30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

eginning <strong>of</strong> and the end <strong>of</strong> the disk imaging to ensure that no data from previous use<br />

is still remained. The mechanism used to reset the test drive is developed by<br />

Department <strong>of</strong> the Defense <strong>of</strong> America. Tableau Write Blocker is utilised consistently<br />

(where applied) to ensure no accidentally write attempt to the test drive. Every result is<br />

also verified again using EnCase to ensure the extracted data are identical to the source.<br />

To answer the SQ3 specified in section 3.2, this study has developed a way to rank the<br />

disk imaging tools according to their per<strong>for</strong>mance. Each disk imaging tool is<br />

undergoes a series <strong>of</strong> test cases and each test case composes a set <strong>of</strong> assertions. The<br />

assertions will be tested and marked either pass or fail. The pass rate is calculated by<br />

using the total number passed assertions to divide the total number <strong>of</strong> assertions in the<br />

test case. The tools are then ranked according to their overall pass rate in all test cases.<br />

Section 5.2 describes and discusses the results <strong>of</strong> the hypotheses testing. To<br />

answer the main research question, the testing results indicate that AIR per<strong>for</strong>med<br />

better than or equal to the other two disk imaging tools in most <strong>of</strong> the common test<br />

cases. Helix 3 Pro per<strong>for</strong>med worse than other two disk imaging tools and Helix 3 Pro<br />

also presented many problems. It is recommended that the disk imaging tools must be<br />

fully validated and verified as extensively as possible. The tool testing must be<br />

conducted in different configurations and different execution environments.<br />

6.3 AREAS OF FUTURE RESEARCH<br />

Current digital <strong>for</strong>ensic tools are unable to keep pace with the growing complexity and<br />

rapid evolution <strong>of</strong> technology in the contemporary digital environment (Roussev &<br />

Richard, 2004; Ayers, 2009). Building a systematic and scientifically proven<br />

methodology to validate the functions <strong>of</strong> the digital <strong>for</strong>ensics tool is a demanding job.<br />

What has been achieved by CFTT, DFTT and other researchers can be used as<br />

stepping stone to building a comprehensive testing framework. The framework must<br />

be automated, tool-independent and future-pro<strong>of</strong>. <strong>Disk</strong> imaging is an important<br />

constituent <strong>of</strong> the evidence collection in the digital <strong>for</strong>ensics investigative process,<br />

according to DFRWS investigative process described in section 2.1.2. Activities such<br />

as examination, analysis and presentation are also crucial <strong>for</strong> the digital <strong>for</strong>ensics<br />

investigation. Different test scenarios with different hardware types can be imposed on<br />

118

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!