کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
457924 696081 2012 9 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Content triage with similarity digests: The M57 case study
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Content triage with similarity digests: The M57 case study
چکیده انگلیسی

In this work we illustrate the use of similarity digests for the purposes of forensic triage. We use a case that consists of 1.5 TB of raw data, including disk images, network captures, RAM snapshots, and USB flash media. We demonstrate that by applying similarity digests in a systematic manner, the scope of examination can be narrowed down within a matter of minutes to hours. In contrast, conventional manual examination of all the data may require several days, and its effectiveness relies substantially on the experience of the investigator.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Digital Investigation - Volume 9, Supplement, August 2012, Pages S60–S68
نویسندگان
, ,