Computer forensic timeline visualization tool

  • Authors:
  • Jens Olsson;Martin Boldt

  • Affiliations:
  • Blekinge Institute of Technology, School of Computing, Box 520, SE-372 25, Ronneby, Sweden;Blekinge Institute of Technology, School of Computing, Box 520, SE-372 25, Ronneby, Sweden

  • Venue:
  • Digital Investigation: The International Journal of Digital Forensics & Incident Response
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Computer Forensics is mainly about investigating crime where computers have been involved. There are many tools available to aid the investigator with this task. We have created a prototype of a new type of tool called CyberForensic TimeLab where all evidence is indexed by their time variables and plotted on a timeline. We believed that this way of visualizing the evidence allows the investigators to find coherent evidence faster and more intuitively. We have performed a user test where a group of people has evaluated our prototype tool against a modern commercial computer forensic tool and the results of this preliminary test are very promising. The results show that users completed the task in shorter time, with greater accuracy and with less errors using CyberForensic TimeLab. The subjects also experienced that the prototype were more intuitive to use and that it allowed them to easier locate evidence that was coherent in time.