The use of self-organising maps for anomalous behaviour detection in a digital investigation

dc.contributor.authorFei, B.K.L. (Bennie Kar Leung)
dc.contributor.authorEloff, Jan H.P.
dc.contributor.authorOlivier, Martin S.
dc.contributor.authorVenter, H.S. (Hein)
dc.date.accessioned2006-11-02T14:11:57Z
dc.date.available2006-11-02T14:11:57Z
dc.date.issued2006-10
dc.description.abstractThe dramatic increase in crime relating to the Internet and computers has caused a growing need for digital forensics. Digital forensic tools have been developed to assist investigators in conducting a proper investigation into digital crimes. In general, the bulk of the digital forensic tools available on the market permit investigators to analyse data that has been gathered from a computer system. However, current state-of-the-art digital forensic tools simply cannot handle large volumes of data in an efficient manner. With the advent of the Internet, many employees have been given access to new and more interesting possibilities via their desktop. Consequently, excessive Internet usage for non-job purposes and even blatant misuse of the Internet have become a problem in many organisations. Since storage media are steadily growing in size, the process of analysing multiple computer systems during a digital investigation can easily consume an enormous amount of time. Identifying a single suspicious computer from a set of candidates can therefore reduce human processing time and monetary costs involved in gathering evidence. The focus of this paper is to demonstrate how, in a digital investigation, digital forensic tools and the self-organising map (SOM) – an unsupervised neural network model – can aid investigators to determine anomalous behaviours (or activities) among employees (or computer systems) in a far more efficient manner. By analysing the different SOMs (one for each computer system), anomalous behaviours are identified and investigators are assisted to conduct the analysis more efficiently. The paper will demonstrate how the easy visualisation of the SOM enhances the ability of the investigators to interpret and explore the data generated by digital forensic tools so as to determine anomalous behaviours.en
dc.description.departmentComputer Science
dc.format.extent373585 bytes
dc.format.mimetypeapplication/pdf
dc.identifier.citationFei, BKL, Eloff, JHP, Olivier, MS & Venter, HS 2006, ‘The use of self-organising maps for anomalous behaviour detection in a digital investigation’, Forensic Science International, vol. 162, issues 1-3, pp. 33-37. [http://www.sciencedirect.com/science/journal/03790738]en
dc.identifier.issn0379-0738
dc.identifier.other10.1016/j.forsciint.2006.06.046
dc.identifier.urihttp://hdl.handle.net/2263/1006
dc.language.isoenen
dc.publisherElsevieren
dc.rightsElsevieren
dc.subjectDigital forensicsen
dc.subjectDigital investigationen
dc.subjectSelf-organising mapen
dc.subjectAnomalous behavioursen
dc.subjectVisualisationen
dc.titleThe use of self-organising maps for anomalous behaviour detection in a digital investigationen
dc.typeArticleen

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Fei_Use(2006).pdf
Size:
364.83 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
2.39 KB
Format:
Item-specific license agreed upon to submission
Description: