DocumentCode :
2898843
Title :
A Quantitative Approach to Triaging in Mobile Forensics
Author :
Marturana, Fabio ; Me, Gianluigi ; Bertè, Rosamaria ; Tacconi, Simone
Author_Institution :
Dept. of Comput. Sci., Syst. & Production, Univ. of Rome Tor Vergata, Rome, Italy
fYear :
2011
fDate :
16-18 Nov. 2011
Firstpage :
582
Lastpage :
588
Abstract :
Forensic study of mobile devices is a relatively new field, dating from the early 2000s. The proliferation of phones (particularly smartphones) on the consumer market has caused a growing demand for forensic examination of the devices, which could not be met by existing Computer Forensics techniques. As a matter of fact, Law enforcement are much more likely to encounter a suspect with a mobile device in his possession than a PC or laptop and so the growth of demand for analysis of mobiles has increased exponentially in the last decade. Early investigations, moreover, consisted of live analysis of mobile devices by examining phone contents directly via the screen and photographing it with the risk of modifying the device content, as well as leaving many parts of the proprietary operating system inaccessible. The recent development of Mobile Forensics, a branch of Digital Forensics, is the answer to the demand of forensically sound examination procedures of gathering, retrieving, identifying, storing and documenting evidence of any digital device that has both internal memory and communication ability [1]. Over time commercial tools appeared which allowed analysts to recover phone content with minimal interference and examine it separately. By means of such toolkits, moreover, it is now possible to think of a new approach to Mobile Forensics which takes also advantage of "Data Mining" and "Machine Learning" theory. This paper is the result of study concerning cell phones classification in a real case of pedophilia. Based on Mobile Forensics "Triaging" concept and the adoption of self-knowledge algorithms for classifying mobile devices, we focused our attention on a viable way to predict phone usage\´s classifications. Based on a set of real sized phones, the research has been extensively discussed with Italian law enforcement cybercrime specialists in order to find a viable methodology to determine the likelihood that a mobile phone has been used to commit the specif- c crime of pedophilia, which could be very relevant during a forensic investigation.
Keywords :
computer forensics; data mining; law administration; learning (artificial intelligence); mobile handsets; Italian law enforcement cybercrime specialists; cell phones classification; computer forensics techniques; data mining; digital forensics; machine learning; mobile devices; mobile forensics; pedophilia; phone contents examining; proprietary operating system; triaging; Classification algorithms; Data mining; Decision trees; Forensics; Mobile communication; Mobile handsets; Testing; Data Mining; Knowledge Analysis; Machine Learning; Mobile Forensics; Triaging;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on
Conference_Location :
Changsha
Print_ISBN :
978-1-4577-2135-9
Type :
conf
DOI :
10.1109/TrustCom.2011.75
Filename :
6120868
Link To Document :
بازگشت