{"id":{"repo_id":"southwales","oai_identifier":"oai:pure.atira.dk:studenttheses/5353fcdd-018f-482f-87e5-2af09d7bec64"},"canonical_url":"https://search.dev.ndltd.org/etd/southwales/oai:pure.atira.dk:studenttheses/5353fcdd-018f-482f-87e5-2af09d7bec64","repository":{"repo_id":"southwales","name":"University of South Wales","base_url":"https://pure.southwales.ac.uk/ws/oai"},"display":{"title":"An exploration into overlooked areas of forensics data analysis, case management and metadata using automation and natural language processing","abstract":"As computer components keeps getting cheaper and more affordable, while also getting better, faster and with more capacity, it negatively impacts digital forensic investigations by the increasing complexity which comes from information overload. Finding correlations, patterns and critical evidence in digital evidence of today’s data sizes of hundreds to thousands of gigabytes is becoming increasingly difficult. Current literature show attempts at addressing these issues, but there is still a big gap between the current state and current need to solve this efficiently.<br/><br/>The work presented in this portfolio introduced novel approaches to (1) handling case management and metadata of any size automatically and present it using distributed interface. (2) automatic analysis of large-scale email communications using machine learning to give unique insights in graph form. (3) automatic preparation of custodian activity correlation and document content (entity) correlation for use in graph-based and timeline-based correlation visualizations. To develop these insights, the use of the computational genre of design science research development methodology and (b) agile development methodology was used, allowing for iterative and cycle-based development. <br/><br/>The research revealed that there are several areas of digital forensics which are overlooked by the digital forensics research community, even more than those covered by the portfolio. It also revealed that the use of data science, mathematics and iterative development methodologies can provide solutions to the issues found in these overlooked areas. <br/><br/>An important implication of this work is the emergent discovery of how these overlooked areas of digital forensics can easily integrate into a grand framework for digital forensic investigations. Instead of having random research projects, some crossing areas with others, some helping others develop, the grand framework design introduces a more community driven approach to a coherent integration across several research areas. This portfolio marks the introduction and beginning of this grand framework but there are more research areas, and this framework can grow much larger than what presented here.<br/>","abstract_html":"As computer components keeps getting cheaper and more affordable, while also getting better, faster and with more capacity, it negatively impacts digital forensic investigations by the increasing complexity which comes from information overload. Finding correlations, patterns and critical evidence in digital evidence of today’s data sizes of hundreds to thousands of gigabytes is becoming increasingly difficult. Current literature show attempts at addressing these issues, but there is still a big gap between the current state and current need to solve this efficiently.&lt;br/&gt;&lt;br/&gt;The work presented in this portfolio introduced novel approaches to (1) handling case management and metadata of any size automatically and present it using distributed interface. (2) automatic analysis of large-scale email communications using machine learning to give unique insights in graph form. (3) automatic preparation of custodian activity correlation and document content (entity) correlation for use in graph-based and timeline-based correlation visualizations. To develop these insights, the use of the computational genre of design science research development methodology and (b) agile development methodology was used, allowing for iterative and cycle-based development. &lt;br/&gt;&lt;br/&gt;The research revealed that there are several areas of digital forensics which are overlooked by the digital forensics research community, even more than those covered by the portfolio. It also revealed that the use of data science, mathematics and iterative development methodologies can provide solutions to the issues found in these overlooked areas. &lt;br/&gt;&lt;br/&gt;An important implication of this work is the emergent discovery of how these overlooked areas of digital forensics can easily integrate into a grand framework for digital forensic investigations. Instead of having random research projects, some crossing areas with others, some helping others develop, the grand framework design introduces a more community driven approach to a coherent integration across several research areas. This portfolio marks the introduction and beginning of this grand framework but there are more research areas, and this framework can grow much larger than what presented here.&lt;br/&gt;","abstract_has_math":false,"creators":["Nor, Glenn"],"institution":null,"degree_name":"Doctoral Thesis","degree_level":"Student thesis","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Abuhmida, Mabrouka","Llewellyn, Eric"],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024","date_published":"2024","updated_at":"2026-07-24T04:39:51Z","subjects":["Computer forensics","Digital evidence","Digital forensic","Natural Language Processing","Machine Learning","Automation","Metadata","Sentiment Analysis","Named Entity Recognition","Case manadement","Email analysis"],"languages":["eng"],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:pure.atira.dk:studenttheses/5353fcdd-018f-482f-87e5-2af09d7bec64"],"render_values":[{"text":"oai:pure.atira.dk:studenttheses/5353fcdd-018f-482f-87e5-2af09d7bec64","href":null,"code":true}]}]},"links":{"outbound_url":"https://pure.southwales.ac.uk/en/studentTheses/5353fcdd-018f-482f-87e5-2af09d7bec64","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Abuhmida, Mabrouka","Llewellyn, Eric"]},{"key":"dc:creator","label":"Author","values":["Nor, Glenn"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2024"]},{"key":"dc:date.issued","label":"Date","values":["2024"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://pure.southwales.ac.uk/en/studentTheses/5353fcdd-018f-482f-87e5-2af09d7bec64"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Student