Managing Terabyte-Scale Investigations with Similarity Digests - Advances in Digital Forensics VIII Access content directly
Conference Papers Year : 2012

Managing Terabyte-Scale Investigations with Similarity Digests

Abstract

The relentless increase in storage capacity and decrease in storage cost present an escalating challenge for digital forensic investigations – current forensic technologies are not designed to scale to the degree necessary to process the ever increasing volumes of digital evidence. This paper describes a similarity-digest-based approach that scales up the task of finding related digital artifacts in massive data sets. The results show that digests can be generated at rates exceeding those of cryptographic hashes on commodity multi-core computing systems. Also, the querying of the digest of a large (1 TB) target for the (trace) presence of a small file can be completed in less than one second with very high precision and recall rates.
Fichier principal
Vignette du fichier
978-3-642-33962-2_2_Chapter.pdf (1.16 Mo) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-01523709 , version 1 (16-05-2017)

Licence

Attribution

Identifiers

Cite

Vassil Roussev. Managing Terabyte-Scale Investigations with Similarity Digests. 8th International Conference on Digital Forensics (DF), Jan 2012, Pretoria, South Africa. pp.19-34, ⟨10.1007/978-3-642-33962-2_2⟩. ⟨hal-01523709⟩
41 View
111 Download

Altmetric

Share

Gmail Facebook X LinkedIn More