Title :
Improving Performance of Forensics Investigation with Parallel Coordinates Visual Analytics
Author :
Wen Bo Wang ; Mao Lin Huang ; Liangfu Lu ; Jinson Zhang
Author_Institution :
Fac. of Eng. & IT, Univ. of Technol., Sydney, NSW, Australia
Abstract :
Computer forensics investigators aim to analyse and present facts through the examination of digital evidences in short times. As the volume of suspicious data is becoming large, the difficulties of catching the digital evidence in a legally acceptable time are high. This paper proposes an effective method for reducing investigation time redundancy to achieve the normalization of data on hard disk drives (HDD) for computer forensics. We use visualization techniques, parallel coordinates, to analyse data instead of using data analysis algorithms only, and also choose a Red-Black tree structure to de-duplicate data. It reduces the time complexity, including the time spent of searching data, adding data as well as deleting data. We show the advantages of our approach, moreover, we demonstrate how this method can enhance the efficiency and quality of computer forensics task.
Keywords :
computational complexity; data analysis; data visualisation; digital forensics; tree data structures; trees (mathematics); HDD; Red-Black tree structure; computer forensics investigation; data addition; data analysis; data deduplication; data deletion; data normalization; data searching; digital evidence examination; hard disk drives; investigation time redundancy; parallel coordinates visual analytics; performance improvement; suspicious data; time complexity reduction; visualization techniques; Analytical models; Computers; Data models; Data visualization; Forensics; Hard disks; Image color analysis; Computer Forensics; Digital Evidence; Red-Black Tree; Visuaization Techniques; parallel coordinates;
Conference_Titel :
Computational Science and Engineering (CSE), 2014 IEEE 17th International Conference on
Conference_Location :
Chengdu
Print_ISBN :
978-1-4799-7980-6
DOI :
10.1109/CSE.2014.337