...
首页> 外文期刊>Digital investigation >Testing the forensic soundness of forensic examination environments on bootable media
【24h】

Testing the forensic soundness of forensic examination environments on bootable media

机译:在可启动媒体上测试法证检查环境的法证健全性

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is performed on the image files. The differential analysis allows us to quantify and explain the alterations made to the image files by the bootable CD/DVD examination. Our approach can be used to experimentally validate new bootable CD/DVD distributions as forensically sound.
机译:在这项工作中,我们实验性地检查了将法证可启动CD / DVD用作法证检查环境的法证健全性。市场上有几种带有可引导CD / DVD的Linux发行版,它们被用作法医检查环境,用于对捕获的计算机系统进行法医分析。在可引导CD / DVD检查之前和之后,计算机系统的硬盘被卸下,第二个系统使用硬件写入阻止程序获取法医图像。对可引导CD / DVD检查之前和之后获取的图像进行哈希处理,并对哈希值进行比较。在哈希值不一致的情况下,会对图像文件执行差异分析。差异分析使我们能够量化和解释可引导CD / DVD检查对映像文件所做的更改。我们的方法可用于通过实验验证新的可引导CD / DVD发行版是否具有鉴证能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号