A Practical Approach for Digital Forensic Triage

Author:

Jiang Jian Guo1,Yang Bo1,Lin Sen2,Zhang Ming Xing1,Liu Kun Ying1

Affiliation:

1. Chinese Academy of Sciences

2. Harbin Engineering University

Abstract

In order to uncover truths to serve justice, case-related data collected from a digital investigation requires substantial resources to analyze, especially in time-critical situations. At present, however, digital forensics has not evolved to meet this ever-increasing demand. Digital forensic triage is a promising solution, as it is designed to maximize the use of resources according to a system of priorities, and hence the efficiency and effectiveness of forensic examinations can be increased. Nevertheless, the lack of concrete methods limits efforts to implement triage. This paper presents a practical approach that is designed to build a prioritizing solution. In this work a new process model is derived based on the presented approach, and it is particularly suited to scenarios where forensic examiners do not have enough time and resources to conduct a full examination and analysis. An example is described to demonstrate how this approach can be used to meet the requirements of network forensic investigations.

Publisher

Trans Tech Publications, Ltd.

Reference24 articles.

1. Federal Bureau of Investigation, Regional Computer Forensics Laboratory (RCFL) Program Annual Report for Fiscal Year 2012, Washington, DC (www. rcf l. gov/downloads/documents/ RCFL_Nat_Annual12. pdf), (2012).

2. K. V. Iserson, and J. C. Moskop, Triage in medicine, part I: concept, history, and types. Annals of emergency medicine, vol. 49(3): 275-281, (2007).

3. A. Agarwal, M. Gupta, S. Gupta and S. C. Gupta, Systematic digital forensic investigation model, International Journal of Computer Science and Security (IJCSS), vol. 5(1) , pp.118-131, (2011).

4. V. Baryamureeba and F. Tushabe, The enhanced digital investigation process model, Proceedings of the Fourth Digital Forensic Research Workshop, (2004).

5. G. Cantrell and D. Dampier, Evaluation of the semi-automated crime-specific digital triage process model, in Advances in Digital Forensics IX, G. Peterson and S. Shenoii (Eds. ), Springer Berlin Heidelberg, p.410 : 83-98, (2013).

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3