Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling

Since it exist a huge backlog of cases and few digital forensic specialists in the Justice System, usually there is not possible to move them to contribute directly into the digital crime scene. On the other side, the law enforcement has a lack of skilled forensic staff available to perform forensic...

Descripción completa

Guardado en:
Detalles Bibliográficos
Autor principal: Gómez, Leopoldo Sebastián M.
Formato: Objeto de conferencia
Lenguaje:Inglés
Publicado: 2012
Materias:
Acceso en línea:http://sedici.unlp.edu.ar/handle/10915/124455
https://41jaiio.sadio.org.ar/sites/default/files/17_SID_2012.pdf
Aporte de:
id I19-R120-10915-124455
record_format dspace
institution Universidad Nacional de La Plata
institution_str I-19
repository_str R-120
collection SEDICI (UNLP)
language Inglés
topic Ciencias Informáticas
Triage
Digital profiling
Prioritization
Case backlog reduction
spellingShingle Ciencias Informáticas
Triage
Digital profiling
Prioritization
Case backlog reduction
Gómez, Leopoldo Sebastián M.
Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling
topic_facet Ciencias Informáticas
Triage
Digital profiling
Prioritization
Case backlog reduction
description Since it exist a huge backlog of cases and few digital forensic specialists in the Justice System, usually there is not possible to move them to contribute directly into the digital crime scene. On the other side, the law enforcement has a lack of skilled forensic staff available to perform forensic triage. Moreover, the reviews on the fly are taking significant time delays, under pressure, technical restrictions and time framed. At this point, when a suspect target system and data are found, it leads to be seized and moved to a dedicated forensic laboratory where the expert can perform the analysis of their content. Under some circumstances, all that may be required is to quickly and efficiently review a number of target systems to establish if they are likely to contain material of interest to an investigation. However, when the digital evidence comes to the specialist, he has a little knowledge of the previous stage, and it is difficult to make decisions about the priorities or activities on the sized devices. Such reviews are often referred to as "forensic triage" reviews and must be performed using forensically acceptable methods in order that any evidence that is identified during the forensic triage process is not damaged, modified or contaminated, literally or from a legal perspective, by the process of acquiring and reviewing the evidence. We have developed a novel triage tool, which tries to catch a criminal profile with an automated predictive classifier focused on child pornography and intellectual property theft. This software detects few critical attributes into the digital evidence and they are compared with other vectors of characteristics extracted from a digital data corpus based on devices of past cases. As a result of this automated process, a criminal profile prediction is done. This tool will assist to computer forensic experts, in order to make decisions about priorities to make full analysis of suspect devices or discard them with low probabilities of losing digital evidence. Our approach should be useful to mitigate the backlog of computer forensics laboratories.
format Objeto de conferencia
Objeto de conferencia
author Gómez, Leopoldo Sebastián M.
author_facet Gómez, Leopoldo Sebastián M.
author_sort Gómez, Leopoldo Sebastián M.
title Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling
title_short Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling
title_full Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling
title_fullStr Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling
title_full_unstemmed Triage in-Lab : Case Backlog Reduction with Forensic Digital Profiling
title_sort triage in-lab : case backlog reduction with forensic digital profiling
publishDate 2012
url http://sedici.unlp.edu.ar/handle/10915/124455
https://41jaiio.sadio.org.ar/sites/default/files/17_SID_2012.pdf
work_keys_str_mv AT gomezleopoldosebastianm triageinlabcasebacklogreductionwithforensicdigitalprofiling
bdutipo_str Repositorios
_version_ 1764820450404204544