The Experts below are selected from a list of 7734 Experts worldwide ranked by ideXlab platform

Jill Slay - One of the best experts on this subject based on the ideXlab platform.

  • validation and verification of computer Forensic Software tools searching function
    Digital Investigation, 2009
    Co-Authors: Yinghua Guo, Jill Slay, Jason Beckett
    Abstract:

    The process of using automated Software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated Software, so as to provide sound evidence. However, the growth in the computer Forensic field has created a demand for new Software (or increased functionality to existing Software) and a means to verify that this Software is truly ''Forensic'' i.e. capable of meeting the requirements of the 'trier of fact'. In this work, we present a scientific and systemical description of the computer Forensic discipline through mapping fundamental functions required in the computer Forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of computer Forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function.

  • wireless Forensic analysis tools for use in the electronic evidence collection process
    Hawaii International Conference on System Sciences, 2007
    Co-Authors: Benjamin Turnbull, Jill Slay
    Abstract:

    This paper discusses the need for both a series of electronic tools and procedural changes to the evidence collection process to accommodate the possibilities of wireless technologies. 802.11-based wireless technologies in particular pose an issue to the collection of electronic evidence, as devices that appear isolated may be tirelessly accessed during the collection phase, leading to after-seizure communications and a tampering of evidence in custody. Whilst Forensic acquisition and analysis procedural guides are yet to discuss the acquisition of wireless devices, one of the core issues in collecting wireless devices is that there is no indication for the number or type of devices connected to a wireless network, should one exist in an area of interest. It is proposed that a series of Forensic Software tools be developed to aid in the detection, analysis and control of wireless networks that are in the process of being seized for Forensic analysis. Through control of the wireless medium, information regarding connected devices may be gathered and methods to prevent communication between devices during and after evidence seizure are also examined

  • digital Forensics validation and verification in a dynamic work environment
    Hawaii International Conference on System Sciences, 2007
    Co-Authors: Jason Beckett, Jill Slay
    Abstract:

    Many Forensic computing practitioners work in a high workload and low resource environment. With the move by the discipline to seek ISO 17025 laboratory accreditation, practitioners are finding it difficult to meet the demands of validation and verification of their tools and still meet the demands of the accreditation framework. Many agencies are ill-equipped to reproduce tests conducted by organizations such as NIST since they cannot verify the results with their equipment and in many cases rely solely on an independent validation study of other peoples' equipment. This creates the issue of tools in reality never being tested. Studies have shown that independent validation and verification of complex Forensic tools is expensive and time consuming, and many practitioners also use tools that were not originally designed for Forensic purposes. This paper explores the issues of validation and verification in the accreditation environment and proposes a paradigm that will reduce the time and expense required to validate and verify Forensic Software tools

C W Johnson - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Software engineering and the need for new approaches to accident investigation
    International Conference on Computer Safety Reliability and Security, 2000
    Co-Authors: C W Johnson
    Abstract:

    Accident reports are intended to explain the causes of human error, system failure and managerial weakness. There is, however, a growing realization that existing investigation techniques fail to meet the challenges created by accidents that involve Software failures. This paper argues that existing Software development techniques cannot easily be used to provide retrospective information about the complex and systemic causes of major accidents. In consequence, we must develop specific techniques to support Forensic Software engineering.

Ronald Van Der Knijff - One of the best experts on this subject based on the ideXlab platform.

  • an open source Forensic Software framework for acquiring and decoding data stored in electronic devices
    International Journal of Digital Evidence, 2005
    Co-Authors: Jeroen Van Den Bos, Ronald Van Der Knijff
    Abstract:

    TULP2G is a Forensic Software framework for acquiring and decoding data stored in electronic devices. The framework consists of a layered architecture with communication, protocol, conversion, and export plug-ins to acquire, decode, and report evidence in customizable layouts. All acquired data is stored in an XML formatted evidence file along with information for auditing purposes. XML files can also be used to customize the framework with different user interface languages. A profile mechanism is built in to save and load framework configuration settings for common investigations. Conversion and export plug-ins can also be used to decode data acquired with other data acquisition methods. TULP2G is implemented in C# using .NET1.1 and released under a BSD license. All Software, including source code is available at http://tulp2g.sourceforge.net/. Currently available plug-ins are mainly targeted towards GSM phone examinations, but the applied open source strategy tries to stimulate other parties in developing more examination functionality.

