主管:中华人民共和国司法部
主办:司法鉴定科学研究院
ISSN 1671-2072  CN 31-1863/N

Chinese Journal of Forensic Sciences ›› 2012 ›› Issue (5): 50-58.

Previous Articles     Next Articles

Integration of User-system View for Cyber Crime Analysis: A Semi-automatic Approach

K.P. Chow1, Erica S.L. Ho1, Lucas C.K. Hui1, etc.   

  1. 1. Department of Computer Science, The University of Hong Kong, Hong Kong 999077, China; 2. Institute of High Energy, Chinese Academy of Science, Beijing 100039, China; 3. Hubei University of Policy, Wuhan 430034, China
  • Received:2012-06-14 Published:2012-09-15 Online:2022-07-25
  • About author:K.P. Chow(1960—),male,associate professor, Chairman of the Information Security and Forensics Society(ISFS), Hong Kong; council member of the Hong Kong Forensics Science Soci-ety. Research field:computer forensics and infommation security. E-mail: chow@cs.hku.hk.


Abstract: There is a rapid rise in cybercrime cases. There does not exist any effective forensic methods to deal with these cybercrime cases. Investigators are required to study the details of a large amount of tedious source in order to understand the crime model and dig out the evidence. This requires a lot of effort and may result in human errors.  In order to overcome these potential errors that may cause by the investigators, we propose a semi-automatic approach that integrates the user view (based on a high level study of the forensic investigator) and the system view (based on the automatic analysis of the source codes) to assist investigators in refining the scope of the investigation. The approach has been verified using a real cybercrime case and the method has been shown to be effective in assisting the investigators in refining the scope of investigation and understanding the crime model.  The semi-automatic approach has improved the efficiency and reliability of the digital forensic analysis of cybercrime cases involving large volume of digital evidence from multiple sources.

摘要:


CLC Number: