2009
DOI: 10.1016/j.diin.2009.06.013
|View full text |Cite
|
Sign up to set email alerts
|

A second generation computer forensic analysis system

Abstract: Keywords:Limitations of existing tools Second generation tools Tool architecture Parallel processing Tool metrics Data design & abstraction Forensic Workflow Functional decomposition Standardised tests a b s t r a c tThe architecture of existing -first generation -computer forensic tools, including the widely used EnCase and FTK products, is rapidly becoming outdated. Tools are not keeping pace with increased complexity and data volumes of modern investigations. This paper discuses the limitations of first gen… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
24
0

Year Published

2014
2014
2023
2023

Publication Types

Select...
5
2
1

Relationship

0
8

Authors

Journals

citations
Cited by 61 publications
(33 citation statements)
references
References 2 publications
0
24
0
Order By: Relevance
“…In Quick and Choo, for the better understanding of the upcoming problems, the authors provided a consolidated survey on research contributions, the challenges and possible solutions allied to storage drive forensics. Similarly, the concern towards the underperforming behavior of existing forensic tools and their processing complexities in the scenario of the ever‐increasing volume of data were highlighted in Ayers …”
Section: Background and Related Workmentioning
confidence: 99%
“…In Quick and Choo, for the better understanding of the upcoming problems, the authors provided a consolidated survey on research contributions, the challenges and possible solutions allied to storage drive forensics. Similarly, the concern towards the underperforming behavior of existing forensic tools and their processing complexities in the scenario of the ever‐increasing volume of data were highlighted in Ayers …”
Section: Background and Related Workmentioning
confidence: 99%
“…It is evident that the time requirements for full disk image collection and analysis process increase significantly with the increasing volume of data . Ayers et al discussed that the previously existing forensic tools and software are falling behind in their ability to handle the increasing complexity and volume of data. In order to address the data volume challenge, Roussev et al have introduced the notion of triage, a partial forensic examination conducted under significant time and resource constraints.…”
Section: Related Workmentioning
confidence: 99%
“…However, some metrics in the DF investigative process have already been proposed, such as the Forensic Traceability Measurement by authors Siti R. Selamat et al [3]. Daniel Ayers [13] makes suggestions for the measurement of the computer forensic tools' efficacy and performance, including the following parameters: absolute (T) and relative (T1) speed; completeness (%); accuracy (100 %); reliability (100 %); auditability (%); repeatability (%); and limitations of first-generation tools (Y/N).…”
Section: Establishing Integrated Model Of the Df Process Performancesmentioning
confidence: 99%