The Experts below are selected from a list of 1446 Experts worldwide ranked by ideXlab platform

Michael Cross - One of the best experts on this subject based on the ideXlab platform.

  • Computer Forensic Software and hardware
    Scene of the Cybercrime (Second Edition), 2008
    Co-Authors: Littlejohn Shinder, Michael Cross
    Abstract:

    This chapter discusses disk imaging and introduces hardware- and Software-based Forensic tools. Disk imaging refers to the process of making an exact copy of a disk. Imaging is sometimes also called disk cloning or ghosting, but the latter terms usually refer to images created for purposes other than evidence preservation. Disk imaging is accepted as standard practice in Computer Forensics to preserve the integrity of the original evidence. Disk imaging differs from creating a standard backup of a disk in that ambient data is not copied to a backup; only active files are copied. Because a backup created with popular backup programs such as the Windows built-in backup utility, Backup Exec, ARCserve, and the like is not an exact duplicate these programs should not be used for disk imaging. Programs such as Norton Ghost include switches that allow one to make a bitstream copy, but these programs were not originally designed for Forensic use. In some cases, the tools are Software-based, but one can also use hardware to acquire evidence from suspect machines. The hardware- and Software-based solutions create bitstream images of the disk, and include any data that is visible to the file system, as well as hidden and deleted files and fragments of files, the MBR, the partition table, and any number of other items on a disk.

Littlejohn Shinder - One of the best experts on this subject based on the ideXlab platform.

  • Computer Forensic Software and hardware
    Scene of the Cybercrime (Second Edition), 2008
    Co-Authors: Littlejohn Shinder, Michael Cross
    Abstract:

    This chapter discusses disk imaging and introduces hardware- and Software-based Forensic tools. Disk imaging refers to the process of making an exact copy of a disk. Imaging is sometimes also called disk cloning or ghosting, but the latter terms usually refer to images created for purposes other than evidence preservation. Disk imaging is accepted as standard practice in Computer Forensics to preserve the integrity of the original evidence. Disk imaging differs from creating a standard backup of a disk in that ambient data is not copied to a backup; only active files are copied. Because a backup created with popular backup programs such as the Windows built-in backup utility, Backup Exec, ARCserve, and the like is not an exact duplicate these programs should not be used for disk imaging. Programs such as Norton Ghost include switches that allow one to make a bitstream copy, but these programs were not originally designed for Forensic use. In some cases, the tools are Software-based, but one can also use hardware to acquire evidence from suspect machines. The hardware- and Software-based solutions create bitstream images of the disk, and include any data that is visible to the file system, as well as hidden and deleted files and fragments of files, the MBR, the partition table, and any number of other items on a disk.

Jason Beckett - One of the best experts on this subject based on the ideXlab platform.

  • validation and verification of Computer Forensic Software tools searching function
    Digital Investigation, 2009
    Co-Authors: Yinghua Guo, Jill Slay, Jason Beckett
    Abstract:

    The process of using automated Software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated Software, so as to provide sound evidence. However, the growth in the Computer Forensic field has created a demand for new Software (or increased functionality to existing Software) and a means to verify that this Software is truly ''Forensic'' i.e. capable of meeting the requirements of the 'trier of fact'. In this work, we present a scientific and systemical description of the Computer Forensic discipline through mapping fundamental functions required in the Computer Forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of Computer Forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function.

Yinghua Guo - One of the best experts on this subject based on the ideXlab platform.

  • validation and verification of Computer Forensic Software tools searching function
    Digital Investigation, 2009
    Co-Authors: Yinghua Guo, Jill Slay, Jason Beckett
    Abstract:

    The process of using automated Software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated Software, so as to provide sound evidence. However, the growth in the Computer Forensic field has created a demand for new Software (or increased functionality to existing Software) and a means to verify that this Software is truly ''Forensic'' i.e. capable of meeting the requirements of the 'trier of fact'. In this work, we present a scientific and systemical description of the Computer Forensic discipline through mapping fundamental functions required in the Computer Forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of Computer Forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function.

Jill Slay - One of the best experts on this subject based on the ideXlab platform.

  • validation and verification of Computer Forensic Software tools searching function
    Digital Investigation, 2009
    Co-Authors: Yinghua Guo, Jill Slay, Jason Beckett
    Abstract:

    The process of using automated Software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated Software, so as to provide sound evidence. However, the growth in the Computer Forensic field has created a demand for new Software (or increased functionality to existing Software) and a means to verify that this Software is truly ''Forensic'' i.e. capable of meeting the requirements of the 'trier of fact'. In this work, we present a scientific and systemical description of the Computer Forensic discipline through mapping fundamental functions required in the Computer Forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of Computer Forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function.