• DocumentCode
    2212205
  • Title

    Automated Event Log File Recovery Based on Content Characters and Internal Structure

  • Author

    Lou, Yongjian ; Wang, Peng ; Xu, Ming ; Zheng, Ning

  • Author_Institution
    Comput. & Software Inst., Hangzhou Dianzi Univ., Hangzhou, China
  • fYear
    2009
  • fDate
    26-28 Dec. 2009
  • Firstpage
    4778
  • Lastpage
    4781
  • Abstract
    Rapidly retrieving valuable information is vital in computer forensic, especially information with respect to the computer system itself. Attentions on the system information such as registry and event log have increasingly promoted the forensic researches. Event log is a very import file in computer, which contains a large amount of available information about what happened on the system observed, but current forensic tool on event log only can repair corrupted log files and has no effect on the situation that event log file has been fragmented. To address this problem, this paper presents an algorithm which allows search for windows event log file data fragments based solely on their data contents, without the need of any meta data. The algorithm is based on searching the signature in log file combining with computing the entropy difference between neighboring clusters. A tool was developed to automate recovery and parse of Windows NT5 (XP and 2003) event logs for computer forensic. This tool automates repair of multiple event logs and parse the recovered files without user intervention. The evaluation of this method shows an average accuracy of 82.5%, with lower false positive.
  • Keywords
    computer forensics; operating systems (computers); system recovery; Windows NT5; automated event log file recovery; computer forensic; computer system; content character; entropy difference; forensic tool; import file; internal structure; log file signature; neighboring cluster; parse; system information; Clustering algorithms; Content based retrieval; Digital forensics; Entropy; File systems; Image analysis; Image retrieval; Information retrieval; Information science; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Science and Engineering (ICISE), 2009 1st International Conference on
  • Conference_Location
    Nanjing
  • Print_ISBN
    978-1-4244-4909-5
  • Type

    conf

  • DOI
    10.1109/ICISE.2009.351
  • Filename
    5454707