thesis"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["Doctoral Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Computer forensics","Digital evidence","Digital forensic","Natural Language Processing","Machine Learning","Automation","Metadata","Sentiment Analysis","Named Entity Recognition","Case manadement","Email analysis"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:pure.atira.dk:studenttheses/5353fcdd-018f-482f-87e5-2af09d7bec64","https://pure.southwales.ac.uk/en/studentTheses/5353fcdd-018f-482f-87e5-2af09d7bec64"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://pure.southwales.ac.uk/files/25818281/PhD_by_Portfolio_Glenn_Nor.pdf"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["As computer components keeps getting cheaper and more affordable, while also getting better, faster and with more capacity, it negatively impacts digital forensic investigations by the increasing complexity which comes from information overload. Finding correlations, patterns and critical evidence in digital evidence of today’s data sizes of hundreds to thousands of gigabytes is becoming increasingly difficult. Current literature show attempts at addressing these issues, but there is still a big gap between the current state and current need to solve this efficiently.<br/><br/>The work presented in this portfolio introduced novel approaches to (1) handling case management and metadata of any size automatically and present it using distributed interface. (2) automatic analysis of large-scale email communications using machine learning to give unique insights in graph form. (3) automatic preparation of custodian activity correlation and document content (entity) correlation for use in graph-based and timeline-based correlation visualizations. To develop these insights, the use of the computational genre of design science research development methodology and (b) agile development methodology was used, allowing for iterative and cycle-based development. <br/><br/>The research revealed that there are several areas of digital forensics which are overlooked by the digital forensics research community, even more than those covered by the portfolio. It also revealed that the use of data science, mathematics and iterative development methodologies can provide solutions to the issues found in these overlooked areas. <br/><br/>An important implication of this work is the emergent discovery of how these overlooked areas of digital forensics can easily integrate into a grand framework for digital forensic investigations. Instead of having random research projects, some crossing areas with others, some helping others develop, the grand framework design introduces a more community driven approach to a coherent integration across several research areas. This portfolio marks the introduction and beginning of this grand framework but there are more research areas, and this framework can grow much larger than what presented here.<br/>"]},{"key":"dc:title","label":"Title","values":["An exploration into overlooked areas of forensics data analysis, case management and metadata using automation and natural language processing"]}]}],"canonical_facts":{"dc:contributor.advisor":["Abuhmida, Mabrouka","Llewellyn, Eric"],"dc:creator":["Nor, Glenn"],"dc:date":["2024"],"dc:date.issued":["2024"],"dc:description.abstract":["As computer components keeps getting cheaper and more affordable, while also getting better, faster and with more capacity, it negatively impacts digital forensic investigations by the increasing complexity which comes from information overload. Finding correlations, patterns and critical evidence in digital evidence of today’s data sizes of hundreds to thousands of gigabytes is becoming increasingly difficult. Current literature show attempts at addressing these issues, but there is still a big gap between the current state and current need to solve this efficiently.<br/><br/>The work presented in this portfolio introduced novel approaches to (1) handling case management and metadata of any size automatically and present it using distributed interface. (2) automatic analysis of large-scale email communications using machine learning to give unique insights in graph form. (3) automatic preparation of custodian activity correlation and document content (entity) correlation for use in graph-based and timeline-based correlation visualizations. To develop these insights, the use of the computational genre of design science research development methodology and (b) agile development methodology was used, allowing for iterative and cycle-based development. <br/><br/>The research revealed that there are several areas of digital forensics which are overlooked by the digital forensics research community, even more than those covered by the portfolio. It also revealed that the use of data science, mathematics and iterative development methodologies can provide solutions to the issues found in these overlooked areas. <br/><br/>An important implication of this work is the emergent discovery of how these overlooked areas of digital forensics can easily integrate into a grand framework for digital forensic investigations. Instead of having random research projects, some crossing areas with others, some helping others develop, the grand framework design introduces a more community driven approach to a coherent integration across several research areas. This portfolio marks the introduction and beginning of this grand framework but there are more research areas, and this framework can grow much larger than what presented here.<br/>"],"dc:identifier":["oai:pure.atira.dk:studenttheses/5353fcdd-018f-482f-87e5-2af09d7bec64","https://pure.southwales.ac.uk/en/studentTheses/5353fcdd-018f-482f-87e5-2af09d7bec64"],"dc:identifier.uri":["https://pure.southwales.ac.uk/files/25818281/PhD_by_Portfolio_Glenn_Nor.pdf"],"dc:language":["eng"],"dc:relation.isreferencedby":["https://pure.southwales.ac.uk/en/studentTheses/5353fcdd-018f-482f-87e5-2af09d7bec64"],"dc:subject":["Computer forensics","Digital evidence","Digital forensic","Natural Language Processing","Machine Learning","Automation","Metadata","Sentiment Analysis","Named Entity Recognition","Case manadement","Email analysis"],"dc:title":["An exploration into overlooked areas of forensics data analysis, case management and metadata using automation and natural language processing"],"dc:type":["Thesis"],"dc:type.qualificationlevel":["Student thesis"],"dc:type.qualificationname":["Doctoral Thesis"]},"updated_at":"2026-07-24T04:39:51Z"}