dfm covers

How Genetic Algorithms can be used in forensics tools

An introduction to using evolutionary techniques for forensic investigation  

Tim Watson writes

During an investigation, or when setting up for forensic readiness, have you ever needed to optimise anything, to search, to pattern-match, or have you wished that your solutions were adaptive – changing as the system changes? From spam filtering through to Olympics event scheduling, Genetic Algorithms (GAs) have been used to search, refine and adapt. We’ll look at how they work, how to use them and by the end of the article you should be able to identify ways in which your work could be improved through the use of evolutionary computing.

Why struggle to identify a solution when you can grow your own? As with any new tool or technique, it is important to be able to identify when to use GAs and what added value they might contribute. While a full appreciation of the attributes of GAs and of their applicability is still out of reach to even the specialists in the field, the essential advantages are fairly straightforward to state. To grasp the benefits of GAs and when to use them, remember that GAs are good when you don’t know what you are doing.

If you know that text messages tend to be shorter when two people know each other well then calculate the statistical properties of text messages from a suspect’s phone and use a library of previously collected statistics to determine how well the communicating parties know each other. This is what John Olsson does when he applies his renowned forensic linguistic skills to text messages [Olsson, J., ‘Forensic Linguistics’, Continuum, 2nd Revised edition, 2008.]. If you know the format of a DOS partition table in the Master Boot Record of a hard disk drive then write an explicit algorithm – an executable recipe – to extract the information you need to tell you which partition is bootable and which ones are likely to contain relevant data. There’s no need to guess when you know what to look for.

But what about a situation where you don’t know enough? If you needed to automatically scan jpeg image files to identify images that show fear, how would you write that algorithm? If you needed a way to choose up to six Facebook profile attributes that are good indicators of online criminal activity, when attributes are often deliberately misleading and when online criminals will react to profiling by changing their profiles to avoid detection, which would you choose, how would you choose them and how would you adapt your choices as the profi les are changed? Both of the previous two examples would benefit from the use of GAs.

Read more on this fascinating subject in Issue 7 of DFM - out now - login or subscribe today!!

Please make cache directory writable.

Submit an Article

Call for Articles

We are keen to publish new articles from all aspects of digital forensics. Click to contact us with your completed article or article ideas.

Featured Book

Learning iOS Forensics

A practical hands-on guide to acquire and analyse iOS devices with the latest forensic techniques and tools.

Meet the Authors

Andrew Harbison

Andrew Harbison is a Director and IT Forensics Lead at Grant Thornton


Coming up in the Next issue of Digital Forensics Magazine

Coming up in Issue 39 on sale from February 2019:

Making Sense of Digital Forensic International Standards

To many the complexity of Standards, their numbering and obscure contents fail to make practical sense and confuse the entry points for effective use. A roadmap is provided in this paper for Standard information access and optimal use. Read More »

Evidentiary Challenges: Social media, the Dark Web, and Admissibility

This article takes a look at two categories of remote evidence: social media, and the dark web. We will also examine two interesting cases: The Target store credit card breach; and the civil case of Fero v Excellus Health Plan, Inc. Read More »

Subscribe today

Vehicle Data Forensics on Unsupported Systems

The article will help readers understand how to approach a vehicle from a digital forensics’ perspective, it will cover a range of infotainment units from popular manufacturers, data extraction methods and examples of data types found which may be considered intelligence and or used as digital evidence. Read More »

Every Issue
Plus the usual Competition, Book Reviews, 360, IRQ, Legal

Click here to read more about the next issue