Advanced Automated Disk Investigation Toolkit - Advances in Digital Forensics XII Access content directly
Conference Papers Year : 2016

Advanced Automated Disk Investigation Toolkit

Abstract

Open source software tools designed for disk analysis play a critical role in digital forensic investigations. The tools typically are onerous to use and rely on expertise in investigative techniques and disk structures. Previous research presented the design and initial development of a toolkit that can be used as an automated assistant in forensic investigations. This chapter builds on the previous work and presents an advanced automated disk investigation toolkit (AUDIT) that leverages a dynamic knowledge base and database. AUDIT has new reporting and inference functionality. It facilitates the investigative process by handling core information technology expertise, including the choice and operational sequence of tools and their configurations. The ability of AUDIT to serve as an intelligent digital assistant is evaluated using a series of tests that compare it against standard benchmark disk images and examine the support it provides to human investigators.
Fichier principal
Vignette du fichier
431606_1_En_20_Chapter.pdf (258.49 Ko) Télécharger le fichier
Origin : Files produced by the author(s)
Loading...

Dates and versions

hal-01758683 , version 1 (04-04-2018)

Licence

Attribution

Identifiers

Cite

Umit Karabiyik, Sudhir Aggarwal. Advanced Automated Disk Investigation Toolkit. 12th IFIP International Conference on Digital Forensics (DF), Jan 2016, New Delhi, India. pp.379-396, ⟨10.1007/978-3-319-46279-0_20⟩. ⟨hal-01758683⟩
50 View
226 Download

Altmetric

Share

Gmail Facebook X LinkedIn More