Exploratory Analysis of File System Metadata for Rapid Investigation of Security Incidents

09/03/2020
by   Michal Beran, et al.
0

Investigating cybersecurity incidents requires in-depth knowledge from the analyst. Moreover, the whole process is demanding due to the vast data volumes that need to be analyzed. While various techniques exist nowadays to help with particular tasks of the analysis, the process as a whole still requires a lot of manual activities and expert skills. We propose an approach that allows the analysis of disk snapshots more efficiently and with lower demands on expert knowledge. Following a user-centered design methodology, we implemented an analytical tool to guide analysts during security incident investigations. The viability of the solution was validated by an evaluation conducted with members of different security teams.

READ FULL TEXT
research
12/02/2021

A tool to support the investigation and visualization of cyber and/or physical incidents

Investigating efficiently the data collected from a system's activity ca...
research
07/02/2019

Methodology for the Automated Metadata-Based Classification of Incriminating Digital Forensic Artefacts

The ever increasing volume of data in digital forensic investigation is ...
research
07/21/2021

The analysis approach of ThreatGet

Nowadays, almost all electronic devices include a communication interfac...
research
09/08/2022

Visual Firewall Log Analysis – At the Border Between Analytical and Appealing

In this paper, we present our design study on developing an interactive ...
research
07/30/2009

Knowledge Elecitation for Factors Affecting Taskforce Productivity using a Questionnaire

In this paper we present the process of Knowledge Elicitation through a ...
research
05/22/2022

Protecting File Activities via Deception for ARM TrustZone

A TrustZone TEE often invokes an external filesystem. While filedata can...
research
04/20/2023

Medical Image Deidentification, Cleaning and Compression Using Pylogik

Leveraging medical record information in the era of big data and machine...

Please sign up or login with your details

Forgot password? Click here to reset