The use of self-organising maps for anomalous behaviour detection in a digital investigation.

نویسندگان

  • B K L Fei
  • J H P Eloff
  • M S Olivier
  • H S Venter
چکیده

The dramatic increase in crime relating to the Internet and computers has caused a growing need for digital forensics. Digital forensic tools have been developed to assist investigators in conducting a proper investigation into digital crimes. In general, the bulk of the digital forensic tools available on the market permit investigators to analyse data that has been gathered from a computer system. However, current state-of-the-art digital forensic tools simply cannot handle large volumes of data in an efficient manner. With the advent of the Internet, many employees have been given access to new and more interesting possibilities via their desktop. Consequently, excessive Internet usage for non-job purposes and even blatant misuse of the Internet have become a problem in many organisations. Since storage media are steadily growing in size, the process of analysing multiple computer systems during a digital investigation can easily consume an enormous amount of time. Identifying a single suspicious computer from a set of candidates can therefore reduce human processing time and monetary costs involved in gathering evidence. The focus of this paper is to demonstrate how, in a digital investigation, digital forensic tools and the self-organising map (SOM)--an unsupervised neural network model--can aid investigators to determine anomalous behaviours (or activities) among employees (or computer systems) in a far more efficient manner. By analysing the different SOMs (one for each computer system), anomalous behaviours are identified and investigators are assisted to conduct the analysis more efficiently. The paper will demonstrate how the easy visualisation of the SOM enhances the ability of the investigators to interpret and explore the data generated by digital forensic tools so as to determine anomalous behaviours.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Using Self-organising Maps for Anomalous Behaviour Detection in a Computer Forensic Investigation

The dramatic increase in crime relating to the Internet and computers has caused a growing need for computer forensics. Computer forensic tools have been developed to assist computer forensic investigators in conducting a proper investigation into digital crimes. In general, the bulk of the computer forensic tools available on the market permit investigators to analyse data that has been gather...

متن کامل

Land use changes detection and spatial distribution using digital and satellite data, case study: Farim drainage basin, Northern of Iran

Land use change may influence many natural phenomena and ecological processes, including runoff, soil erosion, sedimentation and soil conditions. Decreasing of forest area in the North of Iran is one of the critical problems in recent years. The aims of this study are to detect land use changes between 1967 to 2002 using satellite images of Land Sat 7 ETM+ (2002), aerial photos and digital topo...

متن کامل

Computer Network User Behaviour Visualisation Using Self Organising Maps

Computer systems are vulnerable to abuse by insiders and to penetration by outsiders. The amount of monitoring data generated in computer networks is enormous. Tools are needed to ease the work of system operators. Anomaly detection attempts to recognise abnormal behaviour to detect intrusions. A prototype Anomaly Detection System has been constructed. The system provides means for automatic an...

متن کامل

Effect of digital elevation model’s resolution in producing flood hazard maps

Flooding is one of the most devastating natural disasters occurring annually in the Philippines. A call for a solution for this malady is very challenging as well as crucial to be addressed. Mapping flood hazard is an effective tool in determining the extent and depth of floods associated with hazard level in specified areas that need to be prioritized during flood occurrences. Precedent to the...

متن کامل

An Investigation into Digital Library Users' Collaborative Information Seeking (CIS) of Graduate Students of Kharazmi University with an emphasis on two easy and difficult scenarios

Background and Aim: Understanding collaborative information seeking behaviour requires knowing about personal characteristics, differences between users, and the type of interactions occur during a collaborative behaviour. The aim of this study is to investigate dimensions of collaborative information seeking behaviour of graduate students of Kharazmi University when using a digital library bas...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Forensic science international

دوره 162 1-3  شماره 

صفحات  -

تاریخ انتشار 2006