Article ID | Journal | Published Year | Pages | File Type |
---|---|---|---|---|
10342408 | Digital Investigation | 2015 | 11 Pages |
Abstract
We present a new approach to digital forensic evidence acquisition and disk imaging called sifting collectors that images only those regions of a disk with expected forensic value. Sifting collectors produce a sector-by-sector, bit-identical AFF v3 image of selected disk regions that can be mounted and is fully compatible with existing forensic tools and methods. In our test cases, they have achieved an acceleration of >3Ã while collecting >95% of the evidence, and in some cases we have observed acceleration of up to 13Ã. Sifting collectors challenge many conventional notions about forensic acquisition and may help tame the volume challenge by enabling examiners to rapidly acquire and easily store large disks without sacrificing the many benefits of imaging.
Keywords
Related Topics
Physical Sciences and Engineering
Computer Science
Computer Networks and Communications
Authors
Jonathan Grier, Golden G. III,