An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS
An Ontology for Digital Forensics in IT Security Incidents - OPUS
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
70 CHAPTER 9. SUMMARY<br />
after some issue occurred.<br />
Us<strong>in</strong>g the ontology to <strong>in</strong>vestigate the cases made it easier because only<br />
queries had to be issued. For example, <strong>for</strong> the Autorun query the pr<strong>in</strong>tkey<br />
module of volatility needs to be run multiple times to get the data from the<br />
registry <strong>in</strong> the memory. For the registry on the hard disk it is rst needed<br />
to know where the relevant les are located and then extract them with icat<br />
from The Sleuth Kit if the source is an image and then run reglookup <strong>for</strong> each<br />
of them. All this is simplied to only issu<strong>in</strong>g one query because all other<br />
commands have been run automatically dur<strong>in</strong>g the extraction process.<br />
In my op<strong>in</strong>ion the ontological approach has great potential because it<br />
makes <strong>for</strong>ensic analysis easier. <strong>An</strong> additional aspect is that after the database<br />
is lled, multiple <strong>in</strong>vestigators can use this data and do not need to run the<br />
same tools aga<strong>in</strong>.<br />
The creation of the ontology is not that easy as the tools do not create<br />
satisfy<strong>in</strong>g RDFS les or are uncom<strong>for</strong>table to use. If the <strong>for</strong>ensic ontology<br />
is to be developed further, it may be useful to create a tool that allows an<br />
easier creation of RDFS les of similar structure. Additionally, a program<br />
should be developed that makes it easier to parse the output of a <strong>for</strong>ensic<br />
tool and map it to the correct part of the ontology.