30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

and TC-18, AIR has outper<strong>for</strong>med other two disk imaging tools. AIR was able to<br />

provide accurate and complete result in those test cases. The accuracy <strong>of</strong> the result is<br />

essential <strong>for</strong> disk imaging tools. Lawyers can challenge the validity <strong>of</strong> the disk<br />

imaging tools and dismiss the relevant evidence if the <strong>for</strong>ensic investigator per<strong>for</strong>med<br />

data acquisition by using an improperly validated tool. This hypothesis is not in line<br />

with author‟s speculation.<br />

5.3 CONCLUSION<br />

This Chapter discusses the findings based on the data collected from the evaluation <strong>of</strong><br />

the disk imaging tools. Testing environment and procedures are discussed as two<br />

important elements <strong>of</strong> the disk imaging tools validation. These two elements have a<br />

direct impact on the quality and accuracy <strong>of</strong> the evaluation result. The significance <strong>of</strong><br />

the test cases is discussed <strong>for</strong> each individual tool. The focus <strong>of</strong> the discussion <strong>of</strong> each<br />

tool is on the failed test cases. The analysis <strong>of</strong> possible reasons why the tool failed in<br />

the particular test cases provides key findings.<br />

Research challenges are discussed with regards to various problem areas. The<br />

availability <strong>of</strong> the configuration tools <strong>for</strong> the testing environment was limited and it<br />

restricted the ability to run different types <strong>of</strong> test cases <strong>for</strong> the research. Wider range<br />

and types <strong>of</strong> test cases could improve the accuracy and completeness <strong>of</strong> the research.<br />

The discussion <strong>of</strong> the challenges posed by using the Linux <strong>Forensic</strong>s Live CDs can<br />

alert other researchers if they intend to conduct similar type <strong>of</strong> research.<br />

The findings <strong>of</strong> the tools testing imply that the testing requirements,<br />

configuration and the per<strong>for</strong>mance <strong>of</strong> the disk imaging tools are closely linked. The<br />

research found the per<strong>for</strong>mance <strong>of</strong> the disk imaging tools are vary from case to case.<br />

Hypotheses 2 and 3 are not in line with the author‟s original speculation. AIR is<br />

outper<strong>for</strong>med than other two disk imaging tools and Helix 3 Pro per<strong>for</strong>med the worst<br />

among three tools. The author was speculating that Helix 3 pro would per<strong>for</strong>m better<br />

because <strong>of</strong> its reputation and the rich functionalities provided. Apart from the research<br />

model depicted in Figure 3.7, the research also investigate the usability <strong>of</strong> the tools.<br />

Problems concerning the usability <strong>of</strong> the tools are discussed in sections from 5.1.3 to<br />

5.1.5.<br />

112

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!