• AccountabilityFS: A File System Monitor for Forensic Readiness 

      Nordvik, Rune; Liao, Yi-Ching; Langweg, Hanno (Chapter, 2014)
      We present a file system monitor, AccountabilityFS, which prepares an organization for forensic analysis and incident investigation in advance by ensuring file system operation traces readily available. We demonstrate the ...
    • Evidential Reasoning for Forensic Readiness 

      Liao, Yi-Ching; Langweg, Hanno (Peer reviewed; Journal article, 2016)
      To learn from the past, we analyse 1,088 "computer as a target" judgements for evidential reasoning by extracting four case elements: decision, intent, fact, and evidence. Analysing the decision element is essential for ...
    • Process Tracking for Forensic Readiness 

      Liao, Yi-Ching (Doctoral theses at NTNU;2016:339, Doctoral thesis, 2016)
      This thesis contributes to the tangible methods to prepare an enterprise for upcoming digital investigation with complete, pertinent, reliable, and privacy preserving evidence. Regarding an information security incident ...