The Experts below are selected from a list of 120 Experts worldwide ranked by ideXlab platform

Brian Neil Levine - One of the best experts on this subject based on the ideXlab platform.

  • Efficient Smart Phone Forensics Based on Relevance Feedback
    2015
    Co-Authors: Saksham Varma, Robert J Walls, Brian Lynn, Brian Neil Levine
    Abstract:

    When Forensic Triage techniques designed for feature phones are applied to smart phones, these recovery techniques return hundreds of thousands of results, only a few of which are relevant to the inves-tigation. We propose the use of relevance feedback to address this problem: a small amount of investigator input can efficiently and accurately rank in order of relevance, the results of a Forensic Triage tool. We present LIFTR, a novel system for prioritizing information recovered from Android phones. We evaluate LIFTR’s ranking al-gorithm on 13 previously owned Android smart phones and three recovery engines — DEC0DE, Bulk Extractor, and Strings — us-ing a standard information retrieval metric, Normalized Discounted Cumulative Gain (NDCG). LIFTR’s initial ranking improves the NDCG scores of the three engines from 0.0 to an average of 0.73; and with as little as 5 rounds of feedback, the ranking score in-creases to 0.88. Our results demonstrate the efficacy of relevance feedback for quickly locating useful information among the large amount of irrelevant data returned by current recovery techniques. Further, our empirical findings show that a significant amount of important user information persists for weeks or even months in the expired space of a phone’s memory. This phenomenon underscores the importance of using file system agnostic recovery techniques, which are the type of techniques that benefit most from LIFTR

  • SPSM@CCS - Efficient Smart Phone Forensics Based on Relevance Feedback
    Proceedings of the 4th ACM Workshop on Security and Privacy in Smartphones & Mobile Devices, 2014
    Co-Authors: Saksham Varma, Robert J Walls, Brian Lynn, Brian Neil Levine
    Abstract:

    When Forensic Triage techniques designed for feature phones are applied to smart phones, these recovery techniques return hundreds of thousands of results, only a few of which are relevant to the investigation. We propose the use of relevance feedback to address this problem: a small amount of investigator input can efficiently and accurately rank in order of relevance, the results of a Forensic Triage tool. We present LIFTR, a novel system for prioritizing information recovered from Android phones. We evaluate LIFTR's ranking algorithm on 13 previously owned Android smart phones and three recovery engines -- DEC0DE, Bulk Extractor, and Strings? using a standard information retrieval metric, Normalized Discounted Cumulative Gain (NDCG). LIFTR's initial ranking improves the NDCG scores of the three engines from 0.0 to an average of 0.73; and with as little as 5 rounds of feedback, the ranking score in- creases to 0.88. Our results demonstrate the efficacy of relevance feedback for quickly locating useful information among the large amount of irrelevant data returned by current recovery techniques. Further, our empirical findings show that a significant amount of important user information persists for weeks or even months in the expired space of a phone's memory. This phenomenon underscores the importance of using file system agnostic recovery techniques, which are the type of techniques that benefit most from LIFTR.

  • Forensic Triage for mobile phones with dec0de
    USENIX Security Symposium, 2011
    Co-Authors: Robert J Walls, Erik Learnedmiller, Brian Neil Levine
    Abstract:

    We present DEC0DE, a system for recovering information from phones with unknown storage formats, a critical problem for Forensic Triage. Because phones have myriad custom hardware and software, we examine only the stored data. Via flexible descriptions of typical data structures, and using a classic dynamic programming algorithm, we are able to identify call logs and address book entries in phones across varied models and manufacturers. We designed DEC0DE by examining the formats of one set of phone models, and we evaluate its performance on other models. Overall, we are able to obtain high performance for these unexamined models: an average recall of 97% and precision of 80% for call logs; and average recall of 93% and precision of 52% for address books. Moreover, at the expense of recall dropping to 14%, we can increase precision of address book recovery to 94% by culling results that don't match between call logs and address book entries on the same phone.

