CONSTRUCTING SOCIAL NETWORKS AND CLASSIFYING EMAIL ADDRESSES FROM RAW FORENSIC IMAGES
Ward, Erin C.
Stefanou, Marcus S.
McCarrin, Michael R.
MetadataShow full item record
The ability to find email addresses on digital storage media and deduce the relationships between them is critical for the success of many law enforcement and intelligence collection activities. Currently, building these social networks requires manually processing forensic images of acquired digital media. We conduct an experiment using readily available extraction and visualization tools along with a new algorithm that constructs networks based on the byte-offset proximity between digital artifacts. The main objective of this study is to test this new algorithm and refine techniques for classification with a goal of automating steps in the process of constructing social networks. To achieve this, we build an 11 terabyte dataset of drive images, construct networks from them, and assign these networks to the categories “useful” or “not useful” according to whether we believe them to contain information relevant to the actual social network of the device owner. We then interview device owners to determine ground truth, which we use to evaluate our analysis. We succeed in correctly categorizing networks with a recall of 0.9166, precision of 0.6316 and F-score of 0.7643. Our results show that our algorithm is successful in outputting data useful for the construction of the user's social networks.
Approved for public release. distribution is unlimited
Showing items related by title, author, creator and subject.
Torner, Linus P. (Monterey, California: Naval Postgraduate School, 2015-09);Several recent terrorist attacks in Western countries have highlighted the need for strategies to disrupt dark networks, and social network analysis (SNA) has proven to be a useful tool for analyzing network structure and ...
Alderson, David; Ubiquity Staff (Association for Computing Machinery (ACM), 2009-08);Since Duncan Watts and Steve Strogatz published “Collective Dynamics of Small-World Networks” in Nature in 1998, there has been an explosion of interest in mathematical models of large networks, leading to numerous research ...
Hafsia, Raouf. (2001-03);Ad hoc wireless networks are decentralized networks whose members join and leave the network in an asynchronous manner and for short periods of time. Each node participating in the network acts both as host and a router ...