Javascript must be enabled to continue!
Forensic triage of email network narratives through visualisation
View through CrossRef
Purpose
– The purpose of this paper is to propose a novel approach that automates the visualisation of both quantitative data (the network) and qualitative data (the content) within emails to aid the triage of evidence during a forensics investigation. Email remains a key source of evidence during a digital investigation, and a forensics examiner may be required to triage and analyse large email data sets for evidence. Current practice utilises tools and techniques that require a manual trawl through such data, which is a time-consuming process.
Design/methodology/approach
– This paper applies the methodology to the Enron email corpus, and in particular one key suspect, to demonstrate the applicability of the approach. Resulting visualisations of network narratives are discussed to show how network narratives may be used to triage large evidence data sets.
Findings
– Using the network narrative approach enables a forensics examiner to quickly identify relevant evidence within large email data sets. Within the case study presented in this paper, the results identify key witnesses, other actors of interest to the investigation and potential sources of further evidence.
Practical implications
– The implications are for digital forensics examiners or for security investigations that involve email data. The approach posited in this paper demonstrates the triage and visualisation of email network narratives to aid an investigation and identify potential sources of electronic evidence.
Originality/value
– There are a number of network visualisation applications in use. However, none of these enable the combined visualisation of quantitative and qualitative data to provide a view of what the actors are discussing and how this shapes the network in email data sets.
Title: Forensic triage of email network narratives through visualisation
Description:
Purpose
– The purpose of this paper is to propose a novel approach that automates the visualisation of both quantitative data (the network) and qualitative data (the content) within emails to aid the triage of evidence during a forensics investigation.
Email remains a key source of evidence during a digital investigation, and a forensics examiner may be required to triage and analyse large email data sets for evidence.
Current practice utilises tools and techniques that require a manual trawl through such data, which is a time-consuming process.
Design/methodology/approach
– This paper applies the methodology to the Enron email corpus, and in particular one key suspect, to demonstrate the applicability of the approach.
Resulting visualisations of network narratives are discussed to show how network narratives may be used to triage large evidence data sets.
Findings
– Using the network narrative approach enables a forensics examiner to quickly identify relevant evidence within large email data sets.
Within the case study presented in this paper, the results identify key witnesses, other actors of interest to the investigation and potential sources of further evidence.
Practical implications
– The implications are for digital forensics examiners or for security investigations that involve email data.
The approach posited in this paper demonstrates the triage and visualisation of email network narratives to aid an investigation and identify potential sources of electronic evidence.
Originality/value
– There are a number of network visualisation applications in use.
However, none of these enable the combined visualisation of quantitative and qualitative data to provide a view of what the actors are discussing and how this shapes the network in email data sets.
Related Results
CORRELATION AND STRUCTURE OF A FORENSIC TECHNIQUE AND FORENSIC SCIENCE
CORRELATION AND STRUCTURE OF A FORENSIC TECHNIQUE AND FORENSIC SCIENCE
A historical analysis of forensic techniques and forensic science emergence as scientific branches is outlined, their interconnection, differences are considered, the subject, obje...
REGARDING RELATION BETWEEN CLASSIFICATION OF FORENSIC SCIENCE GENERAL THEORY TASKS AND PRACTICAL FORENSIC ACTIVITY (Review Article)
REGARDING RELATION BETWEEN CLASSIFICATION OF FORENSIC SCIENCE GENERAL THEORY TASKS AND PRACTICAL FORENSIC ACTIVITY (Review Article)
The article analyzes conceptual foundations, views and ideas as to understanding of the essence of the classification of forensic science general theory tasks. The main views of sc...
Forensic Pathology Fellowship Training Positions and Subsequent Forensic Pathology Work Effort of past Forensic Pathology Fellows
Forensic Pathology Fellowship Training Positions and Subsequent Forensic Pathology Work Effort of past Forensic Pathology Fellows
The purpose of this study is to document the number of accredited, funded, and filled forensic pathology fellowship positions in the United States and to document the subsequent wo...
Comparison of the Effects of Sacco and START Triage Methods in the Death Risk Assessment of Mass Trauma Patients after Earthquake
Comparison of the Effects of Sacco and START Triage Methods in the Death Risk Assessment of Mass Trauma Patients after Earthquake
Introduction:Compared with traditional START Triage Method, the Sacco Triage Method is a new way to access death risk in disaster scenes. However, due to the difficulties in disast...
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Abstract
The Physical Activity Guidelines for Americans (Guidelines) advises older adults to be as active as possible. Yet, despite the well documented benefits of physical a...
Real-World Performance of a new Online Eye Symptom Triage Tool (eye+dot) in an Emergency Eye Clinic: Mixed Methods Evaluation Study (Preprint)
Real-World Performance of a new Online Eye Symptom Triage Tool (eye+dot) in an Emergency Eye Clinic: Mixed Methods Evaluation Study (Preprint)
BACKGROUND
Previous studies indicate that 37-92% of patients attending hospital emergency eye community. Digital triage tools may have the potential to supp...
PRACTICE AND ASSOCIATED FACTORS OF PEDIATRICS EMERGENCY TRIAGE AMONG HEALTHCARE PROVIDERS WORKING AT TERTIARY HOSPITALS IN WEST OROMIA, ETHIOPIA, 2025
PRACTICE AND ASSOCIATED FACTORS OF PEDIATRICS EMERGENCY TRIAGE AMONG HEALTHCARE PROVIDERS WORKING AT TERTIARY HOSPITALS IN WEST OROMIA, ETHIOPIA, 2025
Abstract
Background
The mortality rate in pediatric emergency rooms within developing countries remains alarmingly high, primar...
Research of Email Classification based on Deep Neural Network
Research of Email Classification based on Deep Neural Network
Abstract
The effective distinction between normal email and spam, so as to maximize the possible of filtering spam has become a research hotspot currently. Naive bay...

