Reference sets contain known content that are used to identify relevant or filter irrelevant content. Application profiles are a type of reference set that contain digital artifacts associated with application software. An application profile can be compared against a target data set to identify relevant evidence of application usage in a variety of investigation scenarios. The research objective is to design and implement a standardised strategy to collect and distribute application software artifacts using application profiles. An advanced technique for creating application profiles was designed using a formalised differential analysis strategy. The design was implemented in a live differential forensic analysis tool, LiveDiff, to automate and simplify data collection. A storage mechanism was designed based on a previously standardised forensic data abstraction. The design was implemented in a new data abstraction, Application Profile XML (APXML), to provide storage, distribution and automated processing of collected artifacts.
翻译:应用简介是一种包含与应用软件相关的数字文物的参考集,可以将应用简介与用于确定各种调查情景中应用使用情况的相关证据的目标数据集进行比较;研究目标是设计和实施一个标准化战略,利用应用简介收集和分发应用软件文物;使用正式的差别分析战略设计了制作应用简介的先进技术;在现场差分法学分析工具LiveDiff中实施设计,使数据收集自动化和简化;根据先前标准化的法医数据抽象化设计了一个存储机制;在新的数据抽象化、应用简介XML(APXML)中实施设计,为收集的文物提供储存、分发和自动处理。