Javascript must be enabled to continue!
Forensic triage of email network narratives through visualisation
View through CrossRef
Purpose
– The purpose of this paper is to propose a novel approach that automates the visualisation of both quantitative data (the network) and qualitative data (the content) within emails to aid the triage of evidence during a forensics investigation. Email remains a key source of evidence during a digital investigation, and a forensics examiner may be required to triage and analyse large email data sets for evidence. Current practice utilises tools and techniques that require a manual trawl through such data, which is a time-consuming process.
Design/methodology/approach
– This paper applies the methodology to the Enron email corpus, and in particular one key suspect, to demonstrate the applicability of the approach. Resulting visualisations of network narratives are discussed to show how network narratives may be used to triage large evidence data sets.
Findings
– Using the network narrative approach enables a forensics examiner to quickly identify relevant evidence within large email data sets. Within the case study presented in this paper, the results identify key witnesses, other actors of interest to the investigation and potential sources of further evidence.
Practical implications
– The implications are for digital forensics examiners or for security investigations that involve email data. The approach posited in this paper demonstrates the triage and visualisation of email network narratives to aid an investigation and identify potential sources of electronic evidence.
Originality/value
– There are a number of network visualisation applications in use. However, none of these enable the combined visualisation of quantitative and qualitative data to provide a view of what the actors are discussing and how this shapes the network in email data sets.
Title: Forensic triage of email network narratives through visualisation
Description:
Purpose
– The purpose of this paper is to propose a novel approach that automates the visualisation of both quantitative data (the network) and qualitative data (the content) within emails to aid the triage of evidence during a forensics investigation.
Email remains a key source of evidence during a digital investigation, and a forensics examiner may be required to triage and analyse large email data sets for evidence.
Current practice utilises tools and techniques that require a manual trawl through such data, which is a time-consuming process.
Design/methodology/approach
– This paper applies the methodology to the Enron email corpus, and in particular one key suspect, to demonstrate the applicability of the approach.
Resulting visualisations of network narratives are discussed to show how network narratives may be used to triage large evidence data sets.
Findings
– Using the network narrative approach enables a forensics examiner to quickly identify relevant evidence within large email data sets.
Within the case study presented in this paper, the results identify key witnesses, other actors of interest to the investigation and potential sources of further evidence.
Practical implications
– The implications are for digital forensics examiners or for security investigations that involve email data.
The approach posited in this paper demonstrates the triage and visualisation of email network narratives to aid an investigation and identify potential sources of electronic evidence.
Originality/value
– There are a number of network visualisation applications in use.
However, none of these enable the combined visualisation of quantitative and qualitative data to provide a view of what the actors are discussing and how this shapes the network in email data sets.
Related Results
Improving emergency department triage quality improvement project
Improving emergency department triage quality improvement project
Background: Healthcare presents challenges that require nursing professionals to continually evaluate their practice. Overcrowding in the emergency department (ED) has become a wor...
The determinants of consumer behavior towards email advertisement
The determinants of consumer behavior towards email advertisement
PurposeThe aim of this study was to develop a theoretical model of email advertising effectiveness and to investigate differences between permission‐based email and spamming. By ex...
Situated Visualization in Motion
Situated Visualization in Motion
Visualisation localisée en mouvement
Dans ma thèse, je définis ce qu'est la visualisation en mouvement et j'apporte plusieurs contributions sur la manière de visual...
Referral to geriatric rehabilitation
Referral to geriatric rehabilitation
Summary
Older hospital patients are vulnerable to adverse outcomes of hospital stay. In aging societies,
post-acute care (PAC) programs were developed to support functional
recov...
CORRELATION AND STRUCTURE OF A FORENSIC TECHNIQUE AND FORENSIC SCIENCE
CORRELATION AND STRUCTURE OF A FORENSIC TECHNIQUE AND FORENSIC SCIENCE
A historical analysis of forensic techniques and forensic science emergence as scientific branches is outlined, their interconnection, differences are considered, the subject, obje...
REGARDING RELATION BETWEEN CLASSIFICATION OF FORENSIC SCIENCE GENERAL THEORY TASKS AND PRACTICAL FORENSIC ACTIVITY (Review Article)
REGARDING RELATION BETWEEN CLASSIFICATION OF FORENSIC SCIENCE GENERAL THEORY TASKS AND PRACTICAL FORENSIC ACTIVITY (Review Article)
The article analyzes conceptual foundations, views and ideas as to understanding of the essence of the classification of forensic science general theory tasks. The main views of sc...
THEORY OF FORENSIC EXPERTOLOGY IN THE SYSTEM OF LAW
THEORY OF FORENSIC EXPERTOLOGY IN THE SYSTEM OF LAW
The article deals with the concept of a general theory of forensic expertology, the conditions for its creation, the place of forensic expert science in the system of legal science...
Do prehospital providers and emergency nurses agree on triage assignment?: an efficacy study
Do prehospital providers and emergency nurses agree on triage assignment?: an efficacy study
ObjectivesThe aim of this study was to investigate the agreement on triage level between prehospital providers and emergency department (ED) nurses in clinical practice when using ...

