Testing the forensic soundness of forensic examination environments on bootable media
نویسندگان
چکیده
In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is performed on the image files. The differential analysis allows us to quantify and explain the alterations made to the image files by the bootable CD/DVD examination. Our approach can be used to experimentally validate new bootable CD/DVD distributions as forensically sound. © 2014 Digital Forensics Research Workshop. Published by Elsevier Ltd. All rights reserved.
منابع مشابه
Computer Forensics Field Triage Process Model
With the proliferation of digital based evidence, the need for the timely identification, analysis and interpretation of digital evidence is becoming more crucial. In many investigations critical information is required while at the scene or within a short period of time measured in hours as opposed to days. The traditional cyber forensics approach of seizing a system(s)/media, transporting it ...
متن کامل[Disease--defence--manipulation: the difficulties in providing forensic-psychiatry opinions].
The challenges met by the psychiatrist and the psychologist and the difficulties in providing forensic-psychiatry and forensic-psychology opinions have been reviewed, based on examples. The studied patient was hospitalised 10 times and the forensic-psychiatry opinion passed 15 times during the judiciary process. Different psychiatric diagnoses were made and different soundness of mind were pass...
متن کاملHow Virtualized Environments Affect Computer Forensics
Virtualized environments can make forensics investigation more difficult. Technological advances in virtualization tools essentially make removable media a PC that can be carried around in a pocket or around a neck. Running operating systems and applications this way leaves very little trace on the host system. This paper will explore all the newest methods for virtualized environments and the ...
متن کاملLive Forensic Acquisition as Alternative to Traditional Forensic Processes
The development of live forensic acquisition in general presents a remedy for some of the problems introduced by traditional forensic acquisition. However, this live forensic acquisition introduces a variety of additional problems, unique to this discipline. This paper presents current research with regards to the forensic soundness of evidence retrieved through live forensic acquisition. The r...
متن کاملForensic Examination of CCTV Digital VTR Surveillance Recording Equipment
Approximately two years ago I authored a paper entitled, “The Forensic Examination of Video Recordings” which discussed some of the more conventional forensic techniques for examining questioned analog videotapes regarding their originality and for possible evidence of tape alteration. This paper specifically addressed the various mechanical and electrical signal anomalies that occur when editi...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Digital Investigation
دوره 11 شماره
صفحات -
تاریخ انتشار 2014