Title : 
Considerations Towards a Cyber Crime Profiling System
         
        
            Author : 
Arthur, Kweku K. ; Olivier, Martin S. ; Venter, Hein S. ; Eloff, Jan H P
         
        
            Author_Institution : 
Dept. of Comput. Sci., Pretoria Univ., Tshwane
         
        
        
        
        
            Abstract : 
The field of digital forensics is faced with a number of challenges, given the constant growth in technologies. The reliability and integrity associated with digital evidence from disparate sources is also a perpetual challenge, requiring considerable human interpretation in the reconstruction of any particular sequence of events. In this paper we present a framework for an integrity-aware forensic evidence management system (FEMS). In an effort to automate the analysis process, this system would provide investigators with a holistic view of the forensic evidence at hand; thereby providing insights into the quality of investigative inferences. The Biba integrity model is incorporated to preserve the integrity of digital evidence, while Casey´s Certainty Scale is chosen as the integrity classification scheme. A finite state automaton (FSA) is used to model the behaviour of the FEMS. In so doing, cyber crime profiling is achieved.
         
        
            Keywords : 
computer crime; data integrity; finite state machines; Casey certainty scale; cyber crime profiling system; digital evidence; finite state automaton; integrity classification scheme; integrity-aware forensic evidence management system; Automata; Availability; Computer crime; Computer security; Digital forensics; Law; Legal factors; Military computing; NASA; US Government;
         
        
        
        
            Conference_Titel : 
Availability, Reliability and Security, 2008. ARES 08. Third International Conference on
         
        
            Conference_Location : 
Barcelona
         
        
            Print_ISBN : 
978-0-7695-3102-1
         
        
        
            DOI : 
10.1109/ARES.2008.107