<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Forensic Artifacts' Analysis using Graph Theory</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Sophia Petra Krišáková</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Pavol Sokol</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Rastislav Krivoš-Belluš</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of Computer Science, Faculty of Science, Pavol Jozef Šafárik University in Košice</institution>
          ,
          <addr-line>Jesenná 5, 040 01 Košice</addr-line>
          ,
          <country country="SK">Slovakia</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The number of cyber-attacks is constantly growing, and their sophistication is increasing due to new techniques and strategies of attackers. Organisations must continuously improve their methods of detecting and responding to these attacks to protect their networks and information systems. The time between the occurrence of a security incident and its identification takes an average of 100 - 200 days, with organisations having a response time of between 50 - 70 days. Our work aims to reduce this time so that organisations can respond to security incidents more quickly. In this work, we use graph theory for forensic analysis in the Windows operating system. The main objective of the work is to identify digital evidence and the relationships between them. For this purpose, we work with datasets from various Capture the Flag (CTF) competitions. We describe the processing stages of the digital evidence and their transformation into graphs and then identify anomalies and cycles in the graphs in order to provide readers with a deeper insight.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;graph theory</kwd>
        <kwd>graph algorithms</kwd>
        <kwd>forensic analysis</kwd>
        <kwd>artifact</kwd>
        <kwd>cybersecurity</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>that article, we focus on how graph theory applied to
individual forensic artefacts available in the Windows
In the digital world, data and network security is a key operating system and the NTFS file system can help us.
concern for organisations of all sizes and industries. With Graph analysis allows us to identify the relationships
the rise of cyber-attacks and their ever-changing nature, between diferent digital evidence and their attributes,
organisations must constantly adapt to protect their as- thereby better understanding the nature of the attack.
sets and ensure the security of their information. Cyber To achieve this objective, we specify the following
attackers are constantly moving forward and developing partial research objectives:
new ways to penetrate systems and gain unauthorised
access to sensitive data. As these attacks become more so- • What attributes of forensic artefacts are best
phisticated, the challenge for organisations is to identify suited for graph representation?
attacks as quickly as possible and respond appropriately • How can specific properties of graphs help
idenand ideally. tify key forensic artefacts and relationships in</p>
      <p>One of the main issues in the response to security at- digital forensics?
tacks is the time between the occurrence of a security
incident, its identification, and the subsequent response. This paper is divided into six sections. Section 2
disThis time can be non-trivial, often measured in hundreds cusses papers relevant to this research. Section 3 specifies
of days, giving attackers ample time to cause damage the methods employed in this paper, including the
colwithout being detected. In addition, even after a secu- lection and processing of the digital evidence. Section 4
rity incident is identified, an organisation needs time to outlines the graph theory applied to digital evidence and
resolve it and restore normal operations. graph generation options. Section 5 discusses the lessons</p>
      <p>Our research focuses on the security incident response learned from applied graph properties to digital evidence.
process, including digital forensics. The main aim is to Section 6 provides a summary, including our suggestions
reduce the time interval required to resolve a security for future research.
incident and provide organisations with a way to respond
more quickly and efectively to security incidents. In</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>
        ITAT 2024 Information Technologies – Applications and Theory 2024, We often think of data analysis and machine learning
September 20–24, 2024, Drienica, Slovakia as elements of artificial intelligence. It may be about
* Corresponding author. analysing data diferently. We must also visualise the
† These authors contributed equally. data, preprocess it, get basic statistics, etc. It is in the
vi$ sophia.petra.krisakova@upjs.sk (S. P. Krišáková); sualisation that graphs can help us. Several works have
alpavol.sokol@upjs.sk (P. Sokol); rastislav.krivos-bellus@upjs.sk ready been done in forensic artefact analysis using graphs.
