The Experts below are selected from a list of 150858 Experts worldwide ranked by ideXlab platform

Kimkwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.

  • data reduction and data mining framework for digital forensic evidence storage Intelligence review and archive
    Trends and issues in crime and criminal justice, 2014
    Co-Authors: Darren Quick, Kimkwang Raymond Choo
    Abstract:

    With the volume of digital forensic evidence rapidly increasing, this paper proposes a data reduction and data mining framework that incorporates a process of reducing data volume by focusing on a subset of information. Foreword The volume of digital forensic evidence is rapidly increasing, leading to large backlogs. In this paper, a Digital Forensic Data Reduction and Data Mining Framework is proposed. Initial research with sample data from South Australia Police Electronic Crime Section and Digital Corpora Forensic Images using the proposed framework resulted in significant reduction in the storage requirements—the reduced subset is only 0.196 percent and 0.75 percent respectively of the original data volume. The framework outlined is not suggested to replace full Analysis, but serves to provide a rapid triage, collection, Intelligence Analysis, review and storage methodology to support the various stages of digital forensic examinations. Agencies that can undertake rapid assessment of seized data can more effectively target specific criminal matters. The framework may also provide a greater potential Intelligence gain from Analysis of current and historical data in a timely manner, and the ability to undertake research of trends over time.

  • data reduction and data mining framework for digital forensic evidence storage Intelligence review and archive
    Trends and issues in crime and criminal justice, 2014
    Co-Authors: Darren Quick, Kimkwang Raymond Choo
    Abstract:

    The volume of digital forensic evidence is rapidly increasing, leading to large backlogs. In this paper, a Digital Forensic Data Reduction and Data Mining Framework is proposed. Initial research with sample data from South Australia Police Electronic Crime Section and Digital Corpora Forensic Images using the proposed framework resulted in significant reduction in the storage requirements — the reduced subset is only 0.196 percent and 0.75 percent respectively of the original data volume. The framework outlined is not suggested to replace full Analysis, but serves to provide a rapid triage, collection, Intelligence Analysis, review and storage methodology to support the various stages of digital forensic examinations. Agencies that can undertake rapid assessment of seized data can more effectively target specific criminal matters. The framework may also provide a greater potential Intelligence gain from Analysis of current and historical data in a timely manner, and the ability to undertake research of trends over time.

Darren Quick - One of the best experts on this subject based on the ideXlab platform.

  • data reduction and data mining framework for digital forensic evidence storage Intelligence review and archive
    Trends and issues in crime and criminal justice, 2014
    Co-Authors: Darren Quick, Kimkwang Raymond Choo
    Abstract:

    With the volume of digital forensic evidence rapidly increasing, this paper proposes a data reduction and data mining framework that incorporates a process of reducing data volume by focusing on a subset of information. Foreword The volume of digital forensic evidence is rapidly increasing, leading to large backlogs. In this paper, a Digital Forensic Data Reduction and Data Mining Framework is proposed. Initial research with sample data from South Australia Police Electronic Crime Section and Digital Corpora Forensic Images using the proposed framework resulted in significant reduction in the storage requirements—the reduced subset is only 0.196 percent and 0.75 percent respectively of the original data volume. The framework outlined is not suggested to replace full Analysis, but serves to provide a rapid triage, collection, Intelligence Analysis, review and storage methodology to support the various stages of digital forensic examinations. Agencies that can undertake rapid assessment of seized data can more effectively target specific criminal matters. The framework may also provide a greater potential Intelligence gain from Analysis of current and historical data in a timely manner, and the ability to undertake research of trends over time.

