An Ontology Engineering Case Study for Advanced Digital Forensic Analysis

Pavel Chikul, Hayretdin Bahsi, Olaf Maennel

Research output: Chapter in Book/Report/Conference proceedingConference contribution

1 Scopus citations

Abstract

Digital forensics faces some serious challenges at present. Those challenges include ever-increasing processed data volumes, heterogeneous nature of evidentiary artifacts, multiple data sources incompatible with each other, and more. Most of the commonly used forensic tools do not provide an intuitive and convenient way of accessing the data. At the same time, storage types such as relational databases cannot fully satisfy the need to store heterogeneous objects and efficiently provide access to specific properties. In this paper, we present an ontology-based approach to processing digital evidence and handling the course of digital investigation. The proposed system, named ForensicFlow, provides means of automatic artifact extraction from different origin sources, namely volatile and non-volatile memory, and reconstruction of event-artifact graphs in order to assist forensic experts in quickly and efficiently outlining the scope of an incident, and conducting an investigation.

Original languageEnglish (US)
Title of host publicationModel and Data Engineering - 10th International Conference, MEDI 2021, Proceedings
EditorsChristian Attiogbé, Sadok Ben Yahia
PublisherSpringer Science and Business Media Deutschland GmbH
Pages67-74
Number of pages8
ISBN (Print)9783030784270
DOIs
StatePublished - 2021
Externally publishedYes
Event10th International Conference on Model and Data Engineering, MEDI 2021 - Virtual, Online
Duration: Jun 21 2021Jun 23 2021

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume12732 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference10th International Conference on Model and Data Engineering, MEDI 2021
CityVirtual, Online
Period6/21/216/23/21

Keywords

  • Digital forensics
  • Event reconstruction
  • Ontology
  • Ransomware
  • Semantic web

ASJC Scopus subject areas

  • Theoretical Computer Science
  • General Computer Science

Fingerprint

Dive into the research topics of 'An Ontology Engineering Case Study for Advanced Digital Forensic Analysis'. Together they form a unique fingerprint.

Cite this