Computer Forensic Timeline Visualization Tool
Blekinge Institute of Technology, School of Computing2009 (English)In: Digital Investigation. The International Journal of Digital Forensics and Incident Response, ISSN 1742-2876, E-ISSN 1873-202X, Vol. 6, no Supplement 1, 78-87 p.Article in journal (Refereed) Published
Computer Forensics is mainly about investigating crime where computers have been involved. There are many tools available to aid the investigator with this task. We have created a prototype of a new type of tool called CyberForensic TimeLab where all evidence is indexed by their time variables and plotted on a timeline. We believed that this way of visualizing the evidence allows the investigators to find coherent evidence faster and more intuitively. We have performed a user test where a group of people has evaluated our prototype tool against a modern commercial computer forensic tool and the results of this preliminary test are very promising. The results show that users completed the task in shorter time, with greater accuracy and with less errors using CyberForensic TimeLab. The subjects also experienced that the prototype were more intuitive to use and that it allowed them to easier locate evidence that was coherent in time.
Place, publisher, year, edition, pages
Elsevier , 2009. Vol. 6, no Supplement 1, 78-87 p.
Computer forensic timeline, Event visualization, E-fraud, Timestamp, Chronological evidence, Time Variable, Time determination
IdentifiersURN: urn:nbn:se:bth-7928DOI: 10.1016/j.diin.2009.06.008ISI: 000269484800010Local ID: oai:bth.se:forskinfo2F6FBF7C89653BC8C1257685003ED2A0OAI: oai:DiVA.org:bth-7928DiVA: diva2:835603