DSpace Repository

CYBER FORENSICS: APPLICATION OF NORMALISED COMPRESSION DISTANCE FOR CROSS DRIVE CORRELATION

Show simple item record

dc.contributor.author Ramesh, Gubba
dc.date.accessioned 2014-11-28T06:52:44Z
dc.date.available 2014-11-28T06:52:44Z
dc.date.issued 2008
dc.identifier M.Tech en_US
dc.identifier.uri http://hdl.handle.net/123456789/11855
dc.guide Joshi, R. C.
dc.description.abstract In this work a new approach of automated Cross-Drive correlation, in computer forensics, is presented. This approach uses the concept of Normalized Information Distance(NID) that helps to derive drive similarity correlation between a pair of disk images. The algorithm uses the Normalized Compression Distance (NCD) which is the implementation approximation of NID. The method proposed is a parameter free correlation unlike the previous work which is based on generation of common features as parameters of comparison and correlation. The ever increasing capacities of digital storage devices and their rapid proliferation makes parameter based systems more time consuming as the generation of features or parameters would take a considerable amount of time. However, parameter free algorithm would provide quick and more complete leads and clues to the investigator so that he can focus only on the highlighted subset of input datasets for further detailed investigation. The main advantages of NCD based cross drive correlation are: examination of data for generating forensic features as parameters is not required, savings on time and resources that otherwise would be required for forensic features extraction, deep knowledge of the underlying data is not required, it would detect all similarities simultaneously, it would automatically select dominant shared features in all pairwise comparisons and can be used effectively for heterogeneous data. The algorithm works in three main stages: conversion of the acquired image to a reduced signature, NCD correlation and finally calculation of pairwise correlation score with graphical representation. Experiments on disk images of 200MB were conducted and the programs developed, without many modifications, can be easily scaled to inputs of sizes in Giga Bytes. en_US
dc.language.iso en en_US
dc.subject ELECTRONICS AND COMPUTER ENGINEERING en_US
dc.subject CYBER FORENSICS en_US
dc.subject NORMALISED COMPRESSION DISTANCE en_US
dc.subject CROSS DRIVE CORRELATION en_US
dc.title CYBER FORENSICS: APPLICATION OF NORMALISED COMPRESSION DISTANCE FOR CROSS DRIVE CORRELATION en_US
dc.type M.Tech Dessertation en_US
dc.accession.number G13926 en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record