Title :
A visual analytic framework for exploring relationships in textual contents of digital forensics evidence
Author :
Jankun-Kelly, T.J. ; Wilson, David ; Stamps, Andrew S. ; Franck, Josh ; Carver, Jeffery ; Swan, J. Edward, II
Author_Institution :
Mississippi State Univ., Starkville, MS, USA
Abstract :
We describe the development of a set of tools for analyzing the textual contents of digital forensic evidence for the purpose of enhancing an investigator´s ability to discover information quickly and efficiently. By examining the textual contents of files and unallocated space, relationships between sets of files and clusters can be formed based on the information that they contain. Using the information gathered from the evidence through the analysis tool, the visualization tool can be used to search through the evidence in an organized and efficient manner. The visualization depicts both the frequency of relevant terms and their location on disk. We also discuss a task analysis with forensics officers to motivate the design.
Keywords :
computer forensics; data visualisation; task analysis; text analysis; computer forensic; digital forensics evidence; task analysis; textual content analysis; visualization tool; Computer crime; Computer graphics; Computer science; Digital forensics; Frequency; Image analysis; Image generation; Information analysis; Visual analytics; Visualization; I.3.3 [Computer Graphics]: Picture/Image Generation; I.3.8 [Computer Graphics]: Applications-Visualization; K.6.m [Management of Computing and Information Systems]: Miscellaneous-Security;
Conference_Titel :
Visualization for Cyber Security, 2009. VizSec 2009. 6th International Workshop on
Conference_Location :
Atlantic City, NJ
Print_ISBN :
978-1-4244-5413-6
DOI :
10.1109/VIZSEC.2009.5375541