(R. 0K0r0i0v-o0š0-0B2e-l1lu9š6)7-8802 (P. Sokol) Many of these have focused on network communication,
© 2024 Copyright for this paper by its authors. Use permitted under Creative Commons License which is diferent from the form of data we use in this
CPWrEooUrckReshdoinpgs IhStpN:/c1e6u1r3-w-0s.o7r3g ACttEribUutRion W4.0oInrtekrnsahtioonpal (PCCroBYce4.0e).dings (CEUR-WS.org) work. Nevertheless, we can take inspiration from them
as they ofer insight into the representation of forensic Due to the proliferation of smart devices, detecting
artefacts using graphs and their connections. We have and mitigating faults in computer networks is crucial.
selected a few of these papers to get a basic overview of Anomalies, whether from security breaches, component
the current state of the art in the given field. failures, or environmental factors, must be promptly
addressed. Recent studies on anomaly detection in
com2.1. Security Data Analysis puter networks categorize solutions and highlight trends
and shortcomings, especially regarding malware in
smartCybercrime risks have escalated with the digitization of phone networks.
data (books, videos, images, medical and genetic infor- Paper [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] introduces a graph-based approach to
netmation) via laptops, tablets, smartphones, and wearables. work forensics, using a graph model of digital evidence
Digital forensics recovers lost or deleted files but requires for evidence presentation and automated reasoning. The
more eficient investigation resources. Current processes proposed hierarchical reasoning framework infers
netrely heavily on human input, slowing responses to rapid work entity states and identifies critical entities. An
incybercrimes. Machine learning can automate digital in- teractive hypothesis testing framework aids in detecting
vestigations, aiding digital investigators [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. attack activities. Experimental results show the
proto
      </p>
      <p>
        Constantini, Gasperis, and Olivieri explored artificial type’s efectiveness in extracting attack scenarios with
intelligence and computational logic, particularly answer minimal expert knowledge.
set programming, to automate evidence analysis in dig- As Internet trafic grows, so do cyber crimes,
necesital forensics. They demonstrated how complex inves- sitating advanced network forensics. One method
comtigations could be optimized and automated to assist bines network vulnerability and graph network evidence
in generating hypotheses for court cases using graph to reconstruct attack scenarios and identify multi-stage
theory-based algorithms [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. attacks, confirmed by experimental results [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        Ch. Easttom highlighted the use of graph theory in Spectral graph theory helps understand network
malcriminal investigations, describing how mathematical ware propagation, essential as device connectivity
inmodelling helps understand relationships among sus- creases. Using various Laplacian matrices to track
netpects, victims, and systems [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Palmer, Campbell, and work pattern changes, one study [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] ofers insights into
Gelfand further discussed graph theory’s role in forensic malware spread, aiding in faster infection detection.
analysis, noting the visualization benefits for
investigators and its potential to support the investigation process
[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. 3. Methodology
      </p>
      <p>
        A study on distributed graph analysis of large-scale
email datasets showcased improved eficiency and accu- In this chapter, we have covered how to acquire,
preproracy in digital evidence analysis using centrality algo- cess, and explain data so that we can combine it into
rithms [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Binwal, Devi, and Singh developed algorithms graphs, filter it, and analyse it later. We have also
defor fingerprint graph representation and isomorphism scribed the creation of the super timeline and the
subsetesting, applicable to broader forensic analysis despite quent transformation of the other two datasets.
difering input data [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>Additionally, attack graphs, used to identify potential 3.1. Data acquisition and description
attack paths and vulnerabilities, are proposed for
practical forensic analysis, including antiforensic scenarios.</p>
      <p>
        These graphs help understand complex attack paths and
missing evidence, demonstrated through a database
attack case study [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>Our contribution is to integrate these methods to
enhance digital forensics. We focus on automating digital
evidence analysis with graph theory to elucidate
relationships among digital evidence and entities.</p>
      <sec id="sec-2-1">
        <title>We selected seven fictitious cases from CTF competitions</title>
        <p>focused on forensics, incident response, and threat
detection, and we used disk images from these cases.</p>
        <p>
          The first example is the case of the stolen Szechuan
sauce from the DFIR Madness portal called Case001
The case of the Stolen Szechuan sauce [
          <xref ref-type="bibr" rid="ref11">11</xref>
          ], where in
this case the main goal was to find out how CITADEL’s
recipe got on the dark web. The company requested
forensic analysis, identification of unwanted applications
installed on the system, and detection of the location and
time of installation. The case also ofers information as
to whether any content was changed, modified, deleted,
or data was leaked. We worked with artefacts from the
company’s DC domain control server (hereafter called
the ”DC server”) and from the Desktop - therefore we
count this case as two datasets.
