30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Abstract<br />

The evaluation <strong>of</strong> digital <strong>for</strong>ensic tools evaluation has been recognised as a<br />

challenging, and insufficiently examined research topic in the field <strong>of</strong> digital<br />

<strong>for</strong>ensics. The mainstream digital <strong>for</strong>ensic tools deployed in law en<strong>for</strong>cement and the<br />

private sector are close-sourced and expensive commercial packages. Open-source<br />

digital <strong>for</strong>ensic tools are the alterative option <strong>for</strong> organisations with less funding.<br />

The reliability <strong>of</strong> digital evidence that is collected, analysed and presented using<br />

those digital <strong>for</strong>ensic tools has been challenged. There are very few organisations<br />

that conduct validation research on digital <strong>for</strong>ensic tools. S<strong>of</strong>tware vendors may<br />

conduct their own validation tests on the s<strong>of</strong>tware but their findings are usually not<br />

available to the public.<br />

Three areas related to digital <strong>for</strong>ensic tools have been reviewed in this study,<br />

namely overview <strong>of</strong> the digital <strong>for</strong>ensic environment, legal and technical<br />

implications <strong>of</strong> digital <strong>for</strong>ensic tools and evaluation <strong>of</strong> disk imaging tools. Imaging<br />

the disk drives is a critical process in <strong>for</strong>ensic investigation and disk imaging tools<br />

are the subject <strong>of</strong> this research. The review <strong>of</strong> relevant literature has guided the<br />

research to study the validity <strong>of</strong> disk imaging tools. A research model is designed<br />

and implemented with the aid <strong>of</strong> testing specifications, requirements, assertions, case<br />

scenarios and test sets. The model hypothesises that the completeness and accuracy<br />

<strong>of</strong> image data affect positively the validity <strong>of</strong> the disk imaging tools. A set <strong>of</strong><br />

selected tools is subjected to validation to analyse if the disk imaging tools generate<br />

complete and accurate results. Various case scenarios are designed and the selected<br />

tools are validated under a set <strong>of</strong> <strong>for</strong>ensically-sound procedures that are defined<br />

according to the test specifications.<br />

The validation has exposed problems and issues <strong>of</strong> the selected disk imaging<br />

tools that have been evaluated. Some issues <strong>of</strong> s<strong>of</strong>tware usability have also been<br />

pointed out and discussed. The study has shown that the attributes completeness and<br />

accuracy positively affect the validity <strong>of</strong> the disk imaging tools. The research<br />

findings will be valuable <strong>for</strong> law en<strong>for</strong>cement and the legal community where<br />

<strong>for</strong>ensic disk imaging tools must produce consistent, complete and accurate results.<br />

S<strong>of</strong>tware developers should focus on ensuring completeness and accuracy <strong>of</strong> the<br />

iv

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!