General finite state machine reasoning method for digital forensics

Long Chen, Guoyin Wang · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2008

Digital forensics investigator faces the challenge of reliability of forensic conclusions. Formal automatic analysis method is helpful to deal with the challenge. The finite state machine analysis method tries to determine all possible sequences of events that could have happened in a digital system during an incident. Its basic idea is to model the target system using a finite state machine and then explore its all possible states on the condition of available evidence. Timed mealy finite state machine is introduced to model the target system, and the formalization of system running process and evidence is presented to match the system running with possible source evidence automatically. Based on Gladyshev's basic reasoning method, general reasoning algorithms with multi strategies are developed to find the possible real scenarios. Case study and experimental results show that our method is feasible and adaptable to possible cases and takes a further step to practical formal reasoning for digital forensics.

Read the paper · More papers on PaperTik