论文标题
基于5W1H的表达方式,用于有效地共享数字法医调查中的信息
5W1H-based Expression for the Effective Sharing of Information in Digital Forensic Investigations
论文作者
论文摘要
数字法医调查用于与数字设备有关的各个领域,包括网络犯罪。这是一种使用许多技术的调查过程,这些技术已作为工具实施。数字法医调查所涵盖的文件类型是广泛且多样的,但是,无法将结果表达为标准化的格式。标准化是通过设备,文件系统或应用程序的类型不同的。不同的输出使其耗时,难以共享信息和实施集成。此外,它可能会削弱网络安全。因此,定义归一化并以相同格式呈现数据很重要。在本文中,提出了基于5W1H的信息共享,用于有效的数字法医调查,以使用六个问题分析数字法医信息 - 谁,谁,何时,何时,为什么以及如何方式。基于基于5W1H的表达式,来自不同类型的文件的数字信息会以相同的输出格式转换并表示。由于5W1H是基本写作原则,因此基于5W1H的表达在案例研究中的应用表明,此表达式增强了信息共享的清晰度和正确性。此外,在安全事件的情况下,此表达式在与Stix兼容方面具有优势。
Digital forensic investigation is used in various areas related to digital devices including the cyber crime. This is an investigative process using many techniques, which have implemented as tools. The types of files covered by the digital forensic investigation are wide and varied, however, there is no way to express the results into a standardized format. The standardization are different by types of device, file system, or application. Different outputs make it time-consuming and difficult to share information and to implement integration. In addition, it could weaken cyber security. Thus, it is important to define normalization and to present data in the same format. In this paper, a 5W1H-based expression for information sharing for effective digital forensic investigation is proposed to analyze digital forensic information using six questions--what, who, where, when, why and how. Based on the 5W1H-based expression, digital information from different types of files is converted and represented in the same format of outputs. As the 5W1H is the basic writing principle, application of the 5W1H-based expression on the case studies shows that this expression enhances clarity and correctness for information sharing. Furthermore, in the case of security incidents, this expression has an advantage in being compatible with STIX.