A Digital Media Similarity Measure for Triage of Digital Forensic Evidence - Advances in Digital Forensics XVI Access content directly
Conference Papers Year : 2020

A Digital Media Similarity Measure for Triage of Digital Forensic Evidence

Myeong Lim
  • Function : Author
  • PersonId : 1133680

Abstract

As the volume of potential digital evidence increases, digital forensic practitioners are challenged to determine the best allocation of their limited resources. While automation will continue to partially mitigate this problem, the preliminary question about which media should be examined by human or machine remains largely unsolved. This chapter describes and validates a methodology for assessing digital media similarity to assist with digital media triage decisions. The application of the methodology is predicated on the idea that unexamined media is likely to be relevant or interesting to a practitioner if the media is similar to other media that were previously determined to be relevant or interesting. The methodology builds on prior work using sector hashing and the Jaccard index of similarity. These two methods are combined in a novel manner and the accuracy of the resulting methodology is demonstrated using a collection of hard drive images with known ground truth. The work goes beyond interesting file and file fragment matching. Specifically, it assesses the overall similarity of digital media to identify systems that might share applications and thus be related, even if common files of interest are encrypted, deleted or otherwise unavailable. In addition to triage decisions, digital media similarity may be used to infer links and associations between disparate entities.
Fichier principal
Vignette du fichier
503209_1_En_7_Chapter.pdf (713.15 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-03657240 , version 1 (02-05-2022)

Licence

Attribution

Identifiers

Cite

Myeong Lim, James Jones. A Digital Media Similarity Measure for Triage of Digital Forensic Evidence. 16th IFIP International Conference on Digital Forensics (DigitalForensics), Jan 2020, New Delhi, India. pp.111-135, ⟨10.1007/978-3-030-56223-6_7⟩. ⟨hal-03657240⟩
18 View
16 Download

Altmetric

Share

Gmail Facebook X LinkedIn More