Investigative Profiling with Computer Forensic Log Data and Association Rules

  • Authors:
  • Tamas Abraham;Olivier de Vel

  • Affiliations:
  • -;-

  • Venue:
  • ICDM '02 Proceedings of the 2002 IEEE International Conference on Data Mining
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

Investigative profiling is an important activity in computerforensics that can narrow the search for one or morecomputer perpetrators. Data mining is a technique that hasproduced good results in providing insight into large volumesof data. This paper describes how the associationrule data mining technique may be employed to generateprofiles from log data and the methodology used for the interpretationof the resulting rule sets. The process relies onbackground knowledge in the form of concept hierarchiesand beliefs, commonly available from, or attainable by, thecomputer forensic investigative team. Results obtained withthe profiling system has identified irregularities in computerlogs.