The Experts below are selected from a list of 87 Experts worldwide ranked by ideXlab platform
Timothy R. Leschke - One of the best experts on this subject based on the ideXlab platform.
-
VizSEC - Change-link 2.0: a Digital Forensic Tool for visualizing changes to shadow volume data
Proceedings of the Tenth Workshop on Visualization for Cyber Security - VizSec '13, 2013Co-Authors: Timothy R. Leschke, Charles NicholasAbstract:We present Change Link 2.0, a coordinated and multiple view Tool for Digital Forensics which supports an understanding of how shadow volume data have changed over time. An improvement over the original Change-Link Tool [25], Change-Link 2.0 provides an overview, a directory-tree view, a directory content view, and a metadata view in a side-by-side, split-screen, linked-view interface that supports easy browsing and detection of files and directories that have changed over time. This data visualization approach supports faster comprehension of Digital Forensic data, quick detection of anomalous data, and a better understanding of "what happened?." Input to Change-Link 2.0 is an evidentiary hard drive containing multiple versions of files and directories which have been archived by the Microsoft Volume Shadow Copy Service [28]. Our contributions include data visualization techniques that support an overview of the entire dataset, as well as an understanding of how the directory-tree structure, individual directory content, and file and directory metadata have changed over time. Change-Link 2.0, and its predecessor, are the first data visualization Tools that we are aware of which support the Forensic examination of shadow volume data.
-
change link 2 0 a Digital Forensic Tool for visualizing changes to shadow volume data
Visualization for Computer Security, 2013Co-Authors: Timothy R. Leschke, Charles NicholasAbstract:We present Change Link 2.0, a coordinated and multiple view Tool for Digital Forensics which supports an understanding of how shadow volume data have changed over time. An improvement over the original Change-Link Tool [25], Change-Link 2.0 provides an overview, a directory-tree view, a directory content view, and a metadata view in a side-by-side, split-screen, linked-view interface that supports easy browsing and detection of files and directories that have changed over time. This data visualization approach supports faster comprehension of Digital Forensic data, quick detection of anomalous data, and a better understanding of "what happened?." Input to Change-Link 2.0 is an evidentiary hard drive containing multiple versions of files and directories which have been archived by the Microsoft Volume Shadow Copy Service [28]. Our contributions include data visualization techniques that support an overview of the entire dataset, as well as an understanding of how the directory-tree structure, individual directory content, and file and directory metadata have changed over time. Change-Link 2.0, and its predecessor, are the first data visualization Tools that we are aware of which support the Forensic examination of shadow volume data.
-
VizSEC - Change-Link: a Digital Forensic Tool for visualizing changes to directory trees
Proceedings of the Ninth International Symposium on Visualization for Cyber Security - VizSec '12, 2012Co-Authors: Timothy R. Leschke, Alan T. ShermanAbstract:We present Change-Link, a customizable data exploration Tool which empowers the user to see visual representations of directories that have changed over time within a computer operating system that supports the Microsoft Volume Shadow Copy Service (VSS). Change-Link displays change information in a split-screen interface comprising an overview of directory change for the entire dataset and a detail view of change for individual directories. Input to Change-Link is an evidence hard drive containing an active file system and previous versions of the directory structure that were archived by the VSS. This approach to browsing change within a directory structure helps a Digital Forensic examiner understand how a particular computer was used to support criminal activity. Because data that have changed are often the most important, identifying directories that have changed over time directs attention towards data of higher importance. By examining the most important data, Digital Forensic examiners are better able to keep pace with the data explosion that is making current Digital Forensic examinations unmanageable. Our contributions include the development of a segmented box and whisker glyph for representing change over time for individual directories, an approach for aggregating VSS data for Digital Forensic examinations, and a data visualization Tool for exploring Digital Forensic data.
-
change link a Digital Forensic Tool for visualizing changes to directory trees
Visualization for Computer Security, 2012Co-Authors: Timothy R. Leschke, Alan T. ShermanAbstract:We present Change-Link, a customizable data exploration Tool which empowers the user to see visual representations of directories that have changed over time within a computer operating system that supports the Microsoft Volume Shadow Copy Service (VSS). Change-Link displays change information in a split-screen interface comprising an overview of directory change for the entire dataset and a detail view of change for individual directories. Input to Change-Link is an evidence hard drive containing an active file system and previous versions of the directory structure that were archived by the VSS. This approach to browsing change within a directory structure helps a Digital Forensic examiner understand how a particular computer was used to support criminal activity. Because data that have changed are often the most important, identifying directories that have changed over time directs attention towards data of higher importance. By examining the most important data, Digital Forensic examiners are better able to keep pace with the data explosion that is making current Digital Forensic examinations unmanageable. Our contributions include the development of a segmented box and whisker glyph for representing change over time for individual directories, an approach for aggregating VSS data for Digital Forensic examinations, and a data visualization Tool for exploring Digital Forensic data.
