aniello
    De Santis, A.
    Soriente, C.
    JOURNAL OF SYSTEMS AND SOFTWARE, 2007, 80 (05) : 750 - 764
  • [8] Faster File Imaging Framework for Digital Forensics
    Kishore, Neha
    Kapoor, Bhanu
    PROCEEDINGS OF 4TH INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION AND CONTROL(ICAC3'15), 2015, 49 : 74 - 81
  • [9] FAIRness in digital forensics datasets' metadata - and how to improve it
    Mombelli, Samuele
    Lyle, James R.
    Breitinger, Frank
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2024, 48
  • [10] SlackStick: Signature-Based File Identification for Live Digital Forensics Examinations
    Hegarty, Rob
    Haggerty, John
    2015 EUROPEAN INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (EISIC), 2015, : 24 - 29