30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

4.4 PRESENTATION OF FINDINGS<br />

A summary <strong>of</strong> the field findings <strong>of</strong> section 4.2 is presented in graphic <strong>for</strong>m to help the<br />

reader understand the test results better. The evaluation results <strong>of</strong> the three evaluated<br />

tools are presented as a bar chart in Figure 4.4.<br />

Figures 4.1 to 4.3 represent the individual evaluation results <strong>of</strong> tools FTK<br />

Imager, Helix 3 Pro and AIR in the test cases that were applied to them. As mentioned<br />

previously, each tool may have different test cases specifically applied. There<strong>for</strong>e, the<br />

test result <strong>of</strong> each tool is presented in their individual figure. Figure 4.4 is a<br />

comparison chart <strong>of</strong> the results obtained <strong>for</strong> three evaluated tools in each <strong>of</strong> test cases.<br />

The number <strong>of</strong> test cases per<strong>for</strong>med <strong>for</strong> each tool depends on the functions that the<br />

tool provided. FTK Imager had 18 test cases tested versus 15 test cases <strong>for</strong> Helix 3 Pro<br />

and AIR. The horizontal axis in Figure 4.1 to 4.3 represents the test cases that applied<br />

to each individual tool. The horizontal axis in Figure 4.4 represents the test cases that<br />

tested all three tested disk imaging tools. The vertical axis in Figure 4.1 to 4.4<br />

represents the pass rate <strong>of</strong> all test cases in percentage. The percentage is derived from<br />

the total number <strong>of</strong> passed assertions divided by the total number <strong>of</strong> tested assertions.<br />

Figure 4.1 indicates that FTK Imager passed many test cases with 100% pass rate and<br />

its worst per<strong>for</strong>mance was in test case TC-12(2). According to Figure 4.2, Helix 3 Pro<br />

did not achieve 100% pass rate and in three <strong>of</strong> the test cases, namely TC-12(1), TC-<br />

12(2) and TC-16(1), it had a pass rate lower than 35% pass rate. Figure 4.3 shows that<br />

AIR reached over 75% pass rate overall per<strong>for</strong>mance across all applied test cases.<br />

Figure 4.4 indicates that FTK Imager and AIR outper<strong>for</strong>m Helix 3 Pro. Helix 3 Pro<br />

has lower than 35% pass rate in three tests, whereas AIR has more than 75% <strong>of</strong> pass<br />

rate in every test case and FTK Imager has average pass rate over 70%. The overall<br />

pass rate in the common test cases indicates AIR outper<strong>for</strong>ms FTK Imager and Helix 3<br />

Pro.<br />

90

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!