Investigative behavior profiling with one class SVM for computer forensics

dc.contributor.author Bhukya, Wilson Naik
dc.contributor.author Banothu, Sateesh Kumar
dc.date.accessioned 2022-03-27T05:51:48Z
dc.date.available 2022-03-27T05:51:48Z
dc.date.issued 2011-12-26
dc.description.abstract Behavior profiling of a user or a system is of great importance and is a non-trivial task of system forensic experts. User profiling information is very much useful for forensic investigators by monitoring and collecting significant changes in user's behavior based on his/her computer usage patterns. Traditional investigation mechanisms are based on command line system events collected using log files. In a GUI based investigative profiling system, most of the user activities are performed using either mouse movements and clicks or a combination of mouse movements and keystrokes. The command line data cannot capture the complete GUI event behavior of the users hence it is insufficient to perform any forensic analysis in GUI based systems. Presently, there is no frame work available to capture the GUI based user behavior for forensic investigation. We have proposed a novel approach to capture the GUI based user behavior using a logging tool. Our experimentation results shows that, the GUI based investigative profiling forensic can give more accurate and leads to identify the culprits. We have shown how one class SVM is less overhead in terms of training and testing instances for computer forensic compared to two class SVM. © 2011 Springer-Verlag.
dc.identifier.citation Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics). v.7080 LNAI
dc.identifier.issn 03029743
dc.identifier.uri 10.1007/978-3-642-25725-4_33
dc.identifier.uri http://link.springer.com/10.1007/978-3-642-25725-4_33
dc.identifier.uri https://dspace.uohyd.ac.in/handle/1/8445
dc.subject forensic investigation
dc.subject GUI based Profiling
dc.subject Mouse events
dc.subject SVM
dc.subject User behavior
dc.title Investigative behavior profiling with one class SVM for computer forensics
dc.type Book Series. Conference Paper
dspace.entity.type
Files
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Plain Text
Description: