Eliciting file relationships using metadata based associations for digital forensics

被引:0
|
作者
Sriram Raghavan
S. V. Raghavan
机构
[1] Secure Cyber Space,Department of Computer Science & Engineering
[2] Indian Institute of Technology Madras,undefined
关键词
Metadata; Metadata association; Metadata family; File relationship; Association group; Association index;
D O I
10.1007/s40012-014-0046-4
中图分类号
学科分类号
摘要
In the conventional system of analysis that is concerned with digital forensics, content is analyzed to describe the state of files in digital evidence and ascertain their relevance. Such content analysis is carried out using “searching”. When searching a file or for a file, use of keywords is the norm. When the exact words are not known, one may use regular expression search which uses a more flexible language for describing a set of keywords that fit a pattern. During analysis, there is also a need to identify all types of associations that exist between the files to answer the six fundamental questions of what, when, where, how, who and why. If the keywords and pattern have limited scope, an examiner often has very little to go on. Metadata contains information that represents the state of a file, even if partially. Besides, metadata based search is amenable to automation by virtue of the ubiquitous nature of metadata. During analysis, metadata can be used to ascertain the nature of digital photographs that were processed using software and identify digitally generated images that resemble original photographs. Metadata can also be used to identify word processing documents that were derived from other documents and stored as a duplicate or after modification in such a way that traditional techniques cannot detect. Often what is needed is the ability to identify section(s) of the evidence where relevant information appears to reside. Metadata based matches give rise to file relationships that encapsulate the event sequence among related files aiding in the discovery. This paper proposes a method to automatically identify associations among the files in digital evidence at the syntactic and semantic levels using metadata. We apply this method to identify metadata associations from collections of image files and word processing documents and elicit inter-file relationships for the purpose of identifying interesting or relevant files from large file collections in digital evidence. We demonstrate that the file relationships identified using metadata help in the identification of doctored photographs and copied documents.
引用
收藏
页码:49 / 64
页数:15
相关论文
共 50 条
  • [21] A Novel Distributed File System Using Blockchain Metadata
    Kumar, Deepa S.
    Dija, S.
    Sumithra, M. D.
    Rahman, M. Abdul
    Nair, Praseeda B.
    WIRELESS PERSONAL COMMUNICATIONS, 2023, 129 (01) : 501 - 520
  • [22] Richer file system metadata using links and attributes
    Ames, A
    Bobb, N
    Brandt, SA
    Hiatt, A
    Maltzahn, C
    Miller, EL
    Neeman, A
    Tuteja, D
    TWENTY-SECOND IEEE/THIRTEENTH NASA GODDARD CONFERENCE ON MASS STORAGE SYSTEMS AND TECHNOLOGIES, PROCEEDINGS: INFORMATION RETRIEVAL FROM VERY LARGE STORAGE SYSTEMS, 2005, : 49 - 60
  • [23] Memory based metadata server for cluster file systems
    Xing, Jing
    Xiong, Jin
    Ma, Jie
    Sun, Ninghui
    GCC 2008: SEVENTH INTERNATIONAL CONFERENCE ON GRID AND COOPERATIVE COMPUTING, PROCEEDINGS, 2008, : 287 - +
  • [24] Archival Metadata for Digital Cultural Heritage Conceptual Provenance, Contextual Forensics, and the Authority of the Found Digital Object
    Tennis, Joseph T.
    2015 DIGITAL HERITAGE INTERNATIONAL CONGRESS, VOL 2: ANALYSIS & INTERPRETATION THEORY, METHODOLOGIES, PRESERVATION & STANDARDS DIGITAL HERITAGE PROJECTS & APPLICATIONS, 2015, : 399 - 401
  • [25] Data investigation based on XFS file system metadata
    Park, Yongmin
    Chang, Hyunsoo
    Shon, Taeshik
    MULTIMEDIA TOOLS AND APPLICATIONS, 2016, 75 (22) : 14721 - 14743
  • [26] Data investigation based on XFS file system metadata
    Yongmin Park
    Hyunsoo Chang
    Taeshik Shon
    Multimedia Tools and Applications, 2016, 75 : 14721 - 14743
  • [27] A digital video tampering forensics scheme based on forensics hash
    Wei, Hui
    Yang, Gao-Bo
    Xia, Ming
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2013, 35 (12): : 2934 - 2941
  • [28] Computer Forensics Using Graphics Processing Unit for File Searching
    Fails, Andrea
    PROCEEDINGS OF THE 50TH ANNUAL ASSOCIATION FOR COMPUTING MACHINERY SOUTHEAST CONFERENCE, 2012,
  • [29] ADAPTIVE TRADEOFF IN METADATA-BASED SMALL FILE OPTIMIZATIONS FOR A CLUSTER FILE SYSTEM
    Li, Xiuqiao
    Dong, Bin
    Xiao, Limin
    Ruan, Li
    INTERNATIONAL JOURNAL OF NUMERICAL ANALYSIS AND MODELING, 2012, 9 (02) : 289 - 303
  • [30] Use of Machine Learning Algorithm on File Metadata for Digital Forensic Investigation Process
    Panchal, Esan P.
    Yagnik, Shruti B.
    Sharma, B. K.
    THIRD INTERNATIONAL CONGRESS ON INFORMATION AND COMMUNICATION TECHNOLOGY, 2019, 797 : 401 - 408