原文传递 Digital Forensics Event Graph Reconstruction.
题名: Digital Forensics Event Graph Reconstruction.
作者: Schelkoph, D. J.
关键词: Web browsers, Operating systems, Computer programming, Computational forensics, Relational databases, Computer program reliability, Computer program documentation, Artificial neural networks, Machine learning, Ontologies, Expert systems, Graphs, Graph databases, Labeled property graphs, Event abstraction
摘要: Ontological data representation and data. normalization can provide a structured way to correlate digital artifacts. This can reduce the amount of data that a forensics examiner needs to process in order to understand the sequence of events that happened on the system. However, ontology processing suffers from large disk consumption and a high computational cost. This paper presents Property Graph Event Reconstruction (PGER), a novel data normalization and event correlation system that leverages a native graph database to improve the speed of queries common in ontological data. PGER reduces the processing time of event correlation grammars and maintains accuracy over a relational database storage format.
报告类型: 科技报告
检索历史
应用推荐