Research Article

CBR-Based Decision Support Methodology for Cybercrime Investigation: Focused on the Data-Driven Website Defacement Analysis

Table 4

Further characteristics and metadata associated with the DS and SPE cases.

Retrieved caseTested cases
Case nameNotifier
DarkSeoul (DS)Hmei7d3b_XStifLer

EncodingWindows-1252Windows-1252Windows-1252ISO-8859-9
IP address203.248.195.178203.86.238.68203.124.37.6677.92.108.3
Domaingyunggi.onnet21.comhttp://www.garycheng.comhealth.ajk.gov.pkyapikimyasallari.com.tr
Date20 Mar 20136 Feb 20144 Feb 20148 Jun 2013
OSWindowsWindowsWindowsWindows
Similarity0.6900.6750.665
Cluster084

Retrieved caseTested cases
Case nameNotifier
Sony pictures Entertainment (SPE)OaddahM@TRiXEL_MuHaMMeD
EncodingEUC-KR, EUC-CNGB2312GB2312GB2312
IP address203.131.222.102203.124.15.55208.29.19.8208.116.45.34
Domainhttp://www.sonypicturesstockfootage.comhttp://www.hzkcgg.comdax.digitalrom.comdigitalairstrip.net
Date24 Nov 201414 Jun 201216 Dec 200218 June 2009
OSWindowsWindowsWindowsWindows
Similarity0.6150.6150.600
Cluster777

The metadata are arranged according to the defined case vector, corresponding with the DS and SPE cases on the left side (shown in part in boldface type).