An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS An Ontology for Digital Forensics in IT Security Incidents - OPUS
48 CHAPTER 6. FORENSIC ONTOLOGY reg:hasHive reg:root rdfs:domain rdfs:range rdfs:domain rdfs:range reg:Registry reg:Hive reg:hasSubKey reg:keyname rdfs:range rdfs:domain rdfs:domain rdfs:domain reg:Key reg:keystate reg:hasValue reg:valuestate reg:value reg:key rdfs:range rdfs:domain rdfs:range rdfs:range rdfs:domain rdfs:domain rdfs:domain rdfs:domain reg:State reg:Value reg:type rdfs:range reg:ValueType Figure 6.7: Registry
6.8. FILE SYSTEM 49 fs:FileSystemObject sw:Resource rdfs:subClassOf fs:File rdfs:subClassOf fs:Folder rdfs:subClassOf fs:childOf rdfs:range rdfs:domain fs:hasPartition fs:Partition rdfs:range hw:Harddisk rdfs:domain fs:hasFileSystem fs:FileSystem rdfs:range rdfs:domain fs:hasFSContent fs:FSContent rdfs:range rdfs:domain fs:hasFSMetaData fs:FSMetaData rdfs:range rdfs:domain fs:hasFSFileName fs:FSFileName rdfs:range rdfs:domain fs:hasFSApplicationData fs:FSApplicationData rdfs:range rdfs:domain fs:hasRootObject rdfs:range rdfs:domain fs:startAddress fs:Address rdfs:range fs:FSContentChunk rdfs:domain fs:endAddress rdfs:range rdfs:domain fs:containsFSContent rdfs:range rdfs:domain fs:containsFSMetaData rdfs:range rdfs:domain fs:containsFSFileName rdfs:range rdfs:domain fs:containsFSApplicationData rdfs:range rdfs:domain fs:hasContentChunk rdfs:domain rdfs:range Figure 6.8: File System
- Page 1: Diplomarbeit An Ontology for Digita
- Page 4 and 5: Acknowledgement I would like to tha
- Page 6 and 7: 4 CONTENTS 5.1.4 Storage . . . . .
- Page 8 and 9: 6 CONTENTS
- Page 10 and 11: 8 CHAPTER 1. INTRODUCTION data lead
- Page 12 and 13: 10 CHAPTER 2. RELATED WORK investig
- Page 14 and 15: 12 CHAPTER 3. GOAL FORENSIC SEMANTI
- Page 16 and 17: 14 CHAPTER 3. GOAL FORENSIC SEMANTI
- Page 18 and 19: 16 CHAPTER 4. FORENSICS Basic rules
- Page 20 and 21: 18 CHAPTER 4. FORENSICS 4.1.2.2 Ran
- Page 22 and 23: 20 CHAPTER 4. FORENSICS entry conta
- Page 24 and 25: 22 CHAPTER 4. FORENSICS 4.2.3.1 Reg
- Page 26 and 27: 24 CHAPTER 4. FORENSICS vulnerable
- Page 28 and 29: 26 CHAPTER 4. FORENSICS The fls -m
- Page 30 and 31: 28 CHAPTER 4. FORENSICS of the sock
- Page 32 and 33: 30 CHAPTER 4. FORENSICS
- Page 34 and 35: 32 CHAPTER 5. ONTOLOGY Person name
- Page 36 and 37: 34 CHAPTER 5. ONTOLOGY 5.1.1 Creati
- Page 38 and 39: 36 CHAPTER 5. ONTOLOGY Resource Des
- Page 40 and 41: 38 CHAPTER 5. ONTOLOGY to be Augsbu
- Page 42 and 43: 40 CHAPTER 5. ONTOLOGY Gephi and Cy
- Page 44 and 45: 42 CHAPTER 5. ONTOLOGY
- Page 46 and 47: 44 CHAPTER 6. FORENSIC ONTOLOGY for
- Page 48 and 49: 46 CHAPTER 6. FORENSIC ONTOLOGY pro
- Page 52 and 53: 50 CHAPTER 6. FORENSIC ONTOLOGY 6.9
- Page 54 and 55: 52 CHAPTER 6. FORENSIC ONTOLOGY Par
- Page 56 and 57: 54 CHAPTER 6. FORENSIC ONTOLOGY
- Page 58 and 59: 56 CHAPTER 7. IMPLEMENTATION 7.3 RD
- Page 60 and 61: 58 CHAPTER 7. IMPLEMENTATION the co
- Page 62 and 63: 60 CHAPTER 7. IMPLEMENTATION 1 SELE
- Page 64 and 65: 62 CHAPTER 7. IMPLEMENTATION Anothe
- Page 66 and 67: 64 CHAPTER 7. IMPLEMENTATION 7.8 St
- Page 68 and 69: 66 CHAPTER 8. EVALUATION 6. The las
- Page 70 and 71: 68 CHAPTER 8. EVALUATION key (CTEMO
- Page 72 and 73: 70 CHAPTER 9. SUMMARY after some is
- Page 74 and 75: 72 APPENDIX A. EXTRACTION TOOL LIST
- Page 76 and 77: 74 APPENDIX A. EXTRACTION TOOL LIST
- Page 78 and 79: 76 APPENDIX B. FORENSIC TOOLS OUTPU
- Page 80 and 81: 78 APPENDIX C. SCREENSHOTS Figure C
- Page 82 and 83: 80 APPENDIX C. SCREENSHOTS Figure C
- Page 84 and 85: 82 APPENDIX C. SCREENSHOTS Figure C
- Page 86 and 87: 84 APPENDIX C. SCREENSHOTS
- Page 88 and 89: 86 BIBLIOGRAPHY [Carrier, 2012c] Ca
- Page 90 and 91: 88 BIBLIOGRAPHY [Microsoft, 2010] M
- Page 92: 90 BIBLIOGRAPHY [W3C, 2004] W3C (20
6.8. FILE SYSTEM 49<br />
fs:FileSystemObject<br />
sw:Resource<br />
rdfs:subClassOf<br />
fs:File<br />
rdfs:subClassOf<br />
fs:Folder<br />
rdfs:subClassOf<br />
fs:childOf<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasPartition<br />
fs:Partition<br />
rdfs:range<br />
hw:Harddisk<br />
rdfs:doma<strong>in</strong><br />
fs:hasFileSystem<br />
fs:FileSystem<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasFSContent<br />
fs:FSContent<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasFSMetaData<br />
fs:FSMetaData<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasFSFileName<br />
fs:FSFileName<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasFSApplicationData<br />
fs:FSApplicationData<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasRootObject<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:startAddress<br />
fs:Address<br />
rdfs:range<br />
fs:FSContentChunk<br />
rdfs:doma<strong>in</strong><br />
fs:endAddress<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:conta<strong>in</strong>sFSContent<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:conta<strong>in</strong>sFSMetaData<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:conta<strong>in</strong>sFSFileName<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:conta<strong>in</strong>sFSApplicationData<br />
rdfs:range<br />
rdfs:doma<strong>in</strong><br />
fs:hasContentChunk<br />
rdfs:doma<strong>in</strong><br />
rdfs:range<br />
Figure 6.8: File System