کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
10342376 696057 2014 8 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Testing the forensic soundness of forensic examination environments on bootable media
ترجمه فارسی عنوان
تست صحت قانونی محاکمات پزشکی قانونی در رسانه های بوت
کلمات کلیدی
محیط آزمون قابل بوته سی دی بوت دی وی دی قابل بوت توابع هش، تجزیه و تحلیل دیفرانسیل،
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی
In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is performed on the image files. The differential analysis allows us to quantify and explain the alterations made to the image files by the bootable CD/DVD examination. Our approach can be used to experimentally validate new bootable CD/DVD distributions as forensically sound.
ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 11, Supplement 2, August 2014, Pages S22-S29
نویسندگان
, , , ,