Sciweavers

SAC
2008
ACM

Using simplified event calculus in digital investigation

13 years 3 months ago
Using simplified event calculus in digital investigation
In a hypothesis-based approach to digital investigation, the investigator formulates his hypothesis about which events took place, and tests them using the evidence available. A formalism for the description of the investigated system is useful in the hypothesis formulation and testing. Simplified Event Calculus, a form of propositional logic, can be used to define and test hypotheses in a digital investigation. When a system is modelled in this logic, observed states can be used to find action hypotheses and test them in the model. This can assist investigators and factfinders in reconstruction of events from digital evidence. The logic can also be used to derive invariants for a system that can be utilized in tools checking evidence from these systems for consistency. Categories and Subject Descriptors F.4.1 [Mathematical Logic and formal languages]: Mathematical Logic
Svein Yngvar Willassen
Added 28 Dec 2010
Updated 28 Dec 2010
Type Journal
Year 2008
Where SAC
Authors Svein Yngvar Willassen
Comments (0)