        </p>
        <sec id="sec-2-1-1">
          <title>2.2. Forensic Analysis in Network</title>
        </sec>
        <sec id="sec-2-1-2">
          <title>Communication Using Graph Theory</title>
        </sec>
      </sec>
      <sec id="sec-2-2">
        <title>While our primary focus is on NTFS file system data from Windows, we also review digital forensics in network communication, linking file system data with network communication data.</title>
        <p>• MACB : timestamps (Modification, Access,</p>
        <p>Changed, Birth)
• Source : source name abbreviation (e.g. REG
registry records)
• Sourcetype : description of the source
• Type : timestamp type (e.g. last entry)
• User : the user name (if any) that is associated
with the event
• Host : host name (if any) that is associated with
the event
• Short : contains a short description field in
which the text is stored
• Desc : an array that contains most of the parsed
information
• Version : version number of the timestamp
• Filename : the name of the file that is associated
with the event
• Inode : inode number of the file being analysed
• Notes : a place to store additional information
• Format : the input module that was used to parse
• Extra : field with parsed information that is
linked and stored here</p>
      </sec>
      <sec id="sec-2-3">
        <title>The other three cases Magnet CTF 2019 [12], Magnet</title>
        <p>
          CTF 2020 [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] and Magnet CTF 2022 [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ] were from the
CTF (Capture the Flag) Magnet Forensics competition. It
was not a classical forensic analysis, but rather answering
questions like ”when did we get the disk image” or ”when
was the software installed”.
        </p>
        <p>
          The last two cases, NIST Data Leakage Case [
          <xref ref-type="bibr" rid="ref15">15</xref>
          ]
and NIST Hacking Case [
          <xref ref-type="bibr" rid="ref16">16</xref>
          ], are used to learn about
diferent forms of data leakage and to improve techniques
for investigating them. We focused on investigating a
data leak case where the key is to uncover evidence of
illegal activities and obtain any information generated
by the suspect.
        </p>
        <sec id="sec-2-3-1">
          <title>3.2. Data preprocessing</title>
        </sec>
      </sec>
      <sec id="sec-2-4">
        <title>For data preprocessing, we followed the same steps in</title>
        <p>
          all seven cases, specifically specifying the preprocessing
process for only one case. We worked with the data
according to the procedure described in the paper [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
        </p>
        <p>
          We created the timeline using the Log2timeline [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]
tool and its plugins. We modified the resulting timeline
with the psort.py tool and the Python language with the
pandas library. Our dataset contained records from 11
diferent data sources, with FILE, EVT, and REG records In addition to the basic seven datasets, we created 6
being the most prominently represented, accounting for additional CSV files containing records from FILE and
87% of all records. We divided the extracted attributes 7 CSV files containing records from EVT. The datasets
into seven categories. from FILE have 44 attributes, and EVT have 40 attributes.
        </p>
        <p>
          We narrowed the dataset to the time of the security These files were created by extracting data from the
origincident and manually identified relevant digital inal supertimeline. For example, if there was a MACB
evidence, including the inode files: 84630, 84880, 84987, column in the original dataset, four new columns were
86966, 86967, 86968, 86970, 86971, 86975, 87059, 87060, created in the new (EVT or FILE) dataset, and the original
87064, 87111, 87112, 87137, and files with the names: one was deleted. The new columns are ’M’, ’A’, ’C’, ’B’. If
’coreupdater. exe’, ’FILESH 1’, ’Secret’, ’BETH_S 1.TXT’, there was a ’.ACB’ record in the original data, we wrote
’Beth-_Secret.lnk’, ’SECRET 1.TXT’, ’SECRET_beth.lnk’, 1 in the relevant ’A’, ’C’, ’B’ columns and 0 in the ’M’
’Szechuan’, ’SZECHU1.TXT’, ’Secret.lnk’, ’NoJerry. column. In this way, we partially created binary data or
lnk’, ’No-Jerry.txt’, ’f01b4d95cf55d32a.automatic- columns. Not all attributes could be converted this way,
Destinationsms’, ’SECRET_beth.txt’, ’Beth_Secret.txt’, so columns like ’date’ or ’time’ were left unchanged. The
’Secret.zip’, ’coreupdater.exe.2424 urv. partial’. exact procedure for creating datasets is explained in [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ].
