Machine Learning for Post-Event Timeline Reconstruction

Machine Learning for Post-Event Timeline Reconstruction
复制标题

用于事件后时间线重建的机器学习

DOI:
--
复制
发表时间:
2006
期刊:
影响因子:
--
通讯作者:
I. Wakeman
I. Wakeman
中科院分区:
--
文献类型:
--
作者:
Muhammad Naeem Khan;I. Wakeman

文献摘要

被引文献

相似文献

在本文中,我们提出了一种新的基于机器学习技术的事后时间线重建方法。事后时间线重建在法医调查中起着至关重要的作用,是数字犯罪的证据。在过去二十年中,开发了各种数字取证工具,以协助计算机取证调查人员进行数字时间轴分析,但大多数工具不能有效地处理大量数据。本文的重点是通过跟踪以前的文件系统活动和准备事件的时间表来概述使用机器学习方法进行计算机取证分析的有效性。我们的方法包括监视文件系统访问,通过运行不同的应用程序在离散的时间间隔获取文件系统快照,并使用这些数据训练递归神经网络以识别各个应用程序的执行模式。该网络的训练版本随后可用于生成被扣押的硬盘的事件后时间表,以在不同的时间间隔验证不同应用的执行。
In this paper, we present a novel approach for post- event timeline reconstruction using machine learning techniques. Post-event timeline reconstruction plays a critical role in forensic investigation and serves as evidence of the digital crime. A variety of digital forensic tools have been developed during last two decades to assist computer forensic investigators for digital timeline analysis but most of them cannot handle large volumes of data in an efficient manner. The focus of this paper is to outline the effectiveness of employing machine learning methodology for computer forensic analysis by tracing previous file-system activities and preparing a timeline of the events. Our approach consists of monitoring the file-system accesses, taking file-system snapshots at discrete intervals of time by running different applications and using this data to train a recurrent neural network to recognize the execution patterns of the individual applications. The trained version of the network could subsequently be used for generating post-event timeline of a seized hard disk to verify the execution of different applications at different time intervals.