  • USENIX Security Symposium - Forensic Triage for mobile phones with DEC0DE
    2011
    Co-Authors: Robert J Walls, Erik Learned-miller, Brian Neil Levine
    Abstract:

    We present DEC0DE, a system for recovering information from phones with unknown storage formats, a critical problem for Forensic Triage. Because phones have myriad custom hardware and software, we examine only the stored data. Via flexible descriptions of typical data structures, and using a classic dynamic programming algorithm, we are able to identify call logs and address book entries in phones across varied models and manufacturers. We designed DEC0DE by examining the formats of one set of phone models, and we evaluate its performance on other models. Overall, we are able to obtain high performance for these unexamined models: an average recall of 97% and precision of 80% for call logs; and average recall of 93% and precision of 52% for address books. Moreover, at the expense of recall dropping to 14%, we can increase precision of address book recovery to 94% by culling results that don't match between call logs and address book entries on the same phone.

Ibrahim Baggili - One of the best experts on this subject based on the ideXlab platform.

  • Computer Profiling for Preliminary Forensic Examination
    2015
    Co-Authors: Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili
    Abstract:

    The quantity problem and the natural desire of law enforcement to confront suspects with evidence of their guilt close to the time of arrest in order to elicit a confession combine to form a need for both effective digital Forensic Triage and preliminary Forensic examination. This paper discusses computer profiling, a method for automated formal reasoning about a computer system, and its applicability to the problem domain of preliminary digital Forensic examination following Triage. It proposes an algorithm for using computer profiling at the preliminary examination stage of an investigation, which focusses on constructing an information model describing a suspect’s computer system in the minimal level of detail necessary to address a formal hypothesis about the system proposed by an investigator. The paper concludes by discussing the expanded utility of the algorithm proposed when contrasted to existing approaches in the digital Forensic Triage and preliminary examination space.

  • ICDF2C - Computer Profiling for Preliminary Forensic Examination
    Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2014
    Co-Authors: Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili
    Abstract:

    The quantity problem and the natural desire of law enforcement to confront suspects with evidence of their guilt close to the time of arrest in order to elicit a confession combine to form a need for both effective digital Forensic Triage and preliminary Forensic examination. This paper discusses computer profiling, a method for automated formal reasoning about a computer system, and its applicability to the problem domain of preliminary digital Forensic examination following Triage. It proposes an algorithm for using computer profiling at the preliminary examination stage of an investigation, which focusses on constructing an information model describing a suspect’s computer system in the minimal level of detail necessary to address a formal hypothesis about the system proposed by an investigator. The paper concludes by discussing the expanded utility of the algorithm proposed when contrasted to existing approaches in the digital Forensic Triage and preliminary examination space.

  • PERFORMANCE OF A LOGICAL, FIVE-PHASE, MULTITHREADED, BOOTABLE Triage TOOL
    Advances in Digital Forensics X, 2014
    Co-Authors: Ibrahim Baggili, Andrew Marrington, Y Jafar
    Abstract:

    This paper describes a five-phase, multi-threaded bootable approach to digital Forensic Triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the Forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable Forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other Forensic Triage tools.

  • IFIP Int. Conf. Digital Forensics - Performance of a Logical, Five- Phase, Multithreaded, Bootable Triage Tool
    Progress in Pattern Recognition Image Analysis Computer Vision and Applications, 2014
    Co-Authors: Ibrahim Baggili, Andrew Marrington, Y Jafar
    Abstract:

    This paper describes a five-phase, multi-threaded bootable approach to digital Forensic Triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the Forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable Forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other Forensic Triage tools.

Robert J Walls - One of the best experts on this subject based on the ideXlab platform.

