State Machine Theory of Digital Forensic Analysis

This page presents my on-going work on formalisation and automation of digital forensic analysis using the theory of state machines. The ultimate aim of this work is to provide rigorous, automatic methods of digital forensic analysis, which are based on models and methods of computer science rather than ad-hoc inference rules. The draft versions of papers and other documents posted on this web page are provided for non-commercial use only.

Software

Event Reconstruction and Analysis in Lisp (EARL) is my experimental software for finite state machine analysis of digital evidence.

Presentations

  1. P. Gladyshev "State Machine Theory of Digital Investigations" - a very accessible introduction to the key ideas of the theory without heavy maths.

Articles and Reports

  1. P. Gladyshev, A. Patel "Formalising Event Time Bounding in Digital Investigations", International Journal of Digital Evidence, vol. 4, no. 2., December 2005.

  2. P. Gladyshev, "Adding Real Time into State Machine Analysis of Digital Evidence", unpublished manuscript, June 2005. 


  3. P. Gladyshev, "Finite State Machine Analysis of a Blackmail Investigation", International Journal of Digital Evidence, vol. 4, no. 1., May 2005.


  4. P. Gladyshev, "Formalising Event Reconstruction in Digital Investigations", Ph.D. dissertation, Department of Computer Science, University College Dublin, August 2004.


  5. P. Gladyshev, A. Patel, "Finite State Machine Approach to Digital Event Reconstruction", Digital Investigation journal, vol.1, no. 2, Elsevier, May 2004. A draft of the paper is available here.


My previous publications can be found here.


Pavel Gladyshev, Ph.D., M.Sc., Dip.Eng.

School of Computer Science and Informatics,
University College Dublin
Belfield, Dublin 4, Ireland
email: pavel at gladyshev.info

Last updated: 15 April 2006