Temporal metadata analysis: A learning classifier system approach

Michael C. Todd,Gilbert L. Peterson
DOI: https://doi.org/10.1016/j.fsidi.2024.301842
IF: 1.805
2024-11-01
Forensic Science International Digital Investigation
Abstract:Digital forensics is a complex field that requires expert knowledge (EK) and specialized tools to collect, analyze, and report on digital evidence. Temporal metadata analysis is particularly challenging, requiring expert knowledge to understand and interpret underlying traces and associate them with their source. This paper introduces Digital Trace Inspector (DTI), a Learning Classifier System (LCS)-based decision support tool for temporal metadata analysis. DTI leverages a binary Michigan-style LCS to locate and group corroborating temporal digital traces of targeted user activity. Rules are built from expert-created atomics encoded as feature vectors using patterns defined in a structured EK rule framework. The system is evaluated on 10 scenarios of typical user behavior on a Windows 10 workstation. Results show that all models achieved perfect recall, had an average F1 score of 0.98, and required little training data.
computer science, information systems, interdisciplinary applications
What problem does this paper attempt to address?