Automated Digital Evidence Target Definition Using Outlier Analysis and Existing Evidence.

Brian D. Carrier, Eugene Howard Spafford · Digital Forensic Research Workshop · 2005

Searching for digital evidence is a time consuming and error-prone process. In this paper, we introduce techniques to automate the searching process by suggesting what searches could be helpful. We also use data mining techniques to find files and directories created during the incident. The results from using these techniques on a compromised honeypot system are given and show that the data mining techniques detect a higher percentage of files than a random sampling would, but there are still many false positives. More research into the error rates of manual searches is needed to fully understand the impact of automated techniques.

Read the paper · More papers on PaperTik