        </p>
        <p>Next, we analysed the inodes and filenames, excluding For later analysis and graphing needs, we had to
cresome inodes and filenames. Finally, we used aggregation ate additional columns in the FILE datasets - MACB, file,
functions and created attribute combinations to analyse dir, and NTFS, which were created by concatenating
the data. some of the columns. MACB - we merged the ’broken’</p>
        <p>We only manually identified inodes and file names in columns ’M’, ’A’, ’C’, ’B’ into one again. In the case of the
the stolen Szechuan sauce recipe; the identified inodes ifle column, these were ’file_executable’, ’file_graphic’,
and file names still need to be identified for the other ’file_documents’, ’file_ps’ and ’file_other’. For dir
datasets. ’dir_appdata’, ’dir_win’, ’dir_user’ and ’dir_other’. NTFS</p>
        <p>
          Each of the seven datasets is a super timeline con- - ’file_stat’, ’NTFS_file_stat’, ’file_entry_shell_item’ and
taining 17 attributes, and the following rows are records ’NTFS_USN_change’.
(events). There are 17 attributes and their description The analysis of the selection of the attributes
menby [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ]: tioned above, as well as the analysis of various
combinations of attributes for anomaly detection, is presented in
the paper [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ].
• Date : the date when the event occurred
• Time : time the event occurred
• Timezone : time zone
        </p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>4. Graph Theory</title>
      <sec id="sec-3-1">
        <title>4.1. Background</title>
        <p>A Graph  = (, ) is a pair of a finite set of 
vertices  = {0, 1, . . . , − 1} and  edges  =
{{,  }|0 ≤ , , &lt; ,  ̸= }. A directed graph has
oriented edges(directed arcs), i.e. the order of vertices
is important (,  ). (Edge-)Weighted graph assigns
the weight to each edge, so the edges are in the form
(,  ,  ).</p>
        <p>A bipartite graph is a special type of graph where
a set of vertices can be divided into two disjoint sets
(partitions), where each edge has exactly one vertex from
every partition.</p>
        <p>There are several definitions and parameters: path
(sequence of incident vertices and edges, starting and
ending vertex (leaf), all vertices are mutually diferent),
excentricity, etc.</p>
        <p>The degree of the vertex  in a graph , denoted by
deg() or (), is the number of edges incident to 
in . The maximum degree of a graph , denoted by
∆( ), is the maximum value among the degrees of all
vertices of the graph . By analogy, we also denote the
minimum degree of a graph .</p>
        <p>Walk in the graph  denotes the alternating sequence
of incident vertices and edges (starting and ending with
vertex). A sequence with mutually diferent edges is
called a trail. A walk where all vertices difer is called
a path. In other words, a path in a graph is a sequence
of vertices for which there indeed exists an edge in the
graph between every two following vertices. No two
vertices (and hence no edges) are repeated. A trail in
which all vertices except the first and last are distinct is
called a cycle.</p>
        <p>A graph is connected if every pair of vertices in the
graph is connected. It means that there is a path between
every pair of vertices. A component of a graph is a
connected subgraph that is not part of any larger connected
subgraph.</p>
        <p>An edge of a graph is called a bridge if the number of
components increases when it is removed. A vertex of
a graph is called a cut vertex/articulation point if the
number of components of the graph increases when it is
removed.</p>
        <p>Eccentricity the () of a point  is the distance of
the point  from the farthest point in the  graph. The
radius of the graph () is the minimum eccentricity
of a point in the graph , and () is the maximum
The center of () is the set of all central vertices in
the graph . The eccentric vertex of a vertex  is the
vertex that is the furthest from it. A vertex v is called
peripheral if () = (). Periphery  ()
of a graph  is the set of all peripheral vertices in the
graph .</p>
      </sec>
      <sec id="sec-3-2">
        <title>4.2. Graph Generation from Forensic</title>
      </sec>
      <sec id="sec-3-3">
        <title>Artifacts</title>
        <sec id="sec-3-3-1">
          <title>Typical graph generation in the security area is creating</title>
          <p>
            just nodes of one type and connecting them depending on
communication [
            <xref ref-type="bibr" rid="ref22">22</xref>
            ] in graph or finding an attack vector
in a directed graph [
            <xref ref-type="bibr" rid="ref23">23</xref>
            ]. Standard computer
networkbased cybersecurity applications cover trafic, security
policies and vulnerabilities/threats [
            <xref ref-type="bibr" rid="ref24">24</xref>
            ].
          </p>
          <p>For the artefacts, one can create nodes from any
attribute (column) or any combination of attributes.
