Title: Automatic forensic log file analysis for Mac OS X systems

Authors: Zeki Turedi; Liangxiu Han

Addresses: School of Computing, Mathematics and Digital Technology, Manchester Metropolitan University, John Dalton Building, Chester Street, Manchester, M1 5GD, UK ' School of Computing, Mathematics and Digital Technology, Manchester Metropolitan University, John Dalton Building, Chester Street, Manchester, M1 5GD, UK

Abstract: Mac OS X-based systems are gaining growing popularity. Yet forensics on this type of systems is still in its infancy and traditional forensic tools do not work well with it. Currently, most examinations for Mac OS X systems are done manually by experts. It is costly and time consuming, especially for those examination tasks involved with large amount of data, such as forensic examination of log files. It is critical to develop new techniques and tools for facilitating Mac OS X-based forensic examination. To address this issue, we have first proposed and developed an automatic log file analyser, which can automatically carve forensic artefacts from multiple log files for facilitating forensic analysis on Mac OS X systems. The experimental evaluation shows our tool can handle large size of data effectively, which enables investigators to analyse log files in a time manner.

Keywords: cyber security; digital forensics; Mac OS X; log files; automatic log file analysis.

DOI: 10.1504/IJESDF.2013.055050

International Journal of Electronic Security and Digital Forensics, 2013 Vol.5 No.2, pp.124 - 138

Received: 23 Jul 2012
Accepted: 04 Apr 2013

Published online: 26 Jul 2014 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article