Yuandong Zhu

Learn More
(This!paper!expands!upon!the!finite!state! machine!approach!for!the!formal!analysis!of! digital!evidence.!The!proposed!method!may! be!used!to!support!the!feasibility!of!a!given! statement!by!testing!it!against!a!relevant! system!model.!To!achieve!this,!a!novel! method!for!modeling!the!system!and! evidential!statements!is!given.!The!method!(More)
Windows XP ShellBag information analysis Registry snapshots analysis a b s t r a c t Built into Microsoft Windows is the ability for the operating system to track user window viewing preferences specific to Windows Explorer. This information, which is called ''ShellBag'' information, is stored in several locations within the Windows Registry in the Windows(More)
This paper proposes a novel method for checking the consistency of forensic registry artifacts by gathering event information from the arti-facts and analyzing the event sequences based on the associated times-tamps. The method helps detect the use of counter-forensic techniques without focusing on one particular counter-forensic tool at a time. Several(More)
This paper introduces a novel approach to user event reconstruction by showing the practicality of generating and implementing signature-based analysis methods to reconstruct high-level user actions from a collection of low-level traces found during a post-mortem forensic analysis of a system. Traditional forensic analysis and the inferences an investigator(More)
The Microsoft Windows registry is an important resource in digital forensic investigations. It contains information about operating system configuration, installed software and user activity. Several researchers have focused on the forensic analysis of the Windows registry, but a robust method for associating past events with registry data values extracted(More)
The correct combat situation assessment is the first premise in air combat decision. In this paper, the writer adopts non-parameter and parameter method to review air combat situation assessment technology. The air combat situation assessment of non-parameter method is mainly discussed in the following several aspects: superiority functions, analytic(More)
This study was designed to perform an acceptable prognostic nomogram for acute myeloid leukemia. The clinical data from 311 patients from our institution and 165 patients generated with Cancer Genome Atlas Research Network were reviewed. A prognostic nomogram was designed according to the Cox's proportional hazard model to predict overall survival (OS). To(More)
  • 1