Informatics Department, State University of Maringá. Maringá, Brazil.
Informatics Department, State University of Maringá, Maringá, Brazil.
Forensic Sci Rev. 2024 Jul;36(2):99-125.
The evolution of digital media has increased the number of crimes committed using digital equipment. This has led to the evolution of the computer forensics area to digital forensics (DF). Such an area aims to analyze information through its main phases of identification, collection, organization, and presentation (reporting). As this area has evolved, many techniques have been developed, mainly focusing on the formalization of terminologies and concepts for providing a common vocabulary comprehension. This has demanded efforts on several initiatives, such as the definition of ontologies, which are a means to identify the main concepts of a given area. Hence, the existing literature provides several ontologies developed for supporting the DF area. Therefore, to identify and analyze the existing ontologies for DF, this paper presents a systematic literature review (SLR) in which primary studies in the literature are studied. This SLR resulted in the identification of ontology building methodologies, ontology types, feasibility points, evaluation/assessment methods, and DF phases and subareas ontologies have supported. These results were based on the analysis of 29 ontologies that aided in answering six research questions. Another contribution of this paper is a set of recommendations on further ontology-based support of DF investigation, which can guide researchers and practitioners in covering existing research gaps.
数字媒体的发展增加了使用数字设备犯罪的数量。这导致了计算机取证领域向数字取证(DF)的发展。该领域旨在通过其识别、收集、组织和呈现(报告)的主要阶段来分析信息。随着该领域的发展,已经开发出了许多技术,主要集中在术语和概念的形式化上,以提供对共同词汇的理解。这需要在几个倡议上付出努力,例如本体的定义,这是确定给定领域主要概念的一种手段。因此,现有文献提供了许多为支持 DF 领域而开发的本体。因此,为了识别和分析现有的 DF 本体,本文提出了一项系统的文献综述(SLR),其中研究了文献中的主要研究。这项 SLR 确定了本体构建方法、本体类型、可行性点、评估/评估方法以及 DF 阶段和子领域本体所支持的内容。这些结果是基于对 29 个本体的分析得出的,这些本体有助于回答六个研究问题。本文的另一个贡献是一套关于进一步基于本体的 DF 调查支持的建议,这可以为研究人员和从业者提供指导,以填补现有研究空白。