• DocumentCode
    2234870
  • Title

    Foundations for Visual Forensic Analysis

  • Author

    Teerlink, Sheldon ; Erbacher, Robert F.

  • Author_Institution
    Access Data, Lindon, UT
  • fYear
    2006
  • fDate
    21-23 June 2006
  • Firstpage
    192
  • Lastpage
    199
  • Abstract
    Computer forensics is the preservation, analysis, and interpretation of computer data. It is a crucial tool in the arsenal of law enforcement investigators, national security analysts, and corporate computer emergency response teams. There is a need for software that aids investigators in locating data on hard drives left by persons committing illegal activities. Analysts use forensic techniques to analyze insider attacks on organizations and recover data hidden or deleted by disgruntled employees or attackers. Advanced software tools are needed to reduce the tedious efforts of forensic examiners, especially when searching large hard drives. This paper discusses the background, algorithms, fundamentals, and techniques intrinsic to the visual analysis of typical computer forensic data. In terms of the visualization technique itself we discuss a visualization techniques to represent file statistics such as file size, last access date, creation date, last modification date, owner, number of i-nodes for fragmentation, and file type. The user interface to this software allows file searching, pattern matching, and the display of file contents
  • Keywords
    police data processing; software tools; advanced software tools; computer forensics; corporate computer emergency response teams; file contents display; file searching; law enforcement investigators; national security analysts; pattern matching; user interface; visual forensic analysis; visualization technique; Algorithm design and analysis; Data visualization; Displays; Forensics; Law enforcement; National security; Pattern matching; Software tools; Statistics; User interfaces;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance Workshop, 2006 IEEE
  • Conference_Location
    West Point, NY
  • Print_ISBN
    1-4244-0130-5
  • Type

    conf

  • DOI
    10.1109/IAW.2006.1652095
  • Filename
    1652095