30.06.2013 Views

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

can be categorized as textual value, numerical value or other type <strong>of</strong> value. The value<br />

<strong>of</strong> each criterion defined in this research is textual value.<br />

Ratings “passed” and “failed” are sufficient enough to identify the gap between<br />

the requirements and the actual per<strong>for</strong>mance <strong>of</strong> the tool. Vatis (2004) adopted the<br />

technique <strong>of</strong> GA matrix in a national research on investigating the gap between the<br />

cyber-attacks and the law en<strong>for</strong>cement security tools.<br />

Table 3.1<br />

Example <strong>of</strong> Gap Analysis Matrix<br />

Criteria<br />

Product<br />

FTK Imager Helix 3 Pro AIR<br />

Requirement 1 PASSED FAILED PASSED<br />

Requirement 2<br />

……………<br />

Requirement X<br />

Figure 3.11 illustrates the mapping <strong>of</strong> the research questions to the research stages.<br />

The data map demonstrates how the research questions will be answered in a logical<br />

and scientific manner. Figure 3.11 also illustrates the detail flow <strong>of</strong> logics how this<br />

research is conducted.<br />

3.5 LIMITATIONS OF THE RESEARCH<br />

The proposed research proposes to examine the per<strong>for</strong>mance <strong>of</strong> the selected disk<br />

imaging tools in different validity tests. However, certain limitations are expected in<br />

the proposed research.<br />

A manageable number <strong>of</strong> disk imaging tools are tested against the designed test<br />

scenarios in the proposed research. Many other disk imaging tools are available on the<br />

market at variable cost but this investigation is focuses on the selected tools. No<br />

attempt is made <strong>for</strong> the findings to be representative but rather a case is built on the<br />

use <strong>of</strong> well-known tools. The main problem <strong>of</strong> this approach is overgeneralisation and<br />

also a sense <strong>of</strong> incompleteness as there are many other s<strong>of</strong>tware tools that could be<br />

tested.<br />

65

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!