首页> 外文学位 >A protocol for the forensic data acquisition of personal computer workstations.
【24h】

A protocol for the forensic data acquisition of personal computer workstations.

机译:用于个人计算机工作站取证数据的协议。

获取原文
获取原文并翻译 | 示例

摘要

Computer forensics is a relatively new and rapidly growing field that addresses the use of computer data as evidence in legal proceedings. As a relatively new field of study, little empirical research has been conducted pertaining to computer forensics. This lack of empirical research contributes to problems for practitioners and academics alike.;For the community of practitioners, problems arise from the dilemma of applying scientific methods to legal matters based on anecdotal training methods, and the academic community is hampered by a lack of theory in this evolving field. This research study is designed to provide benefits to both communities by utilizing a multi-method approach to identify a protocol for practitioners and lay a foundation for academic theory development.;This research addresses the initial and most frequently performed phase of computer forensic examinations, data acquisition. Within the data acquisition phase, this research specifically studies the data acquisition of personal computers, the most frequently encountered target of forensic data acquisitions. A multi-method approach is utilized to identify, classify, and evaluate the tasks forensic examiners perform during forensic data acquisitions of personal computer workstations by building upon the framework of Nute's (1996) dissertation that established a scientific basis for forensic science.;The first phase of this study utilizes inductive research and is largely based on Grounded Theory (Glaser and Strauss, 1967) to empirically identify and classify tasks performed during forensic data acquisitions. The second phase of this study uses a discursive analytic strategy to evaluate the identified tasks by two review panels of experts. One review panel consists of technical experts and the other consists of legal experts.;A protocol is provided for the forensic data acquisition of personal computer workstations based on 103 tasks identified by practitioners and evaluated by experts. Each task is presented with expert panel merit ratings, examiner performance measures, and conditional performance measures. Eight constraints were identified that influence the degree in which practitioners perform the identified tasks.;The protocol provides measures not previously available to practitioners, and this study demonstrates the use of Grounded Theory for forensic protocol development.
机译:计算机取证是一个相对较新且发展迅速的领域,致力于在法律诉讼中使用计算机数据作为证据。作为一个相对较新的研究领域,很少进行与计算机取证有关的经验研究。缺乏实证研究会给从业者和学者带来问题;对于从业者社区来说,问题源于将科学方法应用于基于传闻训练方法的法律问题上的两难处境,而学术界却因缺乏理论而受阻在这个不断发展的领域。这项研究旨在通过采用多种方法为从业者确定协议来为两个社区带来利益,并为学术理论的发展奠定基础。该研究解决了计算机法医检查,数据的初始和最常执行阶段收购。在数据采集阶段,这项研究专门研究了个人计算机的数据采集,这是法医数据采集中最常遇到的目标。通过在Nute(1996)论文的框架上建立法医科学的科学基础,利用一种多方法方法来识别,分类和评估法医检查员在获取个人计算机工作站的法医数据期间执行的任务。本研究的第二阶段利用归纳研究,主要基于扎根理论(Glaser和Strauss,1967),从经验上鉴定和分类法医数据采集过程中执行的任务。本研究的第二阶段使用了一种话语分析策略,以由两个专家评审小组评估已确定的任务。一个评审小组由技术专家组成,另一个由法律专家组成。;提供了一个协议,用于根据从业者识别并由专家评估的103个任务来获取个人计算机工作站的取证数据。每个任务都有专家小组绩效评估,考官绩效评估和条件绩效评估。确定了八个限制因素,这些限制因素会影响从业者执行已确定任务的程度。该协议提供了从业者以前无法获得的措施,本研究证明了扎根理论在法医协议开发中的用途。

著录项

  • 作者

    Carlton, Gregory H.;

  • 作者单位

    University of Hawai'i at Manoa.;

  • 授予单位 University of Hawai'i at Manoa.;
  • 学科 Computer Science.;Information Science.
  • 学位 Ph.D.
  • 年度 2006
  • 页码 343 p.
  • 总页数 343
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号