Performance of a Logical, Five- Phase, Multithreaded, Bootable Triage Tool

Abstract : This paper describes a five-phase, multi-threaded bootable approach to digital forensic triage, which is implemented in a product called Forensics2020. The first phase collects metadata for every logical file on the hard drive of a computer system. The second phase collects EXIF camera data from each image found on the hard drive. The third phase analyzes and categorizes each file based on its header information. The fourth phase parses each executable file to provide a complete audit of the software applications on the system; a signature is generated for every executable file, which is later checked against a threat detection database. The fifth and final phase hashes each file and records its hash value. All five phases are performed in the background while the first responder interacts with the system. This paper assesses the forensic soundness of Forensics2020. The tool makes certain changes to a hard drive that are similar to those made by other bootable forensic examination environments, although the changes are greater in number. The paper also describes the lessons learned from developing Forensics2020, which can help guide the development of other forensic triage tools.
Type de document :
Communication dans un congrès
Gilbert Peterson; Sujeet Shenoi. 10th IFIP International Conference on Digital Forensics (DF), Jan 2014, Vienna, Austria. Springer, IFIP Advances in Information and Communication Technology, AICT-433, pp.279-295, 2014, Advances in Digital Forensics X. 〈10.1007/978-3-662-44952-3_19〉
Liste complète des métadonnées

Littérature citée [17 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01393782
Contributeur : Hal Ifip <>
Soumis le : mardi 8 novembre 2016 - 10:51:35
Dernière modification le : vendredi 1 décembre 2017 - 01:17:01
Document(s) archivé(s) le : mardi 14 mars 2017 - 23:14:57

Fichier

978-3-662-44952-3_19_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Ibrahim Baggili, Andrew Marrington, Yasser Jafar. Performance of a Logical, Five- Phase, Multithreaded, Bootable Triage Tool. Gilbert Peterson; Sujeet Shenoi. 10th IFIP International Conference on Digital Forensics (DF), Jan 2014, Vienna, Austria. Springer, IFIP Advances in Information and Communication Technology, AICT-433, pp.279-295, 2014, Advances in Digital Forensics X. 〈10.1007/978-3-662-44952-3_19〉. 〈hal-01393782〉

Partager

Métriques

Consultations de la notice

175

Téléchargements de fichiers

25