Analysis of Evidence Using Formal Event Reconstruction
This work addresses digital forensics for investigators, but appears incremental as it builds on existing finite state machine methods.
The paper tackles the problem of analyzing digital evidence by expanding a finite state machine approach to formally test statements against system models, and demonstrates it in a case study.
This paper expands upon the finite state machine approach for the formal analysis of digital evidence. The proposed method may be used to support the feasibility of a given statement by testing it against a relevant system model. To achieve this, a novel method for modeling the system and evidential statements is given. The method is then examined in a case study example.