12.07.2015 Views

2013-12-05_tcpflow-and-BE-update

2013-12-05_tcpflow-and-BE-update

2013-12-05_tcpflow-and-BE-update

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The big picture:using low-probability data for high-outcome correlation.bulk_extractor was created to find low-probably, high-value information.• “low-probability” means does not occur by chance; not part of the background.• Examples:—email addresses—Credit card numbers—Evidence of specific executables (prefetch files; PE headers)Once found, the goal was to enable:• Multi-drive correlation—Find all drives with a specific identifier—“Blind correlation” between multiple drives to find identifiers in commonWe now have more sources of low-probability data:• Fragments from ZIP & RAR files• Ethernet MAC addresses66

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!