3LSPG: forensic tool evaluation by three layer stochastic process-based generation of data

  • Authors:
  • York Yannikos;Frederik Franke;Christian Winter;Markus Schneider

  • Affiliations:
  • Fraunhofer Institute for Secure Information Technology, Darmstadt, Germany;Fraunhofer Institute for Secure Information Technology, Darmstadt, Germany;Fraunhofer Institute for Secure Information Technology, Darmstadt, Germany;Fraunhofer Institute for Secure Information Technology, Darmstadt, Germany

  • Venue:
  • IWCF'10 Proceedings of the 4th international conference on Computational forensics
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Since organizations cannot prevent all criminal activities of employees by security technology in practice, the application of IT forensic methods for finding traces in data is extremely important. However, new attack variants for occupational crime require new forensic tools and specific environments may require adoptions of methods and tools. Obviously, the development of tools or their adaption require testing using data containing corresponding traces of attacks. Since real-world data are often not available synthetic data are necessary to perform testing. With 3LSPG we propose a systematic method to generate synthetic test data which contain traces of selected attacks. These data can then be used to evaluate the performance of different forensic tools.