30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

compromised which may further affect the admissibility <strong>of</strong> the digital evidence<br />

presented in court. In relation to the digital evidence, corresponding laws and<br />

guidelines are identified and discussed in section 2.2. Application <strong>of</strong> open source<br />

digital <strong>for</strong>ensic tools in digital investigation has been questioned. However, open<br />

source digital <strong>for</strong>ensic tools still have advantages that proprietary s<strong>of</strong>tware does not<br />

have. A complete understanding <strong>of</strong> the reliability <strong>of</strong> digital <strong>for</strong>ensic tools helps further<br />

define the mandatory requirements <strong>of</strong> disk imaging tools. The requirements will<br />

determine the required functions <strong>for</strong> a disk imaging tool and provide the foundation <strong>of</strong><br />

tool testing requirements. Many digital <strong>for</strong>ensic tools are still yet to be verified and<br />

validated be<strong>for</strong>e they can be used as <strong>for</strong>ensic tools in the field. A standardised digital<br />

<strong>for</strong>ensics tool verification and validation framework or procedures are yet to be<br />

established. Several issues and problems regarding digital <strong>for</strong>ensic tools have been<br />

raised and developed in Chapter 2. A summary <strong>of</strong> key issues and problems are<br />

discussed in this section to provide a snapshot <strong>of</strong> the current trends in digital <strong>for</strong>ensics.<br />

2.6 CONCLUSION<br />

Chapter 2 focuses on reviewing the contexts and discussions relevant to the evaluation<br />

<strong>of</strong> digital <strong>for</strong>ensic tools. A comprehensive overview <strong>of</strong> the digital <strong>for</strong>ensic<br />

environment has been developed. The overview covers the differences between<br />

computer <strong>for</strong>ensics and digital <strong>for</strong>ensics, Investigative Processes & Standardisations<br />

and most importantly the development and evolution <strong>of</strong> digital <strong>for</strong>ensic tools. It shows<br />

the development, the most popular tools and problems <strong>of</strong> digital <strong>for</strong>ensic tools. Digital<br />

<strong>for</strong>ensics tools verification and validation are studied and discussed regarding the<br />

current trends in the industry.<br />

The review covers background studies <strong>of</strong> digital <strong>for</strong>ensics, the legal and<br />

technical issues <strong>of</strong> digital <strong>for</strong>ensic tools. Digital evidence is defined in order to further<br />

analyse its admissibility regarding legal standard and Daubert guidelines <strong>of</strong> the United<br />

States <strong>of</strong> America. In relation to that, the reliability <strong>of</strong> digital <strong>for</strong>ensic tools is<br />

discussed with respect to the perspectives <strong>of</strong> open source and proprietary s<strong>of</strong>tware.<br />

Arguments between open source and proprietary s<strong>of</strong>tware are presented. With the<br />

41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!