15.01.2014 Views

An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS

An Ontology for Digital Forensics in IT Security Incidents - OPUS

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

70 CHAPTER 9. SUMMARY<br />

after some issue occurred.<br />

Us<strong>in</strong>g the ontology to <strong>in</strong>vestigate the cases made it easier because only<br />

queries had to be issued. For example, <strong>for</strong> the Autorun query the pr<strong>in</strong>tkey<br />

module of volatility needs to be run multiple times to get the data from the<br />

registry <strong>in</strong> the memory. For the registry on the hard disk it is rst needed<br />

to know where the relevant les are located and then extract them with icat<br />

from The Sleuth Kit if the source is an image and then run reglookup <strong>for</strong> each<br />

of them. All this is simplied to only issu<strong>in</strong>g one query because all other<br />

commands have been run automatically dur<strong>in</strong>g the extraction process.<br />

In my op<strong>in</strong>ion the ontological approach has great potential because it<br />

makes <strong>for</strong>ensic analysis easier. <strong>An</strong> additional aspect is that after the database<br />

is lled, multiple <strong>in</strong>vestigators can use this data and do not need to run the<br />

same tools aga<strong>in</strong>.<br />

The creation of the ontology is not that easy as the tools do not create<br />

satisfy<strong>in</strong>g RDFS les or are uncom<strong>for</strong>table to use. If the <strong>for</strong>ensic ontology<br />

is to be developed further, it may be useful to create a tool that allows an<br />

easier creation of RDFS les of similar structure. Additionally, a program<br />

should be developed that makes it easier to parse the output of a <strong>for</strong>ensic<br />

tool and map it to the correct part of the ontology.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!