Title: Automatic forensic log file analysis for Mac OS X systems
Authors: Zeki Turedi; Liangxiu Han
Addresses: School of Computing, Mathematics and Digital Technology, Manchester Metropolitan University, John Dalton Building, Chester Street, Manchester, M1 5GD, UK ' School of Computing, Mathematics and Digital Technology, Manchester Metropolitan University, John Dalton Building, Chester Street, Manchester, M1 5GD, UK
Abstract: Mac OS X-based systems are gaining growing popularity. Yet forensics on this type of systems is still in its infancy and traditional forensic tools do not work well with it. Currently, most examinations for Mac OS X systems are done manually by experts. It is costly and time consuming, especially for those examination tasks involved with large amount of data, such as forensic examination of log files. It is critical to develop new techniques and tools for facilitating Mac OS X-based forensic examination. To address this issue, we have first proposed and developed an automatic log file analyser, which can automatically carve forensic artefacts from multiple log files for facilitating forensic analysis on Mac OS X systems. The experimental evaluation shows our tool can handle large size of data effectively, which enables investigators to analyse log files in a time manner.
Keywords: cyber security; digital forensics; Mac OS X; log files; automatic log file analysis.
DOI: 10.1504/IJESDF.2013.055050
International Journal of Electronic Security and Digital Forensics, 2013 Vol.5 No.2, pp.124 - 138
Received: 23 Jul 2012
Accepted: 04 Apr 2013
Published online: 26 Jul 2014 *