Many digital forensic triages were suggested over the last decade to cope with growing data volume, mostly focusing on effective file acquisition techniques such as the classification of relevant file types according to crime types. However, innovative devices and services driving more online and offline activities generate new types of data, and, by the same token, they produce a variety of offense data in the context of allegations, suspicion, and criminal activities. In current practice in triage, investigators hardly diagnose such offense data highly intermingled with massive data generated from daily routines, struggling to gather the seemingly relevant files, or inevitably collecting many devices. But such collection is likely to fail in gathering the necessary evidence or have a huge investigation backlog and legal concerns in data privacy. To solve this issue, the analytical ability to measure and interpret the offense data in sets of ordinary data is required in triage work. We propose a new triage scheme steered by digital profiling approaches, diagnosing offense data in devices, and assessing priority so that the most relevant device or critical work can be examined first. We apply this scheme to industrial espionage for the purpose of detecting online and offline events associated with the crime occurred from a computer, called profile data, and change the profile data into a more human readable format that can provide context for you to understand what really happened in the case. The aim of the triage is to identify potential suspect devices among multiple devices through offense data analyzed at the premises of the undertaking, to provide a quick overview of them, with links to sufficient evidential findings for further investigation in a lab. The paper concludes with our empirical case study that shows the applicability of this profiling triage to reconstruct the crime scene.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Digital Profiling Triage Model for Industrial Espionage

  • Jieun Dokko,
  • Michael Shin

摘要

Many digital forensic triages were suggested over the last decade to cope with growing data volume, mostly focusing on effective file acquisition techniques such as the classification of relevant file types according to crime types. However, innovative devices and services driving more online and offline activities generate new types of data, and, by the same token, they produce a variety of offense data in the context of allegations, suspicion, and criminal activities. In current practice in triage, investigators hardly diagnose such offense data highly intermingled with massive data generated from daily routines, struggling to gather the seemingly relevant files, or inevitably collecting many devices. But such collection is likely to fail in gathering the necessary evidence or have a huge investigation backlog and legal concerns in data privacy. To solve this issue, the analytical ability to measure and interpret the offense data in sets of ordinary data is required in triage work. We propose a new triage scheme steered by digital profiling approaches, diagnosing offense data in devices, and assessing priority so that the most relevant device or critical work can be examined first. We apply this scheme to industrial espionage for the purpose of detecting online and offline events associated with the crime occurred from a computer, called profile data, and change the profile data into a more human readable format that can provide context for you to understand what really happened in the case. The aim of the triage is to identify potential suspect devices among multiple devices through offense data analyzed at the premises of the undertaking, to provide a quick overview of them, with links to sufficient evidential findings for further investigation in a lab. The paper concludes with our empirical case study that shows the applicability of this profiling triage to reconstruct the crime scene.