Eliciting file relationships using metadata based associations for digital forensics

被引:0
|
作者
Sriram Raghavan
S. V. Raghavan
机构
[1] Secure Cyber Space,Department of Computer Science & Engineering
[2] Indian Institute of Technology Madras,undefined
关键词
Metadata; Metadata association; Metadata family; File relationship; Association group; Association index;
D O I
10.1007/s40012-014-0046-4
中图分类号
学科分类号
摘要
In the conventional system of analysis that is concerned with digital forensics, content is analyzed to describe the state of files in digital evidence and ascertain their relevance. Such content analysis is carried out using “searching”. When searching a file or for a file, use of keywords is the norm. When the exact words are not known, one may use regular expression search which uses a more flexible language for describing a set of keywords that fit a pattern. During analysis, there is also a need to identify all types of associations that exist between the files to answer the six fundamental questions of what, when, where, how, who and why. If the keywords and pattern have limited scope, an examiner often has very little to go on. Metadata contains information that represents the state of a file, even if partially. Besides, metadata based search is amenable to automation by virtue of the ubiquitous nature of metadata. During analysis, metadata can be used to ascertain the nature of digital photographs that were processed using software and identify digitally generated images that resemble original photographs. Metadata can also be used to identify word processing documents that were derived from other documents and stored as a duplicate or after modification in such a way that traditional techniques cannot detect. Often what is needed is the ability to identify section(s) of the evidence where relevant information appears to reside. Metadata based matches give rise to file relationships that encapsulate the event sequence among related files aiding in the discovery. This paper proposes a method to automatically identify associations among the files in digital evidence at the syntactic and semantic levels using metadata. We apply this method to identify metadata associations from collections of image files and word processing documents and elicit inter-file relationships for the purpose of identifying interesting or relevant files from large file collections in digital evidence. We demonstrate that the file relationships identified using metadata help in the identification of doctored photographs and copied documents.
引用
收藏
页码:49 / 64
页数:15
相关论文
共 50 条
  • [41] Research and Design of Similar File Forensics System Based on Fuzzy Hash
    Jiang Jianguo
    Chen Jiuming
    Yu Qian
    Liu Kunying
    Liu Chao
    2016 IEEE INFORMATION TECHNOLOGY, NETWORKING, ELECTRONIC AND AUTOMATION CONTROL CONFERENCE (ITNEC), 2016, : 342 - 346
  • [42] IDIOGRAPHIC DIGITAL PROFILING: BEHAVIORAL ANALYSIS BASED ON DIGITAL FORENSICS
    Steel, Chad M.
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2014, 9 (01) : 7 - 18
  • [43] Concurrent File Metadata Structure Using Readers-Writer Lock
    Lee, Chang-Gyu
    Noh, Sunghyun
    Kang, Hyeongu
    Hwang, Soon
    Kim, Youngjae
    36TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, SAC 2021, 2021, : 1172 - 1181
  • [44] DIGITAL AUDIO FORENSICS USING BACKGROUND NOISE
    Ikram, Sohaib
    Malik, Hafiz
    2010 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO (ICME 2010), 2010, : 106 - 110
  • [45] Digital Image Forensics Using EM Algorithm
    Lin, Tim-kun
    Huang, Chung-Lin
    ADVANCES IN MULTIMEDIA INFORMATION PROCESSING - PCM 2009, 2009, 5879 : 994 - 998
  • [46] HopsFS: Scaling Hierarchical File System Metadata Using NewSQL Databases
    Niazi, Salman
    Ismail, Mahmoud
    Haridi, Seif
    Dowling, Jim
    Grohsschmiedt, Steffen
    Ronstrom, Mikael
    PROCEEDINGS OF FAST '17: 15TH USENIX CONFERENCE ON FILE AND STORAGE TECHNOLOGIES, 2017, : 89 - 103
  • [47] Identifying Persons of Interest in Digital Forensics Using NLP-Based AI
    Adkins, Jonathan
    Al Bataineh, Ali
    Khalaf, Majd
    FUTURE INTERNET, 2024, 16 (11)
  • [48] Similarity Analysis of Ransomware based on Portable Executable (PE) File Metadata
    Ayub, Md Ahsan
    Sirai, Ambareen
    2021 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI 2021), 2021,
  • [49] Fast and Low Overhead Metadata Operations for NVM-Based File System Using Slotted Paging
    Lin, Fangzhu
    Xiao, Chunhua
    Liu, Weichen
    Wu, Lin
    Shi, Chen
    Ning, Kun
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2022, 41 (11) : 4481 - 4491
  • [50] How Metadata Enables Enriched File-Based Production Workflows
    Van Rijsselbergen, Dieter
    Verwaest, Maarten
    Mannens, Erik
    Van de Walle, Rik
    SMPTE MOTION IMAGING JOURNAL, 2010, 119 (04): : 27 - 38