• DocumentCode
    710204
  • Title

    Data Warehousing Based Computer Forensics Investigation Framework

  • Author

    Halboob, Waleed ; Mahmod, Ramlan ; Abulaish, Muhammad ; Abbas, Haider ; Saleem, Kashif

  • Author_Institution
    Center of Excellence in Inf. Assurance, King Saud Univ., Riyadh, Saudi Arabia
  • fYear
    2015
  • fDate
    13-15 April 2015
  • Firstpage
    163
  • Lastpage
    168
  • Abstract
    In this paper, we have proposed the design of an efficient computer forensics investigation framework. The proposed framework improves the investigation efficiency using Data Warehouse (DW) concept, which provides a selective evidence identification, collection and analysis. So, only relevant data is investigated instead of investigating the entire user data. The proposed framework consists of a Data Warehouse Engine (DWE) to selectively identify, collect and analyze digital evidences from multiple digital resources. A Digital Evidence Preservation (DEP) mechanism is also introduced for preservation of the collected digital evidences whose authenticity is ensured using cryptographic techniques. An access control mechanism is implemented to allow only authorized investigator to access the preserved digital evidences. The DEP mechanism provides court of law with a Secure Forensic Audit Trial (SFAT) that helps in tracking happened activities on the collected evidences for ensuring the authenticity and reliability of the presented digital evidence.
  • Keywords
    cryptography; data warehouses; digital forensics; DEP mechanism; DWE; SFAT; access control mechanism; computer forensics investigation framework; cryptographic technique; data warehouse engine; data warehousing; digital evidence preservation mechanism; secure forensic audit trial; selective evidence identification; Authorization; Computers; Data mining; Data warehouses; Digital forensics; Access control; Authenticity; Computer forensics; Data warehouse; Digital evidence; Efficiency; and reliability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology - New Generations (ITNG), 2015 12th International Conference on
  • Conference_Location
    Las Vegas, NV
  • Print_ISBN
    978-1-4799-8827-3
  • Type

    conf

  • DOI
    10.1109/ITNG.2015.31
  • Filename
    7113466