Forensic Data Analysis Pipeline
摘要
Today, forensic and judiciary investigation is receiving more and more support from the latest ICT technologies. The different stages of an investigation (e.g. data collection, storage, knowledge extraction, and visualization) require specific ICT methods and tools. The goal of our research was to build a framework dedicated to the judiciary investigation that covers most of these stages. The proposed solution defines an operational workflow for acquiring, processing, analyzing, and extracting relevant information that can be used as judicial evidence. It offers advanced capabilities for monitoring data communication networks, investigating storage systems, performing in-depth digital data analysis, and extracting judicial evidence. In addition, the solution ensures secure storage of forensic evidence, guaranteeing its authenticity and integrity. For this purpose, a multi-approach data protection system was adopted to prevent evidence alteration, modification, or loss.