  • Efficient Smart Phone Forensics Based on Relevance Feedback
    2015
    Co-Authors: Saksham Varma, Robert J Walls, Brian Lynn, Brian Neil Levine
    Abstract:

    When Forensic Triage techniques designed for feature phones are applied to smart phones, these recovery techniques return hundreds of thousands of results, only a few of which are relevant to the inves-tigation. We propose the use of relevance feedback to address this problem: a small amount of investigator input can efficiently and accurately rank in order of relevance, the results of a Forensic Triage tool. We present LIFTR, a novel system for prioritizing information recovered from Android phones. We evaluate LIFTR’s ranking al-gorithm on 13 previously owned Android smart phones and three recovery engines — DEC0DE, Bulk Extractor, and Strings — us-ing a standard information retrieval metric, Normalized Discounted Cumulative Gain (NDCG). LIFTR’s initial ranking improves the NDCG scores of the three engines from 0.0 to an average of 0.73; and with as little as 5 rounds of feedback, the ranking score in-creases to 0.88. Our results demonstrate the efficacy of relevance feedback for quickly locating useful information among the large amount of irrelevant data returned by current recovery techniques. Further, our empirical findings show that a significant amount of important user information persists for weeks or even months in the expired space of a phone’s memory. This phenomenon underscores the importance of using file system agnostic recovery techniques, which are the type of techniques that benefit most from LIFTR

  • SPSM@CCS - Efficient Smart Phone Forensics Based on Relevance Feedback
    Proceedings of the 4th ACM Workshop on Security and Privacy in Smartphones & Mobile Devices, 2014
    Co-Authors: Saksham Varma, Robert J Walls, Brian Lynn, Brian Neil Levine
    Abstract:

    When Forensic Triage techniques designed for feature phones are applied to smart phones, these recovery techniques return hundreds of thousands of results, only a few of which are relevant to the investigation. We propose the use of relevance feedback to address this problem: a small amount of investigator input can efficiently and accurately rank in order of relevance, the results of a Forensic Triage tool. We present LIFTR, a novel system for prioritizing information recovered from Android phones. We evaluate LIFTR's ranking algorithm on 13 previously owned Android smart phones and three recovery engines -- DEC0DE, Bulk Extractor, and Strings? using a standard information retrieval metric, Normalized Discounted Cumulative Gain (NDCG). LIFTR's initial ranking improves the NDCG scores of the three engines from 0.0 to an average of 0.73; and with as little as 5 rounds of feedback, the ranking score in- creases to 0.88. Our results demonstrate the efficacy of relevance feedback for quickly locating useful information among the large amount of irrelevant data returned by current recovery techniques. Further, our empirical findings show that a significant amount of important user information persists for weeks or even months in the expired space of a phone's memory. This phenomenon underscores the importance of using file system agnostic recovery techniques, which are the type of techniques that benefit most from LIFTR.

  • Forensic Triage for mobile phones with dec0de
    USENIX Security Symposium, 2011
    Co-Authors: Robert J Walls, Erik Learnedmiller, Brian Neil Levine
    Abstract:

    We present DEC0DE, a system for recovering information from phones with unknown storage formats, a critical problem for Forensic Triage. Because phones have myriad custom hardware and software, we examine only the stored data. Via flexible descriptions of typical data structures, and using a classic dynamic programming algorithm, we are able to identify call logs and address book entries in phones across varied models and manufacturers. We designed DEC0DE by examining the formats of one set of phone models, and we evaluate its performance on other models. Overall, we are able to obtain high performance for these unexamined models: an average recall of 97% and precision of 80% for call logs; and average recall of 93% and precision of 52% for address books. Moreover, at the expense of recall dropping to 14%, we can increase precision of address book recovery to 94% by culling results that don't match between call logs and address book entries on the same phone.

  • USENIX Security Symposium - Forensic Triage for mobile phones with DEC0DE
    2011
    Co-Authors: Robert J Walls, Erik Learned-miller, Brian Neil Levine
    Abstract:

    We present DEC0DE, a system for recovering information from phones with unknown storage formats, a critical problem for Forensic Triage. Because phones have myriad custom hardware and software, we examine only the stored data. Via flexible descriptions of typical data structures, and using a classic dynamic programming algorithm, we are able to identify call logs and address book entries in phones across varied models and manufacturers. We designed DEC0DE by examining the formats of one set of phone models, and we evaluate its performance on other models. Overall, we are able to obtain high performance for these unexamined models: an average recall of 97% and precision of 80% for call logs; and average recall of 93% and precision of 52% for address books. Moreover, at the expense of recall dropping to 14%, we can increase precision of address book recovery to 94% by culling results that don't match between call logs and address book entries on the same phone.

