...
首页> 外文期刊>Information management & computer security >Forensic triage of email network narratives through visualisation
【24h】

Forensic triage of email network narratives through visualisation

机译:通过可视化对电子邮件网络叙述进行司法鉴定

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Purpose - The purpose of this paper is to propose a novel approach that automates the visualisation of both quantitative data (the network) and qualitative data (the content) within emails to aid the triage of evidence during a forensics investigation. Email remains a key source of evidence during a digital investigation, and a forensics examiner may be required to triage and analyse large email data sets for evidence. Current practice utilises tools and techniques that require a manual trawl through such data, which is a time-consuming process. Design/methodology/approach - This paper applies the methodology to the Enron email corpus, and in particular one key suspect, to demonstrate the applicability of the approach. Resulting visualisations of network narratives are discussed to show how network narratives may be used to triage large evidence data sets. Findings - Using the network narrative approach enables a forensics examiner to quickly identify relevant evidence within large email data sets. Within the case study presented in this paper, the results identify key witnesses, other actors of interest to the investigation and potential sources of further evidence. Practical implications - The implications are for digital forensics examiners or for security investigations that involve email data. The approach posited in this paper demonstrates the triage and visualisation of email network narratives to aid an investigation and identify potential sources of electronic evidence. Originality/value - There are a number of network visualisation applications in use. However, none of these enable the combined visualisation of quantitative and qualitative data to provide a view of what the actors are discussing and how this shapes the network in email data sets.
机译:目的-本文的目的是提出一种新颖的方法,该方法可以自动化电子邮件中定量数据(网络)和定性数据(内容)的可视化,以帮助在法医调查期间对证据进行分类。电子邮件仍然是数字调查期间的主要证据来源,并且可能需要法医检查人员对大型电子邮件数据集进行分类和分析以获取证据。当前的实践利用了需要对这些数据进行手动拖网的工具和技术,这是一个耗时的过程。设计/方法/方法-本文将方法论应用于Enron电子邮件语料库,尤其是一个主要的嫌疑人,以证明该方法的适用性。讨论了网络叙事的可视化结果,以显示如何利用网络叙事对大型证据数据集进行分类。调查结果-使用网络叙述方法,法医检查员可以快速识别大型电子邮件数据集中的相关证据。在本文介绍的案例研究中,研究结果确定了主要证人,调查感兴趣的其他行为者以及进一步证据的潜在来源。实际含义-含义是针对数字取证检查员或涉及电子邮件数据的安全调查。本文提出的方法演示了电子邮件网络叙述的分类和可视化,以帮助调查和识别电子证据的潜在来源。原创性/价值-有许多正在使用的网络可视化应用程序。但是,这些方法都无法实现定量和定性数据的组合可视化,以提供有关参与者正在讨论的内容以及这如何影响电子邮件数据集中的网络的视图。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号