DocumentCode
1957509
Title
A Prototype for Support of Computer Forensic Analysis Combined with the Expected Knowledge Level of an Attacker to More Efficiently Achieve Investigation Results
Author
Bielecki, M. ; Quirchmayr, G.
Author_Institution
Fac. of Comput. Sci., Univ. of Vienna, Vienna, Austria
fYear
2010
fDate
15-18 Feb. 2010
Firstpage
696
Lastpage
701
Abstract
This paper describes a novel approach to combine the strengths of an automated presentation and argumentation support system with a classification of cybercriminals similar to the ones used in law enforcement work. The discussed concept is still in an early stage of development with no substantiated scientific results. The beginning of the paper is dedicated to the description of a prototype based on an automated forensic support system called ??CFAA?? (??Computer Forensic Analyzer and Advisor??). This description is followed by a short classification of current cybercriminals and their knowledge levels. This classification is a slight modification of the one described in "Scene of the Cybercrime" by Debra Littlejohn Shinder. The paper then continues with the presentation of an envisaged approach towards combining the software tool with the determined classification to increase the efficiency of the forensic analysis. The core aim of this paper is to demonstrate the possible increase of efficiency with adjusting the appropriate cybercriminal levels according to the forensic investigation.
Keywords
computer forensics; pattern classification; software tools; CFAA support system; argumentation support system; automated presentation; computer forensic analysis; computer forensic analyzer and advisor; cybercriminal classification; determined classification; expected knowledge level; software tool; Books; Computer science; Conference management; Distributed computing; Engineering management; Forensics; Meetings; Prototypes; Publishing; Software engineering; IT forensics; classification of cybercriminals; combination of analysis with knowledge levels; formal models; prototype;
fLanguage
English
Publisher
ieee
Conference_Titel
Availability, Reliability, and Security, 2010. ARES '10 International Conference on
Conference_Location
Krakow
Print_ISBN
978-1-4244-5879-0
Type
conf
DOI
10.1109/ARES.2010.25
Filename
5438013
Link To Document