首页> 外文会议>International Conference on Information Resources Management >Using Visual Capabilities to Improve Efficiency in Computer Forensic Analysis
【24h】

Using Visual Capabilities to Improve Efficiency in Computer Forensic Analysis

机译:使用视觉功能提高计算机法医分析效率

获取原文

摘要

Computer forensics is the preservation, analysis, and interpretation of computer data. Computer forensics is dependent on the availability of software tools and applications. Such tools are critical components in law enforcement investigations. Due to the diversity of cyber crime and cyber assisted crime, advanced software tools are essential apparatus for typical law enforcement investigators, national security analysts, corporate emergency response teams, civil lawyers, risk management personnel, etc. Typical tools available to investigators are text-based, which are sorely inadequate given the volume of data needing analysis in today's environment. Many modem tools essentially provide simple GUIs to simplify access to typical text-based commands but the capabilities are essentially the same. For simplicity we continue to refer to these as text-based and command-based in contrast to the visualization tools and associated direct manipulation interfaces we are attempting to develop. The reading of such large volumes of textual information is extremely time-consuming in contrast with the interpretation of images through which the user can interpret large amounts of information simultaneously. Forensic analysts have a growing need for new capabilities to aid in locating files holding evidence of criminal activity. Such capabilities must improve both the efficiency of the analysis process and the identification of additionally hidden files. This paper discusses visualization research that more perceptually and intuitively represents file characteristics. Additionally, we integrate interaction capabilities for more complete exploration, significantly improving analysis efficiency. Finally, we discuss the results of an applied user study designed specifically to measure the efficacy of the developed visualization capabilities in the analysis of computer forensic related data.
机译:计算机取证是计算机数据的保存,分析和解释。计算机取证依赖于软件工具和应用程序的可用性。这些工具是执法调查中的关键组成部分。由于网络犯罪和网络辅助犯罪的多样性,先进的软件工具是典型执法调查员,国家安全分析师,企业应急响应团队,民事律师,风险管理人员等的必备仪器。调查人员可用的典型工具是文本 - 鉴于当今环境中需要分析的数据量,基于非常不足。许多调制解调器工具基本上提供了简单的GUI,以简化对基于文本的命令的访问,但功能基本相同。为简单起见,我们继续将这些作为基于文本和命令的命令,与您试图开发的可视化工具和相关的直接操纵接口对比。与通过用户通过该图像的解释同时解释大量信息的图像的解释相比,读取这种大量的文本信息的读取非常耗时。法医分析师越来越需要新的能力,以帮助持有犯罪活动证据的文件。此类功能必须提高分析过程的效率和另外隐藏文件的识别。本文讨论了可视化研究,更感知和直观地代表文件特征。此外,我们还集成了更完整的探索的交互能力,显着提高了分析效率。最后,我们讨论了专门设计的应用用户学习的结果,用于测量显影性能能力在计算机法医相关数据分析中的效果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号