UniTIME: Timestamp interpretation engine for developing unified timelines

S. Raghavan, H. Saran
{"title":"UniTIME: Timestamp interpretation engine for developing unified timelines","authors":"S. Raghavan, H. Saran","doi":"10.1109/SADFE.2013.6911546","DOIUrl":null,"url":null,"abstract":"A critical part of many computer forensic investigations requires developing a unified timeline of activity from the timestamps of the artifacts involved, often involving digital artifacts from across multiple heterogeneous sources of evidence. However, generating such a timeline comes with its own set of challenges, especially if the provenance of the timestamps is not accurately recorded and tracked during an investigation. When sufficient provenance information is not recorded, it can result in inconsistent or ambiguous timelines. In this paper, we propose the Provenance Information Model to address challenges related to timestamp interpretation across multiple time zones and present a provenance structure to accurately capture time zone information and validate time related assertions during analysis. We have developed a prototype implementation of the model, the UniTIME digital time-lining tool, which generates a unified timeline of events derived from across multiple sources. Our tool adjusts the timestamps obtained from multiple heterogeneous evidence sources using the provenance information to generate a unified timeline. We have validated our model and its prototype implementation using the dataset associated with the DFRWS 2008 challenge which included multiple heterogeneous sources of digital evidence with inherent timestamp interpretation challenges. Results have shown that the model is robust with respect to different time zones and varied timestamp representations. Additionally, the assertions recorded when using our PIM can be useful in identifying inconsistencies across artifacts during forensic analysis and digital time-lining.","PeriodicalId":287131,"journal":{"name":"2013 8th International Workshop on Systematic Approaches to Digital Forensics Engineering (SADFE)","volume":"20 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 8th International Workshop on Systematic Approaches to Digital Forensics Engineering (SADFE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SADFE.2013.6911546","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

A critical part of many computer forensic investigations requires developing a unified timeline of activity from the timestamps of the artifacts involved, often involving digital artifacts from across multiple heterogeneous sources of evidence. However, generating such a timeline comes with its own set of challenges, especially if the provenance of the timestamps is not accurately recorded and tracked during an investigation. When sufficient provenance information is not recorded, it can result in inconsistent or ambiguous timelines. In this paper, we propose the Provenance Information Model to address challenges related to timestamp interpretation across multiple time zones and present a provenance structure to accurately capture time zone information and validate time related assertions during analysis. We have developed a prototype implementation of the model, the UniTIME digital time-lining tool, which generates a unified timeline of events derived from across multiple sources. Our tool adjusts the timestamps obtained from multiple heterogeneous evidence sources using the provenance information to generate a unified timeline. We have validated our model and its prototype implementation using the dataset associated with the DFRWS 2008 challenge which included multiple heterogeneous sources of digital evidence with inherent timestamp interpretation challenges. Results have shown that the model is robust with respect to different time zones and varied timestamp representations. Additionally, the assertions recorded when using our PIM can be useful in identifying inconsistencies across artifacts during forensic analysis and digital time-lining.
UniTIME:时间戳解释引擎,用于开发统一的时间线
许多计算机取证调查的关键部分需要根据所涉及的工件的时间戳开发统一的活动时间轴,通常涉及来自多个异构证据来源的数字工件。然而,生成这样的时间轴有其自身的挑战,特别是在调查期间没有准确记录和跟踪时间戳的来源的情况下。当没有记录足够的来源信息时,可能会导致不一致或不明确的时间表。在本文中,我们提出了出处信息模型来解决与跨多个时区的时间戳解释相关的挑战,并提出了一个出处结构来准确捕获时区信息,并在分析期间验证与时间相关的断言。我们已经开发了该模型的原型实现,即UniTIME数字时间线工具,它可以生成来自多个来源的统一事件时间线。我们的工具使用来源信息调整从多个异构证据来源获得的时间戳,以生成统一的时间轴。我们使用与DFRWS 2008挑战相关的数据集验证了我们的模型及其原型实现,其中包括具有固有时间戳解释挑战的多个异构数字证据来源。结果表明,该模型对不同时区和不同时间戳表示具有鲁棒性。此外,在使用我们的PIM时记录的断言对于在取证分析和数字时间排序期间识别工件之间的不一致性非常有用。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信