Moreover, we found the most interesting results for bipartite
graphs, e.g., using two node types. Depending on the
dataset, we focused on diferent pairs of node types.</p>
        </sec>
      </sec>
      <sec id="sec-3-4">
        <title>4.3. Graph from supertimeline</title>
        <p>For the super timeline, we have chosen attributes such
as user, source, MACB, sourcetype and inode and
always two of them as vertex types for the generated
bipartite graph. We can consider other attributes that
will be represented by vertices in the graph, e.g. host,
type, filename. Some of these attributes are
categorical so that we can think of them in this sense. The edge
represents the row’s existence in data containing these
two vertices (artefact). An example of the NIST Data
Leakage case is shown in Fig. 2.</p>
      </sec>
      <sec id="sec-3-5">
        <title>4.4. Graph from EVT artifacts</title>
        <p>In the EVT dataset, we created binary
combinations of three attributes: event_id, user_sid, and
execution_process because we could not tell any
vital information about the relationships between the
attributes by selecting other attributes. We could also
consider attributes like inode, computer_name, and
source_name, since we assume they are finite in
number and not binary values, but that probably wouldn’t
add any value for us. An example of a generated graph
from the EVT dataset is shown in Fig. 1.</p>
      </sec>
      <sec id="sec-3-6">
        <title>4.5. Graph from FILE artefacts</title>
        <sec id="sec-3-6-1">
          <title>In a similar way to the super timeline, we also created</title>
          <p>graphs in the FILE dataset, but with diferent attributes,
such as MACB, dir, file, and NTFS, the creation of which
we explained in Chapter 3.2. In the datasets file, it was
challenging to think of other attributes that would be
suitable for graphing because they were in binary form.
This is why we merged some attributes, but it was
impossible for all of them. We would still include the inode
attribute in the graph creation process, but it had many
unique values. Examples of these graphs are in Fig. 4 and
Fig. 5.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>5. Lessons learned from graph properties</title>
      <sec id="sec-4-1">
        <title>From the generated graphs, we have focused on some graph-based metrics [22] and found some anomalies. In the current research, we have used only unweighted graphs.</title>
        <sec id="sec-4-1-1">
          <title>5.1. Eccentricity</title>
          <p>2022. Fig. 3 shows the graph from the Magnet CTF 2022
case. The lowest eccentricities in this graph were in the
vertices ’WinEVTX’ (source type attribute) and ’Patrick’
(user attribute). We observed the same behaviour in the
other Magnet CTF cases - that is, the graph centre was
always identified as the ’WinEVTX’ vertex and one of
the users.</p>
        </sec>
        <sec id="sec-4-1-2">
          <title>5.2. Degree of vertices</title>
        </sec>
      </sec>
      <sec id="sec-4-2">
        <title>In particular, we can exploit eccentricity in graphs in</title>
        <p>the super timeline dataset created from user and source We exploited the degree of vertex in the datasets created
or user and source type attributes. For example, in the from the supertimeline from the FILE source. We
creNIST Data Leakage Case in Fig. 2, we created a graph ated three types of graphs - MACB and file, MACB and
from the user and source attributes and then found the dir, MACB and NTFS. Fig. 4 shows an example of such
eccentricity of all vertices. The vertices belonging to a graph. The most interesting graphs arose when the
the user attribute had the lowest eccentricity of 3: ’-’, MACB and NTFS timestamps were combined, as shown
’informant’, ’admin11’ and ’temporary’, and the vertices in Fig. 4. At first glance, it might seem that we should
belonging to the source attribute had ’REG’ and ’EVT’. focus on the NTFS_UNS_change attribute because it is
These vertices can also be called the centre of the graph. associated with timestamp C (Change), but neither the</p>
        <p>We also created graphs from the user and source type ifle_stat and NTFS_file_stat vertices are, despite having
attributes and searched for the graph centre. We can illus- the highest degree of vertex - 14. The most significant
trate this with all three Magnet CTF cases 2019, 2020 and vertex in this graph is file_entry_shell_item with a
vertex degree of 6 because if we look further at the records
containing this NTFS attribute value, we find "only" 19
unique inode values in 163 records, and just 9 of these
inodes were identified as relevant to the case.</p>
        <sec id="sec-4-2-1">
          <title>5.3. Cycles in graphs</title>
        </sec>
      </sec>
      <sec id="sec-4-3">
        <title>After creating the graph from The Stolen Szechuan Sauce</title>
        <p>- FILE dataset in Fig. 5, it was not visible what specifically
to focus on, so we had to apply the properties of the graph.
