arXiv · 1302.2395
Signature Based Detection of User Events for Post-Mortem Forensic Analysis
Abstract
This paper introduces a novel approach to user event reconstruction by showing the practicality of generating and implementing signature-based analysis methods to reconstruct high-level user actions from a collection of low-level traces found during a post-mortem forensic analysis of a system. Traditional forensic analysis and the inferences an investigator normally makes when given digital evidence, are examined. It is then demonstrated that this natural process of inferring high-level events from low-level traces may be encoded using signature-matching techniques. Simple signatures using the defined method are created and applied for three popular Windows-based programs as a proof of concept.
Explore related subjects
Keep this discovery
Joshua I. James, Pavel Gladyshev, Yuandong Zhu. 2013-02-11. Signature Based Detection of User Events for Post-Mortem Forensic Analysis. https://doi.org/10.1007/978-3-642-19513-6_8
Cite the original work for its findings. Save a collection to share your selection of sources.