Eliciting file relationships using metadata based associations for digital forensics

被引:0
|
作者
Sriram Raghavan
S. V. Raghavan
机构
[1] Secure Cyber Space,Department of Computer Science & Engineering
[2] Indian Institute of Technology Madras,undefined
关键词
Metadata; Metadata association; Metadata family; File relationship; Association group; Association index;
D O I
10.1007/s40012-014-0046-4
中图分类号
学科分类号
摘要
In the conventional system of analysis that is concerned with digital forensics, content is analyzed to describe the state of files in digital evidence and ascertain their relevance. Such content analysis is carried out using “searching”. When searching a file or for a file, use of keywords is the norm. When the exact words are not known, one may use regular expression search which uses a more flexible language for describing a set of keywords that fit a pattern. During analysis, there is also a need to identify all types of associations that exist between the files to answer the six fundamental questions of what, when, where, how, who and why. If the keywords and pattern have limited scope, an examiner often has very little to go on. Metadata contains information that represents the state of a file, even if partially. Besides, metadata based search is amenable to automation by virtue of the ubiquitous nature of metadata. During analysis, metadata can be used to ascertain the nature of digital photographs that were processed using software and identify digitally generated images that resemble original photographs. Metadata can also be used to identify word processing documents that were derived from other documents and stored as a duplicate or after modification in such a way that traditional techniques cannot detect. Often what is needed is the ability to identify section(s) of the evidence where relevant information appears to reside. Metadata based matches give rise to file relationships that encapsulate the event sequence among related files aiding in the discovery. This paper proposes a method to automatically identify associations among the files in digital evidence at the syntactic and semantic levels using metadata. We apply this method to identify metadata associations from collections of image files and word processing documents and elicit inter-file relationships for the purpose of identifying interesting or relevant files from large file collections in digital evidence. We demonstrate that the file relationships identified using metadata help in the identification of doctored photographs and copied documents.
引用
收藏
页码:49 / 64
页数:15
相关论文
共 50 条
  • [31] Computer Forensics Research and Implementation Based on NTFS File System
    Liu Naiqi
    Wang Zhongshan
    Hao Yujie
    QinKe
    2008 ISECS INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT, VOL 1, PROCEEDINGS, 2008, : 519 - +
  • [32] Analysis and Implementation of UFS File System Based on Computer Forensics
    Yang Lei
    Gao Qinquan
    Luo Delin
    Wu Shunxiang
    QUANTUM, NANO, MICRO AND INFORMATION TECHNOLOGIES, 2011, 39 : 186 - 191
  • [33] DESIGN FOR NETWORK FILE FORENSICS SYSTEM BASED ON APPROXIMATE MATCHING
    Xu, Fei
    Liu, Pinxin
    FORENSIC SCIENCE INTERNATIONAL, 2017, 277 : 120 - 120
  • [34] Using asynchronous writes on metadata to improve file system performance
    Feng, LC
    Chang, RC
    JOURNAL OF SYSTEMS AND SOFTWARE, 1996, 35 (01) : 43 - 54
  • [35] Using asynchronous writes on metadata to improve file system performance
    Natl Chiao Tung Univ, Hsinshu, Taiwan
    J Syst Software, 1 (43-54):
  • [36] Problem based learning in digital forensics
    Irons, Alastair
    Thomas, Paula
    HIGHER EDUCATION PEDAGOGIES, 2016, 1 (01): : 95 - 105
  • [37] A blockchain based private framework for facilitating digital forensics using IoT
    Suri, Bhawna
    Taneja, Shweta
    Sharma, Siddharth
    Verma, Vishwajeet
    Parashar, Divyanshi
    Sikka, Parth
    Arora, Monika
    Ahmad, Sayed Sayeed
    JOURNAL OF DISCRETE MATHEMATICAL SCIENCES & CRYPTOGRAPHY, 2023, 26 (05): : 1249 - 1263
  • [38] Forensic Application-Fingerprinting based on File System Metadata
    Kaelber, Sven
    Dewald, Andreas
    Freiling, Felix C.
    2013 SEVENTH INTERNATIONAL CONFERENCE ON IT SECURITY INCIDENT MANAGEMENT AND IT FORENSICS (IMF 2013), 2013, : 98 - 112
  • [39] Implementation and Analysis of the File System Based on Metadata Dynamic Hashing
    Ma, Si
    Cai, Tao
    Zhan, Yongzhao
    MECHATRONICS AND INTELLIGENT MATERIALS II, PTS 1-6, 2012, 490-495 : 1034 - 1038
  • [40] Android Digital Forensics - Simplifying Android Forensics Using Regular Expressions
    Jeyamohan, Neera
    2017 17TH INTERNATIONAL CONFERENCE ON ADVANCES IN ICT FOR EMERGING REGIONS (ICTER) - 2017, 2017, : 348 - 348