Automated Collection and Correlation of File Provenance Information - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

Automated Collection and Correlation of File Provenance Information

Résumé

The provenance of a file is a detailing of its origins and activities. Tools have been developed that help maintain the provenance of files. However, these tools require prior installation on a computer of interest before and while provenance-generating events occur. The automated tool described in this chapter can reconstruct the provenance of a file from a variety of artifacts. It identifies relevant temporal and user correlations between the artifacts and presents them to an investigator. Results from six use cases demonstrate that these correlations are reliable and valuable in digital forensic investigations.
Fichier principal
Vignette du fichier
456364_1_En_15_Chapter.pdf (139 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01716392 , version 1 (23-02-2018)

Licence

Paternité

Identifiants

Citer

Ryan Good, Gilbert Peterson. Automated Collection and Correlation of File Provenance Information. 13th IFIP International Conference on Digital Forensics (DigitalForensics), Jan 2017, Orlando, FL, United States. pp.269-284, ⟨10.1007/978-3-319-67208-3_15⟩. ⟨hal-01716392⟩
108 Consultations
111 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More