30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Testing<br />

requirements<br />

Selected disk<br />

imaging tools<br />

Input<br />

1. Test Scenarios<br />

2. Test Procedures<br />

3. Configuration <strong>of</strong> Test<br />

Environment<br />

Figure 3.7. Research model.<br />

56<br />

Tests<br />

Per<strong>for</strong>mance<br />

<strong>of</strong> the selected disk imaging<br />

tools in terms <strong>of</strong> Accuracy<br />

& Completeness<br />

The hypotheses about the per<strong>for</strong>mance between the testing and the validity <strong>of</strong> the<br />

selected disk imaging tools are as follow:<br />

H1: FTK Imager will per<strong>for</strong>m better than the other two selected disk<br />

imaging tools in most <strong>of</strong> the common test cases;<br />

H2: Helix 3 Pro will per<strong>for</strong>m better than AIR Imager in most <strong>of</strong> the<br />

common test cases;<br />

H3: AIR will per<strong>for</strong>m better than the other two selected disk imaging<br />

tools in a very few common test cases.<br />

According to the literature reviewed in sections 2.2.2, 2.2.4.2 and 2.3.1, accurancy and<br />

completeness are two important criteria <strong>for</strong> evaluating the per<strong>for</strong>mance <strong>of</strong> disk<br />

imaging tools. There<strong>for</strong>e, the research aims to find out which disk imaging tools are<br />

most successful under various testing scenarios.<br />

3.3 THE RESEARCH MODEL<br />

The five studies reviewed in Section 3.1 have investigated the standardised approach<br />

and other potential methods <strong>of</strong> assessing digital <strong>for</strong>ensic disk imaging tools. The main<br />

objective that needs to be established is to empirically verify the validity <strong>of</strong> digital<br />

<strong>for</strong>ensic disk imaging tools. The essential element <strong>of</strong> this research is to execute a<br />

series <strong>of</strong> test scenarios on the selected disk imaging tools based on the defined test<br />

requirements. It should be noted that the testing utilises black-box testing techniques<br />

by executing a set <strong>of</strong> pre-defined test scenarios to investigate the validity <strong>of</strong> disk<br />

imaging tools in a logical and standardised approach. Utilising test scenarios based on<br />

a set <strong>of</strong> pre-defined requirements to verify disk imaging tools is a common and

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!