Article ID Journal Published Year Pages File Type
457923 Digital Investigation 2012 10 Pages PDF
Abstract

The dramatic growth of storage capacity and network bandwidth is making it increasingly difficult for forensic examiners to report what is present on a piece of subject media. Instead, analysts are focusing on what characteristics of the media have changed between two snapshots in time. To date different algorithms have been implemented for performing differential analysis of computer media, memory, digital documents, network traces, and other kinds of digital evidence. This paper presents an abstract differencing strategy and applies it to all of these problem domains. Use of an abstract strategy allows the lessons gleaned in one problem domain to be directly applied to others.

Related Topics
Physical Sciences and Engineering Computer Science Computer Networks and Communications
Authors
, , ,