Case-Based Reasoning in Live Forensics - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

Case-Based Reasoning in Live Forensics

Résumé

The traditional forensic search and seizure process employed by law enforcement is not always appropriate given large data volumes and the potential of hard drive encryption. This paper proposes a framework built on case-based reasoning to support a live forensic response during the search and seizure process. The framework assists a first responder by identifying the risks and the procedures to ensure the optimal collection of evidence based on prior cases. Test results demonstrate that the framework provides valuable assistance to first responders, reducing the time taken to complete a response and increasing the likelihood of a successful conclusion.
Fichier principal
Vignette du fichier
978-3-642-24212-0_6_Chapter.pdf (544.9 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01569564 , version 1 (27-07-2017)

Licence

Paternité

Identifiants

Citer

Bruno Hoelz, Celia Ralha, Frederico Mesquita. Case-Based Reasoning in Live Forensics. 7th Digital Forensics (DF), Jan 2011, Orlando, FL, United States. pp.77-88, ⟨10.1007/978-3-642-24212-0_6⟩. ⟨hal-01569564⟩
67 Consultations
421 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More