Header menu link for other important links
X
Digital evidence composition in fraud detection
Serugudi V. Raghavan
Published in
2010
Volume: 31 LNICST
   
Pages: 1 - 8
Abstract
In recent times, digital evidence has found its way into several digital devices. The storage capacity in these devices is also growing exponentially. When investigators come across such devices during a digital investigation, it may take several man-hours to completely analyze the contents. To date, there has been little achieved in the zone that attempts to bring together different evidence sources and attempt to correlate the events they record. In this paper, we present an evidence composition model based on the time of occurrence of such events. The time interval between events promises to reveal many key associations across events, especially when on multiple sources. The time interval is then used as a parameter to a correlation function which determines quantitatively the extent of correlation between the events. The approach has been demonstrated on a network capture sequence involving phishing of a bank website. The model is scalable to an arbitrary set of evidence sources and preliminary results indicate that the approach has tremendous potential in determining correlations on vast repositories of case data. © Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering 2010.
About the journal
JournalLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering
ISSN18678211
Open AccessNo
Concepts (17)
  •  related image
    COMPOSITION MODEL
  •  related image
    Correlation function
  •  related image
    DIGITAL EVIDENCE
  •  related image
    DIGITAL INVESTIGATION
  •  related image
    EVENT
  •  related image
    EVIDENCE SOURCE
  •  related image
    Fraud detection
  •  related image
    Multiple source
  •  related image
    NETWORK CAPTURE
  •  related image
    Phishing
  •  related image
    PROBABILITY FUNCTION
  •  related image
    Storage capacity
  •  related image
    Time interval
  •  related image
    CRIME
  •  related image
    Digital devices
  •  related image
    ELECTRONIC CRIME COUNTERMEASURES
  •  related image
    Computer crime