02.12.2012 Views

gengenbach-forensic-workflows-2012

gengenbach-forensic-workflows-2012

gengenbach-forensic-workflows-2012

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

conforms to the Digital Forensics XML (DFXML) metadata schema. 102 The DFXML file<br />

and a copy of the disk image are then packaged using the BagIt object packaging<br />

specification developed by the Library of Congress and California Digital Library. 103 The<br />

BagIt package allows the disk image and any associated metadata to be packaged as part<br />

of the same “bag,” enabling higher-level description and a manifest of the bag contents to<br />

be archived in Yale University Libraries digital storage, the Rescue Repository.<br />

The Rescue Repository is a library-wide managed storage environment<br />

specifically for the digital materials acquired and ingested by each collection in Yale<br />

University Libraries. 104 Within the Rescue Repository, files are verified and validated by<br />

JSTOR/Harvard Object Validation Environment (JHOVE), and ingests are monitored<br />

through ingest activity logs by a nightly reporting script. 105 The Rescue Repository is a<br />

“dark archive,” in that it does not allow public access to materials, but only internally to<br />

those with proper permissions—mostly the administrators of that material from each of<br />

the collections with the ability to ingest into the Repository.<br />

For this reason, the Beinecke has provided an alternative method of access by<br />

copying the disk image before it is added to a BagIt package. This access disk image<br />

copy is maintained on separate network storage, and may be subject to further processing<br />

with a robust <strong>forensic</strong> analysis tool, the Forensic Toolkit (FTK). 106 This tool is used for<br />

arrangement and description, and to define the levels of access available to the user.<br />

Accessible material is then provided to the user on a secure access station in the Beinecke<br />

102 See Appendix D, “fiwalk” and “Digital Forensics XML.”<br />

103 See Appendix D, “BagIt.”<br />

104 “Yale University Rescue Repository: About the Rescue Repository,” Yale University Library: Integrated<br />

Systems and Programming Group http://www.library.yale.edu/ito/RRweb/AboutRescueRepository.html<br />

(accessed July <strong>2012</strong>).<br />

105 Ibid.<br />

106 Note that this is a different program from FTK Imager. For more information, see Appendix D, “Forensic<br />

Toolkit (FTK).”<br />

30

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!