2014
DOI: 10.1016/j.dss.2014.01.007
|View full text |Cite
|
Sign up to set email alerts
|

A case-based reasoning method for locating evidence during digital forensic device triage

Abstract: The role of triage in digital forensics is disputed, with some practitioners questioning its reliability for identifying evidential data. Although successfully implemented in the field of medicine, triage has not established itself to the same degree in digital forensics. This article presents a novel approach to triage for digital forensics. Case-Based Reasoning Forensic Triager (CBR-FT) is a method for collecting and reusing past digital forensic investigation information in order to highlight likely evident… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
25
0

Year Published

2017
2017
2023
2023

Publication Types

Select...
6
1

Relationship

4
3

Authors

Journals

citations
Cited by 35 publications
(25 citation statements)
references
References 30 publications
0
25
0
Order By: Relevance
“…Horsman et al [10] extend the ideas presented in [37] and discuss a Case-Based Reasoning Forensic Triager (CBR-FT) method for retrieving the evidential data based on the location of the digital evidence in the past cases. The CBR-FT maintains a knowledge base for gathering the previous experience.…”
Section: Methods Of Post-mortem Triagementioning
confidence: 99%
See 3 more Smart Citations
“…Horsman et al [10] extend the ideas presented in [37] and discuss a Case-Based Reasoning Forensic Triager (CBR-FT) method for retrieving the evidential data based on the location of the digital evidence in the past cases. The CBR-FT maintains a knowledge base for gathering the previous experience.…”
Section: Methods Of Post-mortem Triagementioning
confidence: 99%
“…The runtimes are very short, however, it is not clear why they are so short, and an explanation is not provided. Moreover, Horsman et al [10] state that hashing and keyword searching approaches can limit the effectiveness of digital triage because they are too restrictive. The limitations of the ANT solution are the following: there is no possibility to boot from the external source and encrypted data could not be analysed.…”
Section: A Hash Database Index Filementioning
confidence: 99%
See 2 more Smart Citations
“…Not only are more devices in need of investigation, each device typically maintains a greater level of internal storage. The task of processing larger volumes of data remains a topic of interest, and one still in need of a universal consistent solution (Horsman et al, 2014;Quick and Choo, 2014). As a result, the time restrictions of pre-charge bail are being applied to a moving target, one where feasibility remains an issue.…”
Section: Implications Of Time On Investigationsmentioning
confidence: 99%