Feedback

Faculté des Sciences appliquées
Faculté des Sciences appliquées
Mémoire

Master thesis : UniForeXT: A Unified Data Model for Cross-Tool Integration in Digital Forensic Triage

Télécharger
Robert, Louan ULiège
Promoteur(s) : Donnet, Benoît ULiège
Date de soutenance : 29-jui-2026/30-jui-2026 • URL permanente : http://hdl.handle.net/2268.2/26068
Détails
Titre : Master thesis : UniForeXT: A Unified Data Model for Cross-Tool Integration in Digital Forensic Triage
Titre traduit : [fr] UniForeXT : un modèle unifié pour l'intégration inter-outils dans le triage en forensique numérique
Auteur : Robert, Louan ULiège
Date de soutenance  : 29-jui-2026/30-jui-2026
Promoteur(s) : Donnet, Benoît ULiège
Membre(s) du jury : Debruyne, Christophe ULiège
Mathy, Laurent ULiège
Langue : Anglais
Nombre de pages : 109
Mots-clés : [en] forensics
[en] incident triage
[en] DFIR
[en] Heterogeneous data integration
[en] knowledge graph
[en] ontology
[en] Cybersecurity data engineering
[en] uniforext
[en] forensic data integration
[en] digital forensics
[fr] informatique légale
[fr] forensique
[fr] tri des incidents
[fr] dfir
[fr] Cybersécurité
Discipline(s) : Ingénierie, informatique & technologie > Sciences informatiques
Commentaire : This master thesis was completed in collaboration with the Center for Cybersecurity Belgium.
Institution(s) : Université de Liège, Liège, Belgique
Diplôme : Master en sciences informatiques, à finalité spécialisée en "computer systems security"
Faculté : Mémoires de la Faculté des Sciences appliquées

Résumé

[en] The heterogeneous outputs of specialized forensic tools are a bottleneck in digital forensics and incident response (DFIR) triage. This thesis introduces UniForeXT, a tool-agnostic framework that consolidates diverse forensic artifacts into a unified, searchable knowledge graph, to accelerate triage workflows. UniForeXT comprises three integrated components: (1) a lightweight ontology that models forensic entities (e.g., detections, events, processes, users, hosts, etc.) using controlled vocabularies, (2) a YAML-to-RDF mapping tool driven by configuration and implemented in Java that generates an RDF graph and validates output using SHACL shapes, and (3) a UniForeXT tailored JavaFX/HTML visualization client that offers five complementary views to support analysis from an overview to a drill-down. Evaluation on realistic CERT Belgium datasets shows ingestion of ~500 MB in ~31 seconds and full SHACL validation in ~2 minutes (both run offline, ahead of analysis). Representative triage queries return in under 300 ms. Future directions include web-based, multi-user visualization, entity reconciliation, RML/YARRLM interoperability, LLM-assisted workflows, and broader user studies. UniForeXT demonstrates that ontology-driven integration, pragmatic mapping, and purposeful visualization can reduce forensic fragmentation and are likely to improve triage efficiency.


Fichier(s)

Document(s)

File
Access master-thesis-louan-robert.pdf
Description:
Taille: 2.69 MB
Format: Adobe PDF
File
Access abstract.pdf
Description:
Taille: 200.09 kB
Format: Adobe PDF

Annexe(s)

File
Access UniForeXT-code.zip
Description: The complete source code associated with this thesis. The repository is also available online and can be accessed on GitHub, see the linked URLs.
Taille: 483.99 kB
Format: Unknown

Auteur

  • Robert, Louan ULiège Université de Liège > Master sc. inform. fin. spéc. comput. syst. secur.

Promoteur(s)

Membre(s) du jury

  • Debruyne, Christophe ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Représentation et ingénierie des données
    ORBi Voir ses publications sur ORBi
  • Mathy, Laurent ULiège Université de Liège - ULiège > Dép. d'électric., électron. et informat. (Inst.Montefiore) > Systèmes informatiques répartis et sécurité
    ORBi Voir ses publications sur ORBi








Tous les documents disponibles sur MatheO sont protégés par le droit d'auteur et soumis aux règles habituelles de bon usage.
L'Université de Liège ne garantit pas la qualité scientifique de ces travaux d'étudiants ni l'exactitude de l'ensemble des informations qu'ils contiennent.