30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ecommended practice according to a variety <strong>of</strong> digital <strong>for</strong>ensic tool studies (Byers &<br />

Shahmehri, 2009; NIST, 2004; Wilsdon & Slay, 2006; Yinghua & Slay, 2010;<br />

SWGDE, 2009a). A scenario-based testing approach is the most suitable method <strong>of</strong><br />

assessing the validity <strong>of</strong> disk imaging tools.<br />

The proposed research includes five phases and is illustrated in Figure 3.8<br />

below. <strong>Disk</strong> imaging tools are selected based on the preliminary requirements (see<br />

Table 2.6) and a series <strong>of</strong> market and vendor researches. <strong>Disk</strong> imaging tools and their<br />

documentations are acquired and reviewed in phase one. Determination <strong>of</strong> which disk<br />

imaging tools will be selected <strong>for</strong> testing will be based on the budget <strong>of</strong> the study,<br />

reputation and publicity <strong>of</strong> the tools. Sources <strong>of</strong> the in<strong>for</strong>mation are also a subject <strong>of</strong><br />

research in relevant research articles, journals, websites, <strong>for</strong>ums and books. Research<br />

budget is another important tool selection criterion. After a list <strong>of</strong> disk imaging tools<br />

has been selected, the method function mapping adopted from Guo & Slay (2010) will<br />

be used to provide a level <strong>of</strong> abstraction that would specify the required functions <strong>of</strong><br />

disk imaging tools <strong>for</strong> the <strong>for</strong>ensic s<strong>of</strong>tware developers, industry practitioners and<br />

other researchers who are conducting their own <strong>for</strong>ensic tools validation. The process<br />

<strong>of</strong> test requirements specification will be initiated once the function mapping is<br />

completed. CFTT program has made significant progress in specifying the<br />

requirements <strong>for</strong> the disk imaging function. Testing requirements from CFTT has been<br />

considered as a standard when testing disk imaging tools. In addition, a review <strong>of</strong><br />

other releated research conducted in Section 2.2.4 and the documentation <strong>of</strong> selected<br />

tools will serve as input to requirement specifications in Phase 2. A list <strong>of</strong> mandatory<br />

and optional requirements is generated. The test requirements are designed based on<br />

the two testing criteria, namely accuracy and completeness. A completed list <strong>of</strong><br />

mandatory and optional testing requirements is documented in Appendix 2. Quality <strong>of</strong><br />

the test requirements is set through an in<strong>for</strong>mal discussion with some experienced<br />

industry experts.<br />

57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!