• DocumentCode
    245945
  • Title

    Improving Performance of Forensics Investigation with Parallel Coordinates Visual Analytics

  • Author

    Wen Bo Wang ; Mao Lin Huang ; Liangfu Lu ; Jinson Zhang

  • Author_Institution
    Fac. of Eng. & IT, Univ. of Technol., Sydney, NSW, Australia
  • fYear
    2014
  • fDate
    19-21 Dec. 2014
  • Firstpage
    1838
  • Lastpage
    1843
  • Abstract
    Computer forensics investigators aim to analyse and present facts through the examination of digital evidences in short times. As the volume of suspicious data is becoming large, the difficulties of catching the digital evidence in a legally acceptable time are high. This paper proposes an effective method for reducing investigation time redundancy to achieve the normalization of data on hard disk drives (HDD) for computer forensics. We use visualization techniques, parallel coordinates, to analyse data instead of using data analysis algorithms only, and also choose a Red-Black tree structure to de-duplicate data. It reduces the time complexity, including the time spent of searching data, adding data as well as deleting data. We show the advantages of our approach, moreover, we demonstrate how this method can enhance the efficiency and quality of computer forensics task.
  • Keywords
    computational complexity; data analysis; data visualisation; digital forensics; tree data structures; trees (mathematics); HDD; Red-Black tree structure; computer forensics investigation; data addition; data analysis; data deduplication; data deletion; data normalization; data searching; digital evidence examination; hard disk drives; investigation time redundancy; parallel coordinates visual analytics; performance improvement; suspicious data; time complexity reduction; visualization techniques; Analytical models; Computers; Data models; Data visualization; Forensics; Hard disks; Image color analysis; Computer Forensics; Digital Evidence; Red-Black Tree; Visuaization Techniques; parallel coordinates;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
  • Conference_Location
    Chengdu
  • Print_ISBN
    978-1-4799-7980-6
  • Type

    conf

  • DOI
    10.1109/CSE.2014.337
  • Filename
    7023848