Whitelisting system state in windows forensic memory visualizations. (March 2017)
- Record Type:
- Journal Article
- Title:
- Whitelisting system state in windows forensic memory visualizations. (March 2017)
- Main Title:
- Whitelisting system state in windows forensic memory visualizations
- Authors:
- Lapso, Joshua A.
Peterson, Gilbert L.
Okolica, James S. - Abstract:
- Abstract: Examiners in the field of digital forensics regularly encounter enormous amounts of data and must identify the few artifacts of evidentiary value. One challenge these examiners face is manual reconstruction of complex datasets with both hierarchical and associative relationships. The complexity of this data requires significant knowledge, training, and experience to correctly and efficiently examine. Current methods provide text-based representations or low-level visualizations, but levee the task of maintaining global context of system state on the examiner. This research presents a visualization tool that improves analysis methods through simultaneous representation of the hierarchical and associative relationships and local detailed data within a single page application. A novel whitelisting feature further improves analysis by eliminating items of less interest from view. Results from a pilot study demonstrate that the visualization tool can assist examiners to more accurately and quickly identify artifacts of interest.
- Is Part Of:
- Digital investigation. Volume 20(2016)
- Journal:
- Digital investigation
- Issue:
- Volume 20(2016)
- Issue Display:
- Volume 20, Issue 2016 (2016)
- Year:
- 2016
- Volume:
- 20
- Issue:
- 2016
- Issue Sort Value:
- 2016-0020-2016-0000
- Page Start:
- 2
- Page End:
- 15
- Publication Date:
- 2017-03
- Subjects:
- Memory forensics -- Incident response -- Information visualization -- Forensic visualization tools -- Single page web application -- D3.js
Forensic sciences -- Data processing -- Periodicals
Criminal investigation -- Data processing -- Periodicals
363.250285 - Journal URLs:
- http://www.sciencedirect.com/science/journal/17422876 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.diin.2016.12.002 ↗
- Languages:
- English
- ISSNs:
- 1742-2876
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3588.396620
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 166.xml