Back to Search
Start Over
Generating a Corpus of Mobile Forensic Images for Masquerading user Experimentation
- Source :
- Journal of Forensic Sciences. 61:1467-1472
- Publication Year :
- 2016
- Publisher :
- Wiley, 2016.
-
Abstract
- The Periodic Mobile Forensics (PMF) system investigates user behavior on mobile devices. It applies forensic techniques to an enterprise mobile infrastructure, utilizing an on-device agent named TractorBeam. The agent collects changed storage locations for later acquisition, reconstruction, and analysis. TractorBeam provides its data to an enterprise infrastructure that consists of a cloud-based queuing service, relational database, and analytical framework for running forensic processes. During a 3-month experiment with Purdue University, TractorBeam was utilized in a simulated operational setting across 34 users to evaluate techniques to identify masquerading users (i.e., users other than the intended device user). The research team surmises that all masqueraders are undesirable to an enterprise, even when a masquerader lacks malicious intent. The PMF system reconstructed 821 forensic images, extracted one million audit events, and accurately detected masqueraders. Evaluation revealed that developed methods reduced storage requirements 50-fold. This paper describes the PMF architecture, performance of TractorBeam throughout the protocol, and results of the masquerading user analysis.
- Subjects :
- Engineering
Service (systems architecture)
Mobile device forensics
Databases, Factual
Database
business.industry
Relational database
Enterprise architecture
020207 software engineering
Cloud computing
02 engineering and technology
User analysis
Forensic Medicine
computer.software_genre
Mobile Applications
Pathology and Forensic Medicine
World Wide Web
0202 electrical engineering, electronic engineering, information engineering
Genetics
020201 artificial intelligence & image processing
business
computer
Protocol (object-oriented programming)
Mobile device
Software
Subjects
Details
- ISSN :
- 00221198
- Volume :
- 61
- Database :
- OpenAIRE
- Journal :
- Journal of Forensic Sciences
- Accession number :
- edsair.doi.dedup.....b141fc34748c478b43aca34a8d424cad
- Full Text :
- https://doi.org/10.1111/1556-4029.13178