Rapid forensic imaging of large disks with sifting collectors
نویسندگان
چکیده
We present a new approach to digital forensic evidence acquisition and disk imaging called sifting collectors that images only those regions of a disk with expected forensic value. Sifting collectors produce a sector-by-sector, bit-identical AFF v3 image of selected disk regions that can be mounted and is fully compatible with existing forensic tools and methods. In our test cases, they have achieved an acceleration of >3 while collecting >95% of the evidence, and in some cases we have observed acceleration of up to 13 . Sifting collectors challenge many conventional notions about forensic acquisition and may help tame the volume challenge by enabling examiners to rapidly acquire and easily store large disks without sacrificing the many benefits of imaging. © 2015 The Authors. Published by Elsevier Ltd on behalf of DFRWS. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/
منابع مشابه
Immunohistochemical Expression of p53 and bcl2 in Colorectal Adenomas and Carcinomas Using Automated Cellular Imaging System
Background & Objective: The current approaches to reduce the risk of colorectal carcinoma are through the detection and removal of the precursor lesion” adenomatous polyps”. The study was conducted to evaluate the immunohistochemical expression of p53 and bcl2 in colorectal adenomas and carcinomas. Patients and Methods: A total of 86 cases, 33 colorectal adenomas, 33 colorect...
متن کاملLow Budget Forensic Drive Imaging Using ARM Based Single Board Computers
Traditional forensic analysis of hard disks and external media typically involves a “dead analysis” of a powered down machine. Forensic acquisition of hard drives and external media has traditionally been accomplished by one of several means: standalone forensic duplicator; using a hardware write-blocker or dock attached to a laptop, computer, workstation, etc.; forensic operating systems that ...
متن کاملDigital Forensics as a Big Data Challenge
Digital Forensics, as a science and part of the forensic sciences, is facing new challenges that may well render established models and practices obsolete. The dimensions of potential digital evidence supports has grown exponentially, be it hard disks in desktop and laptops or solid state memories in mobile devices like smartphones and tablets, even while latency times lag behind. Cloud service...
متن کاملThe Impact of MD5 File Hash Collisions On Digital Forensic Imaging
The Message Digest 5 (MD5) hash is commonly used as for integrity verification in the forensic imaging process. The ability to force MD5 hash collisions has been a reality for more than a decade, although there is a general consensus that hash collisions are of minimal impact to the practice of computer forensics. This paper describes an experiment to determine the results of imaging two disks ...
متن کاملRapid Death Due to Alcohol Withdrawal Syndrome: Case Report and Review of Literature
Background: Alcohol withdrawal syndrome (AWS) is one of the most serious complications associated with chronic alcoholism. Sudden deaths are not uncommon in AWS. In severe stages of AWS, delirium tremens (DT) occurs, which is characterized with agitation, global confusion, disorientation, visual and auditory hallucinations in addition to autonomic hyperactivity. Case report: A 30-year old man, ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Digital Investigation
دوره 14 شماره
صفحات -
تاریخ انتشار 2015