Testing the forensic soundness of forensic examination environments on bootable media

نویسندگان

  • Ahmed Fathy Abdul Latif Mohamed
  • Andrew Marrington
  • Farkhund Iqbal
  • Ibrahim M. Baggili
چکیده

In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is performed on the image files. The differential analysis allows us to quantify and explain the alterations made to the image files by the bootable CD/DVD examination. Our approach can be used to experimentally validate new bootable CD/DVD distributions as forensically sound. © 2014 Digital Forensics Research Workshop. Published by Elsevier Ltd. All rights reserved.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Computer Forensics Field Triage Process Model

With the proliferation of digital based evidence, the need for the timely identification, analysis and interpretation of digital evidence is becoming more crucial. In many investigations critical information is required while at the scene or within a short period of time measured in hours as opposed to days. The traditional cyber forensics approach of seizing a system(s)/media, transporting it ...

متن کامل

[Disease--defence--manipulation: the difficulties in providing forensic-psychiatry opinions].

The challenges met by the psychiatrist and the psychologist and the difficulties in providing forensic-psychiatry and forensic-psychology opinions have been reviewed, based on examples. The studied patient was hospitalised 10 times and the forensic-psychiatry opinion passed 15 times during the judiciary process. Different psychiatric diagnoses were made and different soundness of mind were pass...

متن کامل

How Virtualized Environments Affect Computer Forensics

Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the ...

متن کامل

Live Forensic Acquisition as Alternative to Traditional Forensic Processes

The development of live forensic acquisition in general presents a remedy for some of the problems introduced by traditional forensic acquisition. However, this live forensic acquisition introduces a variety of additional problems, unique to this discipline. This paper presents current research with regards to the forensic soundness of evidence retrieved through live forensic acquisition. The r...

متن کامل

Forensic Examination of CCTV Digital VTR Surveillance Recording Equipment

Approximately two years ago I authored a paper entitled, “The Forensic Examination of Video Recordings” which discussed some of the more conventional forensic techniques for examining questioned analog videotapes regarding their originality and for possible evidence of tape alteration. This paper specifically addressed the various mechanical and electrical signal anomalies that occur when editi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • Digital Investigation

دوره 11  شماره 

صفحات  -

تاریخ انتشار 2014