We looked for the base cycles in the graph. We found
43 of these, and seven cycles contained inodes that were
manually identified as relevant to the case by the analysis.
In the same way, we analysed the graph created from the
MACB and lfiename attributes, where we also found file
names in the base cycles marked as relevant to the case
by manual analysis. In this analysis, however, we must
consider that the attributes are not equivalent because
the MACB timestamps or combinations will always be
at most 16, and the inodes are a diferent number, often
much higher.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>6. Results and future works</title>
      <sec id="sec-5-1">
        <title>This paper focuses on the automation of response to secu</title>
        <p>rity incidents, including digital forensic analysis within
the Windows operating system and NTFS file system.
For this purpose, we used the graphs’ structure and
properties to better understand the relationships between the
analysed digital evidence. The paper demonstrated the
possibilities of generating graphs, particularly from
super timeline formats, event records, and the Master File
Table. We showed that it is essential to carefully select
the attributes of artefacts that can be used as vertices and
to determine the corresponding edges of the graphs. At
the same time, we identified several properties of graphs,
whose analysis can help better understand the
relationships and identify interesting or relevant digital evidence.
In the future, we will enhance our models with weighted
graphs.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgment</title>
      <sec id="sec-6-1">
        <title>This paper was supported by the Slovak Research and Development Agency under contract No. APVV-23-0137 and contract No. APVV-21-0336.</title>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Iqbal</surname>
            , Salman,
            <given-names>S. A.</given-names>
          </string-name>
          <string-name>
            <surname>Alharbi</surname>
          </string-name>
          ,
          <article-title>Advancing automation in digital forensic investigations using machine learning forensics, Digital Forensic Science</article-title>
          .
          <source>IntechOpen</source>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S.</given-names>
            <surname>Costantini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. D.</given-names>
            <surname>Gasperis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Olivieri</surname>
          </string-name>
          ,
          <article-title>Digital forensics and investigations meet artificial intelligence</article-title>
          ,
          <source>Annals of Mathematics and Artificial Intelligence</source>
          (
          <year>2019</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>C.</given-names>
            <surname>Easttom</surname>
          </string-name>
          ,
          <article-title>Utilizing graph theory to model forensic examination</article-title>
          ,
          <source>International Journal of Innovative Research in Information Security (IJIRIS) 4</source>
          (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>I. Palmer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Campbell</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Gelfand</surname>
          </string-name>
          ,
          <article-title>Exploring digital evidence with graph theory</article-title>
          ,
          <source>in: ADFSL Conference on Digital Forensics, Security and Law</source>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>S.</given-names>
            <surname>Ozcan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Astekin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. K.</given-names>
            <surname>Shashidhar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Zhou</surname>
          </string-name>
          ,
          <article-title>Centrality and scalability analysis on distributed graph of large-scale e-mail dataset for digital forensics</article-title>
          ,
          <source>in: IEEE International Conference on Big Data (Big Data)</source>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>J.</given-names>
            <surname>Binwal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Devi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Singh</surname>
          </string-name>
          ,
          <article-title>Mathematical modelling and simulation of fingerprint analysis using graph isomorphism, domination, and graph pebbling</article-title>
          ,
          <source>Advances and Applications in Discrete Mathematics</source>
          (
          <year>2023</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>C.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Singhal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Wijesekera</surname>
          </string-name>
          ,
          <article-title>Using attack graphs in forensic examinations</article-title>
          , in: Seventh International Conference on Availability,
          <source>Reliability and Security</source>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>W.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T. E.</given-names>
            <surname>Daniels</surname>
          </string-name>
          ,
          <article-title>Building evidence graphs for network forensics analysis</article-title>
          ,
          <source>in: 21st Annual Computer Security Applications Conference (ACSAC'05)</source>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>J.</given-names>
            <surname>He</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Chang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>He</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. S.</given-names>
            <surname>Pathan</surname>
          </string-name>
          ,
          <article-title>Network forensics method based on evidence graph and vulnerability reasoning</article-title>
          , MDPI, future internet (
          <year>2016</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>C. McGee</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Guo</surname>
            ,
            <given-names>Z. Wang,</given-names>
          </string-name>
          <article-title>The application of the graph laplacian in network forensics</article-title>
          ,
          <source>in: IEEE 12th Annual Information Technology, Electronics and Mobile Communication Conference (IEMCON)</source>
          ,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <source>[11] Case 001 - the stolen szechuan sauce</source>
          ,
          <year>2024</year>
          . URL: https://dfirmadness.com/ the-stolen
          <string-name>
            <surname>-</surname>
          </string-name>
          szechuan-sauce/, online, [cit. 2024-
          <volume>02</volume>
          - 18].
