Forensic investigation method and tool based on the user behaviour analysis

Namheun Son, Sangjin Lee

Research output: Chapter in Book/Report/Conference proceedingConference contribution

2 Citations (Scopus)

Abstract

Today, people use a variety of digital devices, and events taking place in them are stored in specific forms mostly including data indicating when each event took place. So far, different methods have been constantly researched and developed to analyse various events, most of which analyse event data unnecessary for a forensic investigation. As a result, investigators should carry out additional work to select data needed for an actual investigation, making the process of analysis more difficult and longer. Besides, since the capacity of storage media gets higher and events become more diversified, such a phenomenon seems gradually worsened. Thus, this paper suggests a timeline-based method of checking 'users' behaviour patterns' at a look by analysing, interpreting and visualizing various user behaviour-based events in a short time, since time information exists in digital devices. Moreover, the range of analyses can be widened since investigators can analyse events through computer and smartphone used most out of all the digital devices, not simply through a single system.

Original languageEnglish
Title of host publicationProceedings of the 9th Australian Digital Forensics Conference
Pages125-133
Number of pages9
Publication statusPublished - 2011 Dec 1
Event9th Australian Digital Forensics Conference - Perth, WA, Australia
Duration: 2011 Dec 52011 Dec 7

Other

Other9th Australian Digital Forensics Conference
CountryAustralia
CityPerth, WA
Period11/12/511/12/7

Fingerprint

Digital devices
Smartphones

Keywords

  • Event based
  • Smartphone Forensics
  • Timeline-based
  • User Behaviour
  • Visualization

ASJC Scopus subject areas

  • Information Systems

Cite this

Son, N., & Lee, S. (2011). Forensic investigation method and tool based on the user behaviour analysis. In Proceedings of the 9th Australian Digital Forensics Conference (pp. 125-133)

Forensic investigation method and tool based on the user behaviour analysis. / Son, Namheun; Lee, Sangjin.

Proceedings of the 9th Australian Digital Forensics Conference. 2011. p. 125-133.

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Son, N & Lee, S 2011, Forensic investigation method and tool based on the user behaviour analysis. in Proceedings of the 9th Australian Digital Forensics Conference. pp. 125-133, 9th Australian Digital Forensics Conference, Perth, WA, Australia, 11/12/5.
Son N, Lee S. Forensic investigation method and tool based on the user behaviour analysis. In Proceedings of the 9th Australian Digital Forensics Conference. 2011. p. 125-133
Son, Namheun ; Lee, Sangjin. / Forensic investigation method and tool based on the user behaviour analysis. Proceedings of the 9th Australian Digital Forensics Conference. 2011. pp. 125-133
@inproceedings{b1fa20abc7884239b12e05b8830c1e1a,
title = "Forensic investigation method and tool based on the user behaviour analysis",
abstract = "Today, people use a variety of digital devices, and events taking place in them are stored in specific forms mostly including data indicating when each event took place. So far, different methods have been constantly researched and developed to analyse various events, most of which analyse event data unnecessary for a forensic investigation. As a result, investigators should carry out additional work to select data needed for an actual investigation, making the process of analysis more difficult and longer. Besides, since the capacity of storage media gets higher and events become more diversified, such a phenomenon seems gradually worsened. Thus, this paper suggests a timeline-based method of checking 'users' behaviour patterns' at a look by analysing, interpreting and visualizing various user behaviour-based events in a short time, since time information exists in digital devices. Moreover, the range of analyses can be widened since investigators can analyse events through computer and smartphone used most out of all the digital devices, not simply through a single system.",
keywords = "Event based, Smartphone Forensics, Timeline-based, User Behaviour, Visualization",
author = "Namheun Son and Sangjin Lee",
year = "2011",
month = "12",
day = "1",
language = "English",
isbn = "9780729806954",
pages = "125--133",
booktitle = "Proceedings of the 9th Australian Digital Forensics Conference",

}

TY - GEN

T1 - Forensic investigation method and tool based on the user behaviour analysis

AU - Son, Namheun

AU - Lee, Sangjin

PY - 2011/12/1

Y1 - 2011/12/1

N2 - Today, people use a variety of digital devices, and events taking place in them are stored in specific forms mostly including data indicating when each event took place. So far, different methods have been constantly researched and developed to analyse various events, most of which analyse event data unnecessary for a forensic investigation. As a result, investigators should carry out additional work to select data needed for an actual investigation, making the process of analysis more difficult and longer. Besides, since the capacity of storage media gets higher and events become more diversified, such a phenomenon seems gradually worsened. Thus, this paper suggests a timeline-based method of checking 'users' behaviour patterns' at a look by analysing, interpreting and visualizing various user behaviour-based events in a short time, since time information exists in digital devices. Moreover, the range of analyses can be widened since investigators can analyse events through computer and smartphone used most out of all the digital devices, not simply through a single system.

AB - Today, people use a variety of digital devices, and events taking place in them are stored in specific forms mostly including data indicating when each event took place. So far, different methods have been constantly researched and developed to analyse various events, most of which analyse event data unnecessary for a forensic investigation. As a result, investigators should carry out additional work to select data needed for an actual investigation, making the process of analysis more difficult and longer. Besides, since the capacity of storage media gets higher and events become more diversified, such a phenomenon seems gradually worsened. Thus, this paper suggests a timeline-based method of checking 'users' behaviour patterns' at a look by analysing, interpreting and visualizing various user behaviour-based events in a short time, since time information exists in digital devices. Moreover, the range of analyses can be widened since investigators can analyse events through computer and smartphone used most out of all the digital devices, not simply through a single system.

KW - Event based

KW - Smartphone Forensics

KW - Timeline-based

KW - User Behaviour

KW - Visualization

UR - http://www.scopus.com/inward/record.url?scp=84867700577&partnerID=8YFLogxK

UR - http://www.scopus.com/inward/citedby.url?scp=84867700577&partnerID=8YFLogxK

M3 - Conference contribution

SN - 9780729806954

SP - 125

EP - 133

BT - Proceedings of the 9th Australian Digital Forensics Conference

ER -