Affiliation:
1. Department of Computer Science, Friedrich-Alexander-Universität Erlangen-Nürnberg (FAU), Germany
Abstract
Digital investigations are largely concerned with reconstructing past events based on traces in digital systems. Given their importance, many concepts have been established to describe their quality—most of them concerned with procedural aspects, i.e., authenticity and integrity, for example. Besides that, there exist principal concepts that have been overlooked in the past: Two of those criteria are
relevance
and
expressiveness
of digital evidence. Unlike others, those are directly concerned with reaching the investigative goal. Therefore, we approach these two overlooked concepts of digital evidence by giving formal definitions. To illustrate the usefulness, we present two applications: First, we demonstrate that the notions of expressiveness and completeness can be used to guide investigations by presenting the
Facet-oriented Criminalistic Cycle
as a thinking model, which extends the well-established criminalistic cycle. Second, we put the concepts into practice by calculating the expressiveness of facets from a state machine representation of a digital system utilizing temporal logic and a model checker. Furthermore, we sketch out the implications of this improved way of defining relevance and expressiveness. Accordingly, this article aims to improve the understanding of these critical aspects of the overall investigative process.
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Networks and Communications,Computer Science Applications,Hardware and Architecture,Safety Research,Information Systems,Software
Reference37 articles.
1. Criminalistics is reasoning backwards;Berger Charles;Nederl. Jurist.,2010
2. Argumentation and Evidence
3. Categories of digital investigation analysis techniques based on the computer history model
4. NuSMV 2: An OpenSource Tool for Symbolic Model Checking
5. Characteristic evidence, counter evidence and reconstruction problems in forensic computing;Dewald Andreas;it Inf. Technol.,2015
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献