Charles Nicholas - One of the best experts on this subject based on the ideXlab platform.
-
VizSEC - Change-link 2.0: a Digital Forensic Tool for visualizing changes to shadow volume data
Proceedings of the Tenth Workshop on Visualization for Cyber Security - VizSec '13, 2013Co-Authors: Timothy R. Leschke, Charles NicholasAbstract:We present Change Link 2.0, a coordinated and multiple view Tool for Digital Forensics which supports an understanding of how shadow volume data have changed over time. An improvement over the original Change-Link Tool [25], Change-Link 2.0 provides an overview, a directory-tree view, a directory content view, and a metadata view in a side-by-side, split-screen, linked-view interface that supports easy browsing and detection of files and directories that have changed over time. This data visualization approach supports faster comprehension of Digital Forensic data, quick detection of anomalous data, and a better understanding of "what happened?." Input to Change-Link 2.0 is an evidentiary hard drive containing multiple versions of files and directories which have been archived by the Microsoft Volume Shadow Copy Service [28]. Our contributions include data visualization techniques that support an overview of the entire dataset, as well as an understanding of how the directory-tree structure, individual directory content, and file and directory metadata have changed over time. Change-Link 2.0, and its predecessor, are the first data visualization Tools that we are aware of which support the Forensic examination of shadow volume data.
-
change link 2 0 a Digital Forensic Tool for visualizing changes to shadow volume data
Visualization for Computer Security, 2013Co-Authors: Timothy R. Leschke, Charles NicholasAbstract:We present Change Link 2.0, a coordinated and multiple view Tool for Digital Forensics which supports an understanding of how shadow volume data have changed over time. An improvement over the original Change-Link Tool [25], Change-Link 2.0 provides an overview, a directory-tree view, a directory content view, and a metadata view in a side-by-side, split-screen, linked-view interface that supports easy browsing and detection of files and directories that have changed over time. This data visualization approach supports faster comprehension of Digital Forensic data, quick detection of anomalous data, and a better understanding of "what happened?." Input to Change-Link 2.0 is an evidentiary hard drive containing multiple versions of files and directories which have been archived by the Microsoft Volume Shadow Copy Service [28]. Our contributions include data visualization techniques that support an overview of the entire dataset, as well as an understanding of how the directory-tree structure, individual directory content, and file and directory metadata have changed over time. Change-Link 2.0, and its predecessor, are the first data visualization Tools that we are aware of which support the Forensic examination of shadow volume data.
Edi Abdurachman - One of the best experts on this subject based on the ideXlab platform.
-
ICCSCI - A review of collisions in cryptographic hash function used in Digital Forensic Tools
Procedia Computer Science, 2017Co-Authors: Zulfany Erlisa Rasjid, Gunawan Witjaksono, Benfano Soewito, Edi AbdurachmanAbstract:Abstract Digital Forensic Tool is a software used by Digital evidence investigators to extract data and information from a Digital evidence. The integrity of the Digital evidence must be maintained through the chain of custody in order to be admissible in court. Most Digital extraction Tool use either MD5 (Message Digest) or SHA (Secured Hash Algorithm) hashing to check the integrity of Digital evidence. The hashing algorithm has been found to have a weakness known as collision in which two different messages have the same hashing values. Although the probability of producing such weakness is very small, this collision can be used to deny the usage of the evidence in court of justice. After the first collision has been found, many cryptanalysts have tried to explore various methods to detect the collisions with shorter and efficient time. This paper is to review the existing methods in Digital Forensic Tools that have been used to create a collision attacks in Digital evidence.
-
a review of collisions in cryptographic hash function used in Digital Forensic Tools
Procedia Computer Science, 2017Co-Authors: Zulfany Erlisa Rasjid, Gunawan Witjaksono, Benfano Soewito, Edi AbdurachmanAbstract:Abstract Digital Forensic Tool is a software used by Digital evidence investigators to extract data and information from a Digital evidence. The integrity of the Digital evidence must be maintained through the chain of custody in order to be admissible in court. Most Digital extraction Tool use either MD5 (Message Digest) or SHA (Secured Hash Algorithm) hashing to check the integrity of Digital evidence. The hashing algorithm has been found to have a weakness known as collision in which two different messages have the same hashing values. Although the probability of producing such weakness is very small, this collision can be used to deny the usage of the evidence in court of justice. After the first collision has been found, many cryptanalysts have tried to explore various methods to detect the collisions with shorter and efficient time. This paper is to review the existing methods in Digital Forensic Tools that have been used to create a collision attacks in Digital evidence.
Jill Slay - One of the best experts on this subject based on the ideXlab platform.
-
Extracting Evidence Related to VoIP Calls
2011Co-Authors: David Irwin, Jill SlayAbstract:The Voice over Internet Protocol (VoIP) is designed for voice communications over IP networks. To use a VoIP service, an individual only needs a user name for identification. In comparison, the public switched telephone network requires detailed information from a user before creating an account. The limited identity information requirement makes VoIP calls appealing to criminals. In addition, due to VoIP call encryption, conventional eavesdropping and wiretapping methods are ineffective. Forensic investigators thus require alternative methods for recovering evidence related to VoIP calls. This paper describes a Digital Forensic Tool that extracts and analyzes VoIP packets from computers used to make VoIP calls.
-
IFIP Int. Conf. Digital Forensics - Extracting Evidence Related to VoIP Calls
Advances in Digital Forensics VII, 2011Co-Authors: David Irwin, Jill SlayAbstract:The Voice over Internet Protocol (VoIP) is designed for voice communications over IP networks. To use a VoIP service, an individual only needs a user name for identification. In comparison, the public switched telephone network requires detailed information from a user before creating an account. The limited identity information requirement makes VoIP calls appealing to criminals. In addition, due to VoIP call encryption, conventional eavesdropping and wiretapping methods are ineffective. Forensic investigators thus require alternative methods for recovering evidence related to VoIP calls. This paper describes a Digital Forensic Tool that extracts and analyzes VoIP packets from computers used to make VoIP calls.
Zulfany Erlisa Rasjid - One of the best experts on this subject based on the ideXlab platform.
-
ICCSCI - A review of collisions in cryptographic hash function used in Digital Forensic Tools
Procedia Computer Science, 2017Co-Authors: Zulfany Erlisa Rasjid, Gunawan Witjaksono, Benfano Soewito, Edi AbdurachmanAbstract:Abstract Digital Forensic Tool is a software used by Digital evidence investigators to extract data and information from a Digital evidence. The integrity of the Digital evidence must be maintained through the chain of custody in order to be admissible in court. Most Digital extraction Tool use either MD5 (Message Digest) or SHA (Secured Hash Algorithm) hashing to check the integrity of Digital evidence. The hashing algorithm has been found to have a weakness known as collision in which two different messages have the same hashing values. Although the probability of producing such weakness is very small, this collision can be used to deny the usage of the evidence in court of justice. After the first collision has been found, many cryptanalysts have tried to explore various methods to detect the collisions with shorter and efficient time. This paper is to review the existing methods in Digital Forensic Tools that have been used to create a collision attacks in Digital evidence.
-
a review of collisions in cryptographic hash function used in Digital Forensic Tools
Procedia Computer Science, 2017Co-Authors: Zulfany Erlisa Rasjid, Gunawan Witjaksono, Benfano Soewito, Edi AbdurachmanAbstract:Abstract Digital Forensic Tool is a software used by Digital evidence investigators to extract data and information from a Digital evidence. The integrity of the Digital evidence must be maintained through the chain of custody in order to be admissible in court. Most Digital extraction Tool use either MD5 (Message Digest) or SHA (Secured Hash Algorithm) hashing to check the integrity of Digital evidence. The hashing algorithm has been found to have a weakness known as collision in which two different messages have the same hashing values. Although the probability of producing such weakness is very small, this collision can be used to deny the usage of the evidence in court of justice. After the first collision has been found, many cryptanalysts have tried to explore various methods to detect the collisions with shorter and efficient time. This paper is to review the existing methods in Digital Forensic Tools that have been used to create a collision attacks in Digital evidence.