DocumentCode
2234870
Title
Foundations for Visual Forensic Analysis
Author
Teerlink, Sheldon ; Erbacher, Robert F.
Author_Institution
Access Data, Lindon, UT
fYear
2006
fDate
21-23 June 2006
Firstpage
192
Lastpage
199
Abstract
Computer forensics is the preservation, analysis, and interpretation of computer data. It is a crucial tool in the arsenal of law enforcement investigators, national security analysts, and corporate computer emergency response teams. There is a need for software that aids investigators in locating data on hard drives left by persons committing illegal activities. Analysts use forensic techniques to analyze insider attacks on organizations and recover data hidden or deleted by disgruntled employees or attackers. Advanced software tools are needed to reduce the tedious efforts of forensic examiners, especially when searching large hard drives. This paper discusses the background, algorithms, fundamentals, and techniques intrinsic to the visual analysis of typical computer forensic data. In terms of the visualization technique itself we discuss a visualization techniques to represent file statistics such as file size, last access date, creation date, last modification date, owner, number of i-nodes for fragmentation, and file type. The user interface to this software allows file searching, pattern matching, and the display of file contents
Keywords
police data processing; software tools; advanced software tools; computer forensics; corporate computer emergency response teams; file contents display; file searching; law enforcement investigators; national security analysts; pattern matching; user interface; visual forensic analysis; visualization technique; Algorithm design and analysis; Data visualization; Displays; Forensics; Law enforcement; National security; Pattern matching; Software tools; Statistics; User interfaces;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance Workshop, 2006 IEEE
Conference_Location
West Point, NY
Print_ISBN
1-4244-0130-5
Type
conf
DOI
10.1109/IAW.2006.1652095
Filename
1652095
Link To Document