Brian D Carrier - One of the best experts on this subject based on the ideXlab platform.

  • defining digital Forensic examination and analysis tool using abstraction layers
    International Journal of Digital Evidence, 2003
    Co-Authors: Brian D Carrier
    Abstract:

    This paper uses the theory of abstraction layers to describe the purpose and goals of digital Forensic analysis tools. Using abstraction layers, we identify where tools can introduce errors and provide requirements that the tools must follow. Categories of Forensic analysis types are also defined based on the abstraction layers. Abstraction layers are not a new concept, but their usage in digital Forensic analysis is not well documented. What does it mean to be a Digital Forensic Analysis Tool? How do we categorize the different types of analysis tools? For example, an investigator can view the files and directories of a suspect system by using either specialized Forensic Software or by using the operating system (OS) of an analysis system and viewing the files by mounting the drive. Both methods allow the investigator to view evidence in allocated files, but only the specialized Forensic Software allows him to easily view unallocated files. Additional tools are required if he is relying on the OS. Clearly both allow the investigator to find evidence and therefore should be considered Forensic tools, but it is unclear how we should compare and categorize them. The high-level process of digital Forensics includes the acquisition of data from a source, analysis of the data and extraction of evidence, and preservation and presentation of the evidence. Previous work has been done on the theory and requirements of data acquisition [7] and the preservation of evidence [4]. This paper addresses the tools that are used for the analysis of data and extraction of evidence. This paper examines the nature of tools in digital Forensics and proposes definitions and requirements. Current digital Forensic tools produce results that have been successfully used in prosecutions, but lack designs that were created with Forensic science needs. They provide the investigator with access to evidence, but typically do not provide access to methods for verifying that the evidence is reliable. This is necessary when approaching digital Forensics from a scientific point of view and could be a legal requirement in the future. The core concept of this paper is the basic notion of abstraction layers. Abstraction layers exist in all forms of digital data and therefore in the tools used to analyze them. The idea of using tools for layers of abstraction is not new, but a discussion of the definitions, properties, and error types of abstraction layers when used with digital

Jason Beckett - One of the best experts on this subject based on the ideXlab platform.

  • validation and verification of computer Forensic Software tools searching function
    Digital Investigation, 2009
    Co-Authors: Yinghua Guo, Jill Slay, Jason Beckett
    Abstract:

    The process of using automated Software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated Software, so as to provide sound evidence. However, the growth in the computer Forensic field has created a demand for new Software (or increased functionality to existing Software) and a means to verify that this Software is truly ''Forensic'' i.e. capable of meeting the requirements of the 'trier of fact'. In this work, we present a scientific and systemical description of the computer Forensic discipline through mapping fundamental functions required in the computer Forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of computer Forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function.

  • digital Forensics validation and verification in a dynamic work environment
    Hawaii International Conference on System Sciences, 2007
    Co-Authors: Jason Beckett, Jill Slay
    Abstract:

    Many Forensic computing practitioners work in a high workload and low resource environment. With the move by the discipline to seek ISO 17025 laboratory accreditation, practitioners are finding it difficult to meet the demands of validation and verification of their tools and still meet the demands of the accreditation framework. Many agencies are ill-equipped to reproduce tests conducted by organizations such as NIST since they cannot verify the results with their equipment and in many cases rely solely on an independent validation study of other peoples' equipment. This creates the issue of tools in reality never being tested. Studies have shown that independent validation and verification of complex Forensic tools is expensive and time consuming, and many practitioners also use tools that were not originally designed for Forensic purposes. This paper explores the issues of validation and verification in the accreditation environment and proposes a paradigm that will reduce the time and expense required to validate and verify Forensic Software tools