25.12.2013 Views

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SLAMorris Final Thesis After Corrections.pdf - Cranfield University

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

and had a high number of false positives; therefore further research into the<br />

format of H3 fragments is required to assist with maximising the data recovered.<br />

Each method used in the previous research had different strengths; methods 1<br />

and 2 produced the most accurate results on structured information with a<br />

known syntax. Method 3 produced accurate results with a file which had a<br />

known but variable structure; both methods 3 and 4 improved the accuracy of<br />

pattern matching for the image only fragments. If the strengths of each method<br />

were utilised it may be possible to construct a single approach to identifying<br />

thumbnail cache file fragments. In order to compare any new implementation to<br />

the previous methods the information to be carved should remain as described<br />

in Section 7.5. In order to successfully maximise the data recovered and<br />

maximise the relationships formed it is necessary to both identify thumbnail<br />

cache file fragments and to reassemble the files where possible. The<br />

reassembly of a thumbnail cache file would assist with forming relationships<br />

between artefacts and provide contextual information about any artefacts<br />

recovered. Therefore it is necessary to consider the potential input requirements<br />

of reassembly methods to ensure the output produced from this research is<br />

suitable for the next stage of this research project.<br />

For this research it is necessary to consider the feasibility and performance of<br />

the reassembly approach. If fragments have not been successfully identified<br />

then it will not be possible to completely reassemble the information; this<br />

suggests that it is better to identify all relevant fragments and have some false<br />

positives than to fail to identify a relevant fragment. However a large number of<br />

false positives can reduce the feasibility of the reassembly method. For<br />

example a large number of false positives may result in a substantial number of<br />

comparisons which may significantly impact the processing time required to<br />

complete the reassembly process. It may also affect the number of false<br />

positive reassembled files produced. This would mean an analyst had more<br />

Page<br />

205

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!