Andrew Marrington - One of the best experts on this subject based on the ideXlab platform.

  • Computer Profiling for Preliminary Forensic Examination
    2015
    Co-Authors: Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili
    Abstract:

    The quantity problem and the natural desire of law enforcement to confront suspects with evidence of their guilt close to the time of arrest in order to elicit a confession combine to form a need for both effective digital Forensic Triage and preliminary Forensic examination. This paper discusses computer profiling, a method for automated formal reasoning about a computer system, and its applicability to the problem domain of preliminary digital Forensic examination following Triage. It proposes an algorithm for using computer profiling at the preliminary examination stage of an investigation, which focusses on constructing an information model describing a suspect’s computer system in the minimal level of detail necessary to address a formal hypothesis about the system proposed by an investigator. The paper concludes by discussing the expanded utility of the algorithm proposed when contrasted to existing approaches in the digital Forensic Triage and preliminary examination space.

  • ICDF2C - Computer Profiling for Preliminary Forensic Examination
    Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2014
    Co-Authors: Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili
    Abstract:

    The quantity problem and the natural desire of law enforcement to confront suspects with evidence of their guilt close to the time of arrest in order to elicit a confession combine to form a need for both effective digital Forensic Triage and preliminary Forensic examination. This paper discusses computer profiling, a method for automated formal reasoning about a computer system, and its applicability to the problem domain of preliminary digital Forensic examination following Triage. It proposes an algorithm for using computer profiling at the preliminary examination stage of an investigation, which focusses on constructing an information model describing a suspect’s computer system in the minimal level of detail necessary to address a formal hypothesis about the system proposed by an investigator. The paper concludes by discussing the expanded utility of the algorithm proposed when contrasted to existing approaches in the digital Forensic Triage and preliminary examination space.

  • PERFORMANCE OF A LOGICAL, FIVE-PHASE, MULTITHREADED, BOOTABLE Triage TOOL
    Advances in Digital Forensics X, 2014
    Co-Authors: Ibrahim Baggili, Andrew Marrington, Y Jafar
    Abstract:

    This paper describes a five-phase, multi-threaded bootable approach to digital Forensic Triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the Forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable Forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other Forensic Triage tools.

  • IFIP Int. Conf. Digital Forensics - Performance of a Logical, Five- Phase, Multithreaded, Bootable Triage Tool
    Progress in Pattern Recognition Image Analysis Computer Vision and Applications, 2014
    Co-Authors: Ibrahim Baggili, Andrew Marrington, Y Jafar
    Abstract:

    This paper describes a five-phase, multi-threaded bootable approach to digital Forensic Triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the Forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable Forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other Forensic Triage tools.

Y Jafar - One of the best experts on this subject based on the ideXlab platform.

  • PERFORMANCE OF A LOGICAL, FIVE-PHASE, MULTITHREADED, BOOTABLE Triage TOOL
    Advances in Digital Forensics X, 2014
    Co-Authors: Ibrahim Baggili, Andrew Marrington, Y Jafar
    Abstract:

    This paper describes a five-phase, multi-threaded bootable approach to digital Forensic Triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the Forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable Forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other Forensic Triage tools.

  • IFIP Int. Conf. Digital Forensics - Performance of a Logical, Five- Phase, Multithreaded, Bootable Triage Tool
    Progress in Pattern Recognition Image Analysis Computer Vision and Applications, 2014
    Co-Authors: Ibrahim Baggili, Andrew Marrington, Y Jafar
    Abstract:

    This paper describes a five-phase, multi-threaded bootable approach to digital Forensic Triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the Forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable Forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other Forensic Triage tools.