🤖 AI Summary
Modern cybersecurity threats and the proliferation of heterogeneous binary artifacts challenge existing digital forensics approaches in interpretability, scalability, and human–machine collaboration efficiency.
Method: This paper introduces an open-source binary forensics framework that integrates multi-granularity visualization, semantic modeling, large language model (LLM)-driven dynamic reasoning, and a predicate logic rule engine to establish a scalable, multi-tiered analytical architecture. Crucially, it proposes an LLM-augmented neuro-symbolic reasoning mechanism—uniquely combining symbolic logic with neural inference—to generate interpretable, semantically grounded recommendations regarding document content and user behavior.
Contribution/Results: The framework bridges industrial practice and academic research, empirically demonstrating significant improvements in forensic workflow efficiency. It has already enabled multiple high-impact publications and supports ongoing research, including several manuscripts under preparation.
📝 Abstract
Cybersecurity threats continue to become more sophisticated and diverse in their artifacts, boosting both their volume and complexity. To overcome those challenges, we present GView, an open-source forensic analysis framework with visual and AI-enhanced reasoning. It started with focus on the practical cybersecurity industry. It has evolved significantly, incorporating large language models (LLMs) to dynamically enhance reasoning and ease the forensic workflows. This paper surveys both the current state of GView with its published papers alongside those that are in the publishing process. It also includes its innovative use of logical inference through predicates and inference rules for both the analyzed documents and the user's actions for better suggestions. We highlight the extensible architecture, showcasing its potential as a bridge between the practical forensics worlds with the academic research.