Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

DiagAnalyzer: User behavior analysis and visualization using Windows Diagnostics logs

Full metadata record
DC Field Value Language
dc.contributor.authorPark, Sungha-
dc.contributor.authorLee, Sangjin-
dc.date.accessioned2022-12-09T13:42:22Z-
dc.date.available2022-12-09T13:42:22Z-
dc.date.created2022-12-08-
dc.date.issued2022-09-
dc.identifier.issn2666-2817-
dc.identifier.urihttps://scholar.korea.ac.kr/handle/2021.sw.korea/146603-
dc.description.abstractWindows Diagnostics, which is used by default in Windows 10 and Windows 11, records basic device information as well as various detailed user activities of those who use Windows. Previously, there have been several preceding studies that attempted to apply diagnostics information to digital forensics analysis, but there have been no practical methods or publicly available tools to analyze data in relation to user behavior. Therefore, this paper analyzed how three representative activities (attaching and detaching USB storage devices, web browser activities, and wireless network activities) are recorded in Window Diagnostics. Furthermore, based on the analysis results, we developed DiagAnalyzer, which automatically analyzes the diagnostics event log and visualizes the user's behavior. Through the meth-odology and tool of this paper, the application of Windows Diagnostics deserves further attention as an important artifact in digital forensics investigation for Windows in the future. (c) 2022 The Author(s). Published by Elsevier Ltd on behalf of DFRWS This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).-
dc.languageEnglish-
dc.language.isoen-
dc.publisherELSEVIER SCI LTD-
dc.titleDiagAnalyzer: User behavior analysis and visualization using Windows Diagnostics logs-
dc.typeArticle-
dc.contributor.affiliatedAuthorLee, Sangjin-
dc.identifier.doi10.1016/j.fsidi.2022.301450-
dc.identifier.wosid000875559100007-
dc.identifier.bibliographicCitationFORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, v.43-
dc.relation.isPartOfFORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION-
dc.citation.titleFORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION-
dc.citation.volume43-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.description.journalClass1-
dc.description.isOpenAccessY-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalWebOfScienceCategoryComputer Science, Information Systems-
dc.relation.journalWebOfScienceCategoryComputer Science, Interdisciplinary Applications-
dc.subject.keywordAuthorWindows Diagnostics-
dc.subject.keywordAuthorEventtranscript-
dc.subject.keywordAuthordb-
dc.subject.keywordAuthorWindows forensics-
dc.subject.keywordAuthorWindows 10-
dc.subject.keywordAuthorWindows 11-
Files in This Item
There are no files associated with this item.
Appears in
Collections
School of Cyber Security > Department of Information Security > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher LEE, SANG JIN photo

LEE, SANG JIN
정보보호학과
Read more

Altmetrics

Total Views & Downloads

BROWSE