Using simplified event calculus in digital investigation

  • Authors:
  • Svein Yngvar Willassen

  • Affiliations:
  • Norwegian University of Science and Technology, Trondheim, Norway

  • Venue:
  • Proceedings of the 2008 ACM symposium on Applied computing
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In a hypothesis-based approach to digital investigation, the investigator formulates his hypothesis about which events took place, and tests them using the evidence available. A formalism for the description of the investigated system is useful in the hypothesis formulation and testing. Simplified Event Calculus, a form of propositional logic, can be used to define and test hypotheses in a digital investigation. When a system is modelled in this logic, observed states can be used to find action hypotheses and test them in the model. This can assist investigators and fact-finders in reconstruction of events from digital evidence. The logic can also be used to derive invariants for a system that can be utilized in tools checking evidence from these systems for consistency.