Article thumbnail

Supporting Process Mining with Recovered Residual Data

By Ludwig Englbrecht, Stefan Schönig and Günther Pernul

Abstract

Understanding how workflows are actually carried out within an organisation can provide a crucial contribution to business process improvement. This paper presents a concept for reconstructing a business process by using file residuals on a hard-drive and without the need for existing event logs. Thereby, methods from the area of process mining are enriched with approaches from digital forensics investigations in a Digital Trace Miner. First, a framework that extracts traces originating from business process execution based on residual data is developed in order to link them to the processes. The traces from the extraction are used in a life-cycle to keep related data up-to-date. This approach has been implemented and evaluated by a prototype. The evaluation shows that this approach enables useful insights regarding the tasks performed on a suspect computer by associating recovered files by using file-carving mechanisms

Topics: 000 Allgemeines, Wissenschaft, ddc:000
Publisher: 'Springer Science and Business Media LLC'
Year: 2020
DOI identifier: 10.1007/978-3-030-63479-7_27
OAI identifier: oai:epub.uni-regensburg.de:43677
Download PDF:
Sorry, we are unable to provide the full text but you may find it at the following location(s):
  • http://orcid.org/0000-0002-854... (external link)
  • https://epub.uni-regensburg.de... (external link)
  • Suggested articles


    To submit an update or takedown request for this paper, please submit an Update/Correction/Removal Request.