Using Self-Organising Maps for Anomalous Behaviour Detection in a Computer Forensic Investigation

Fei, Eloff, Olivier, Tillwick, and Venter


Citation information

B. K. L. Fei, J. H. P. Eloff, M. S. Olivier, H. M. Tillwick, and H. S. Venter. Using self-organising maps for anomalous behaviour detection in a computer forensic investigation. In H. S. Venter, J. H. P. Eloff, L. Labuschagne, and M. M. Eloff, editors, Proceedings of the Fifth Annual Information Security South Africa Conference (ISSA2005), Sandton, South Africa, 6 2005a. Research in progress paper, published electronically


The dramatic increase in crime relating to the Internet and computers has caused a growing need for computer forensics. Computer forensic tools have been developed to assist computer forensic investigators in conducting a proper investigation into digital crimes. In general, the bulk of the computer forensic tools available on the market permit investigators to analyse data that has been gathered from a computer system. However, current state-of-the-art computer forensic tools simply cannot handle large volumes of data in an efficient manner. With the advent of the Internet, many employees have been given access to new and more interesting possibilities via their desktop. Consequently, excessive Internet usage for non-job purposes and even blatant misuse of the Internet (such as employees accessing Web sites that promote pornography and other illegal activities) have become a problem in many organisations. Since storage media are steadily growing in size, the process of analysing multiple computer systems during a digital investigation can easily consume an enormous amount of time. Identifying a single suspicious computer from a set of candidates can therefore reduce human processing time and/or reduce the monetary costs involved in gathering evidence.

The focus of this paper is to demonstrate how, in a digital investigation, computer forensic tools and the self-organising map (SOM) an unsupervised neural network model can aid computer forensic investigators to determine anomalous behaviours (or activities) among employees (or computer systems) in a far more efficient manner. By analysing the different SOMs (one for each computer system), anomalous behaviours are identified and investigators are assisted to conduct the analysis more efficiently. The paper will demonstrate how the easy visualisation of the SOM enhances the ability of the investigators to interpret and explore the data generated by computer forensic tools so as to determine anomalous behaviours.

Full text

A pre- or postprint of the publication is available at

BibTeX reference

AUTHOR={Bennie K L Fei and Jan H P Eloff and Martin S Olivier and Heiko M Tillwick and Hein S Venter},
TITLE={Using Self-Organising Maps for Anomalous Behaviour Detection in a Computer Forensic Investigation},
BOOKTITLE={Proceedings of the Fifth Annual Information Security South Africa Conference (ISSA2005)},
EDITOR={Hein S Venter and Jan H P Eloff and Les Labuschagne and Mariki M Eloff},
ADDRESS={Sandton, South Africa},
NOTE={Research in progress paper, published electronically} )

[Publications] [Home]
Page maintained by Martin Olivier
Record refreshed: January 16, 2018

Beta version of new bibliography database; please report errors (or copyright violations) that may have slipped in.