A framework for the forensic investigation of unstructured email relationship data
Haggerty, J, Karran, A, Lamb, D and Taylor, M 2011, 'A framework for the forensic investigation of unstructured email relationship data' , International Journal of Digital Crime and Forensics, 3 (3) , pp. 1-18.
- Published Version
Download (3MB) | Preview
Our continued reliance on email communications ensures that it remains a major source of evidence during a digital investigation. Emails comprise both structured and unstructured data. Structured data provides qualitative information to the forensics examiner and is typically viewed through existing tools. Unstructured data is more complex as it comprises information associated with social networks, such as relationships within the network, identification of key actors and power relations, and there are currently no standardised tools for its forensic analysis. Moreover, email investigations may involve many hundreds of actors and thousands of messages. This paper posits a framework for the forensic investigation of email data. In particular, it focuses on the triage and analysis of unstructured data to identify key actors and relationships within an email network. This paper demonstrates the applicability of the approach by applying relevant stages of the framework to the Enron email corpus. The paper illustrates the advantage of triaging this data to identify (and discount) actors and potential sources of further evidence. It then applies social network analysis techniques to key actors within the data set. This paper posits that visualisation of unstructured data can greatly aid the examiner in their analysis of evidence discovered during an investigation.
|Themes:||Subjects outside of the University Themes|
|Schools:||Colleges and Schools > College of Science & Technology > School of Computing, Science and Engineering > Computer Networking & Telecommunications Research Centre
Colleges and Schools > College of Science & Technology > School of Computing, Science and Engineering
|Journal or Publication Title:||International Journal of Digital Crime and Forensics|
|Depositing User:||J Haggerty|
|Date Deposited:||11 Oct 2011 09:09|
|Last Modified:||20 Aug 2013 17:13|
Actions (login required)
|Edit record (repository staff only)|