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <article-title>Magnet ctf 2019 windows desktop</article-title>
          ,
          <year>2019</year>
          . URL: https://digitalcorpora.s3.amazonaws.com/ corpora/scenarios/magnet/2019%20CTF%
          <fpage>20</fpage>
          -
          <lpage>%</lpage>
          20Windows-Desktop.zip, online, [cit. 2024-
          <volume>02</volume>
          -18].
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Magnet</surname>
          </string-name>
          ctf
          <year>2020</year>
          windows,
          <year>2020</year>
          . URL: https://digitalcorpora.s3.amazonaws.com/ corpora/scenarios/magnet/2020%20CTF%
          <fpage>20</fpage>
          -
          <lpage>%</lpage>
          20Windows.zip, online, [cit. 2024-
          <volume>02</volume>
          -18].
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Magnet</surname>
          </string-name>
          ctf
          <year>2022</year>
          windows,
          <year>2022</year>
          . URL: https://digitalcorpora.s3.amazonaws.com/ corpora/scenarios/magnet/2022%20CTF%
          <fpage>20</fpage>
          -
          <lpage>%</lpage>
          20Windows.zip, online, [cit. 2024-
          <volume>02</volume>
          -18].
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <source>[15] Data leakage case</source>
          ,
          <year>2024</year>
          . URL: https: //cfreds-archive.
          <article-title>nist.gov/data_leakage_case/ data-leakage-case.html, online</article-title>
          , [cit. 2024-
          <volume>02</volume>
          -18].
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Hacking</surname>
            <given-names>case</given-names>
          </string-name>
          ,
          <year>2024</year>
          . URL: https://cfreds-archive.nist. gov/Hacking_Case.html, online, [cit. 2024-
          <volume>02</volume>
          -18].
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>E.</given-names>
            <surname>Marková</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Sokol</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Kováčová</surname>
          </string-name>
          ,
          <article-title>Detection of relevant digital evidence in the forensic timelines</article-title>
          , in: International Conference on Electronics,
          <source>Computers and Artificial Intelligence (ECAI)</source>
          , IEEE,
          <year>2022</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>7</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Plaso</surname>
          </string-name>
          ,
          <year>2024</year>
          . URL: https://plaso.readthedocs.io/en/ latest, online, [cit. 2024-
          <volume>04</volume>
          -13].
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>E.</given-names>
            <surname>Marková</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Sokol</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. P.</given-names>
            <surname>Krišáková</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Kováčová</surname>
          </string-name>
          ,
          <article-title>Dataset of windows operating system forensics artefacts, Data in Brief (</article-title>
          <year>2024</year>
          )
          <fpage>110693</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>D. B. West</surname>
          </string-name>
          , Introduction to graph theory, Prentice hall,
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>B.</given-names>
            <surname>Brešar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Kardoš</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Katrenič</surname>
          </string-name>
          , G. Semanišin, Minimum
          <article-title>-path vertex cover</article-title>
          ,
          <source>DAM</source>
          <volume>159</volume>
          (
          <year>2011</year>
          )
          <fpage>1189</fpage>
          -
          <lpage>1195</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>G.</given-names>
            <surname>Zonneveld</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Principi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Baldi</surname>
          </string-name>
          ,
          <article-title>Using graph theory for improving machine learning-based detection of cyber attacks</article-title>
          ,
          <year>2024</year>
          . URL: https://arxiv. org/pdf/2402.07878.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>T.</given-names>
            <surname>Mézešová</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Sokol</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Bajtoš</surname>
          </string-name>
          ,
          <article-title>Evaluation of attackers' skill levels in multi-stage attacks</article-title>
          ,
          <source>Information</source>
          <volume>11</volume>
          (
          <year>2020</year>
          )
          <fpage>537</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>V. P.</given-names>
            <surname>Janeja</surname>
          </string-name>
          ,
          <article-title>Data Analytics for Cybersecurity, Chapter 9: Cybersecurity through Network and Graph Data</article-title>
          ,
          <year>2022</year>
          . URL: https://doi.org/10.1017/ 9781108231954.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>