State Machine Theory of Digital Forensic Analysis

This page presents on-going work on formalisation and automation of digital forensic analysis using the theory of state machines. The ultimate aim of this work is to provide rigorous, automatic methods of digital forensic analysis, which are based on models and methods of computer science rather than ad-hoc inference rules. The draft versions of papers and other documents posted on this web page are provided for non-commercial use only.

Software

Event Reconstruction and Analysis in Lisp (EARL) is my experimental software for finite state machine analysis of digital evidence.

Presentations

  1. P. Gladyshev "State Machine Theory of Digital Investigations" - a very accessible introduction to the key ideas of the theory without heavy maths.

Articles and Reports

  1. P. Gladyshev, A. Enbacka "Rigorous Development of Automated Inconsistency Checks for Digital Evidence Using the B Method", International Journal of Digital Evidence, vol. 6, no. 2., November 2007.
  2. P. Gladyshev, A. Patel "Formalising Event Time Bounding in Digital Investigations", International Journal of Digital Evidence, vol. 4, no. 2., December 2005.

  3. P. Gladyshev, "Adding Real Time into State Machine Analysis of Digital Evidence", unpublished manuscript, June 2005. 


  4. P. Gladyshev, "Finite State Machine Analysis of a Blackmail Investigation", International Journal of Digital Evidence, vol. 4, no. 1., May 2005.


  5. P. Gladyshev, "Formalising Event Reconstruction in Digital Investigations", Ph.D. dissertation, Department of Computer Science, University College Dublin, August 2004.


  6. P. Gladyshev, A. Patel, "Finite State Machine Approach to Digital Event Reconstruction", Digital Investigation journal, vol.1, no. 2, Elsevier, May 2004. A draft of the paper is available here.


My previous publications can be found here.


Pavel Gladyshev, Ph.D., M.Sc., Dip.Eng.

School of Computer Science and Informatics,
University College Dublin
Belfield, Dublin 4, Ireland
email: pavel dot gladyshev at ucd dot ie

Last updated: 30 July 2008