  • data reduction and data mining framework for digital forensic evidence storage Intelligence review and archive
    Trends and issues in crime and criminal justice, 2014
    Co-Authors: Darren Quick, Kimkwang Raymond Choo
    Abstract:

    The volume of digital forensic evidence is rapidly increasing, leading to large backlogs. In this paper, a Digital Forensic Data Reduction and Data Mining Framework is proposed. Initial research with sample data from South Australia Police Electronic Crime Section and Digital Corpora Forensic Images using the proposed framework resulted in significant reduction in the storage requirements — the reduced subset is only 0.196 percent and 0.75 percent respectively of the original data volume. The framework outlined is not suggested to replace full Analysis, but serves to provide a rapid triage, collection, Intelligence Analysis, review and storage methodology to support the various stages of digital forensic examinations. Agencies that can undertake rapid assessment of seized data can more effectively target specific criminal matters. The framework may also provide a greater potential Intelligence gain from Analysis of current and historical data in a timely manner, and the ability to undertake research of trends over time.

Fabio Martinelli - One of the best experts on this subject based on the ideXlab platform.

  • a scheme for the sticky policy representation supporting secure cyber threat Intelligence Analysis and sharing
    International Conference on Supercomputing, 2019
    Co-Authors: Oleksii Osliak, Andrea Saracino, Fabio Martinelli
    Abstract:

    This paper aims to propose a structured threat information expression (STIX)-based data representation for privacy-preserving data Analysis to report format and semantics of specific data types and to represent sticky policies in the format of embedded human-readable data sharing agreements (DSAs). More specifically, the authors exploit and extend the STIX standard to represent in a structured way Analysis-ready pieces of data and the attached privacy policies.,The whole scheme is designed to be completely compatible with the STIX 2.0 standard for cyber-threat Intelligence (CTI) representation. The proposed scheme will be implemented in this work by defining the complete scheme for representing an email, which is more expressive than the standard one defined for STIX, designed specifically for spam email Analysis.,Moreover, the paper provides a new scheme for general DSA representation that has been practically applied for the process of encoding specific attributes in different CTI reports.,Because of the chosen approach, the research results may have limitations. Specifically, current practice for entity recognition has the limitation that was discovered during the research. However, its effect on process time was minimized and the way for improvement was proposed.,This paper has covered the existing gap including the lack of generality in DSA representation for privacy-preserving Analysis of structured CTI. Therefore, the new model for DSA representation was introduced, as well as its practical implementation.

Malcolm K Sparrow - One of the best experts on this subject based on the ideXlab platform.

  • the application of network Analysis to criminal Intelligence an assessment of the prospects
    Social Networks, 1991
    Co-Authors: Malcolm K Sparrow
    Abstract:

    Abstract This paper explores the opportunities for the application of network analytic techniques to the problems of criminal Intelligence Analysis, paying particular attention to the identification of vulnerabilities in different types of criminal organization — from terrorist groups to narcotics supply networks. A variety of concepts from the network Analysis literature are considered in terms of the promise they hold for helping law enforcement agencies extract useful information from existing collections of link data. For example, six different notions of “centrality” and the three major notions of “equivalence” are examined for their relevance in revealing the mechanics and vulnerabilities of criminal enterprises.

John T Stasko - One of the best experts on this subject based on the ideXlab platform.

  • characterizing the Intelligence Analysis process through a longitudinal field study implications for visual analytics
    Information Visualization, 2014
    Co-Authors: Younah Kang, John T Stasko
    Abstract:

    While Intelligence Analysis has been a primary target domain for visual analytics system development, relatively little user and task Analysis has been conducted within this area. Our research community’s understanding of the work processes and practices of Intelligence analysts is not deep enough to adequately address their needs. Without a better understanding of the analysts and their problems, we cannot build visual analytics systems that integrate well with their work processes and truly provide benefit to them. In order to close this knowledge gap, we conducted a longitudinal, observational field study of Intelligence analysts in training within the Intelligence program at Mercyhurst College. We observed three teams of analysts, each working on an Intelligence problem for a 10-week period. Based on the findings of the study, we describe and characterize processes and methods of Intelligence Analysis that we observed, make clarifications regarding the processes and practices, and suggest design impli...