首页> 外文会议>IFIP WG 11.9 International Conference on Digital Forensics >AUTOMATED COLLECTION AND CORRELATION OF FILE PROVENANCE INFORMATION
【24h】

AUTOMATED COLLECTION AND CORRELATION OF FILE PROVENANCE INFORMATION

机译:自动收集和文件源信息的相关性

获取原文

摘要

The provenance of a file is a detailing of its origins and activities. Tools have been developed that help maintain the provenance of files. However, these tools require prior installation on a computer of interest before and while provenance-generating events occur. The automated tool described in this chapter can reconstruct the provenance of a file from a variety of artifacts. It identifies relevant temporal and user correlations between the artifacts and presents them to an investigator. Results from six use cases demonstrate that these correlations are reliable and valuable in digital forensic investigations.
机译:文件的出处是其起源和活动的详细信息。已经开发了有助于维护文件的出处的工具。但是,这些工具需要先安装在感兴趣的计算机上,同时出处生成事件发生。本章中描述的自动化工具可以重建来自各种伪影的文件的出处。它识别伪像之间的相关时间和用户相关性,并将它们呈现给调查员。六种用例的结果表明,这些相关性在数字法医调查中是可靠的和有价值的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号