30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

producing unreliable results. Extra verification should be conducted over the acquired<br />

data with the application <strong>of</strong> another well-tested tool.<br />

Three disk imaging tools were tested against different test scenarios. The per<strong>for</strong>mance<br />

<strong>of</strong> each evaluated tool varies. AIR has achieved higher overall pass rate than the<br />

others, followed by FTK Imager. Helix 3 Pro has not achieved 100% pass rate in any<br />

test cases (see Section 5.1.3 <strong>for</strong> more details). During the acquisition <strong>of</strong> HPA or DCO<br />

hidden areas, none <strong>of</strong> the evaluated disk imaging tools was able to acquire the hidden<br />

areas (see testing results in Sections 4.2.2.3 and 4.2.2.10). Helix 3 Pro has presented<br />

problems in some test cases. Some usability problems were observed and discussed as<br />

well. Better usability will improve the user experience <strong>of</strong> the s<strong>of</strong>tware. The disk<br />

imaging tool AIR also presented a few problems both in terms <strong>of</strong> usability and<br />

per<strong>for</strong>mance (see discussion in Section 5.1.4). The research encountered technical<br />

challenges such as locating configuration tools, dealing with hidden areas and using<br />

<strong>Forensic</strong>s Live CDs during the evaluation (further details are provided in Section<br />

5.1.6).<br />

1.3 STRUCTURE OF THE THESIS<br />

The thesis consists <strong>of</strong> four main sections apart from Chapter 1. Introduction and<br />

Chapter 6. Conclusion. Chapter 1 sheds light on the gaps in the research areas and the<br />

motivation <strong>of</strong> this research.<br />

Chapter 2 presents a literature review and studies the findings <strong>of</strong> other academic<br />

studies in this research field. The state-<strong>of</strong>-the-art <strong>of</strong> digital <strong>for</strong>ensics is reviewed at the<br />

beginning <strong>of</strong> the chapter. The review <strong>of</strong> investigative processes & standardisations can<br />

help the researcher to understand the standard disk imaging procedures that are used in the<br />

industry. The research reviews the evolution <strong>of</strong> digital <strong>for</strong>ensics tools and the<br />

characteristics <strong>of</strong> existing tools in the market (including their limitations). The chapter<br />

then investigates the legal and technical implications <strong>of</strong> digital <strong>for</strong>ensics tools. It reviews<br />

the definition and characteristics <strong>of</strong> digital evidence and how it can be recognised as<br />

admissible in courtroom. Most <strong>of</strong> the digital evidence is collected, analysed and presented<br />

using digital <strong>for</strong>ensic tools. The validity <strong>of</strong> the digital evidence extracted by the digital<br />

<strong>for</strong>ensic tools may be challenged. <strong>Forensic</strong> practitioners are demanding research on the<br />

validation <strong>of</strong> digital <strong>for</strong>ensics tools. The background and the existing works on digital<br />

4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!