首页> 外文期刊>Security and Communications Networks >Effectiveness of file-based deduplication in digital forensics
【24h】

Effectiveness of file-based deduplication in digital forensics

机译:数字取证中基于文件的重复数据删除的有效性

获取原文
获取原文并翻译 | 示例

摘要

Over the last decades, the increasing amount of storage became a pressing problem for forensic investigators. This is caused by the computerization of everyday life and the associated increasing number of different devices in typical households. Considering multi-terabyte storage on the suspects' side, even more storage requirements emerge on the side of the investigator for secure backup and working copies. In this paper, we improve the standardized forensic process by proposing to rigorously use file deduplication across devices as well as file whitelisting in investigations in order to reduce the amount of data that needs to be stored for analysis as early as during data acquisition. These improvements happen in an automatic fashion and are completely transparent to the forensic investigator. They may furthermore be added without negative effects to the chain of custody or artifact validity in court and are evaluated in a realistic use case. Additionally, we illustrate the effectivity of our proposed approach on a real-world corpus by showing a notable reduction in number of reduced files as well as storage. Copyright (c) 2016 John Wiley & Sons, Ltd.
机译:在过去的几十年中,不断增加的存储量已成为法医研究人员的紧迫问题。这是由于日常生活的计算机化以及典型家庭中相关设备数量的不断增加引起的。考虑到犯罪嫌疑人方面的多TB存储,调查人员方面对安全备份和工作副本提出了更多存储要求。在本文中,我们通过建议跨设备严格使用文件重复数据删除以及在调查中使用文件白名单来改进标准化的取证过程,以减少早在数据采集期间就需要存储进行分析的数据量。这些改进是自动进行的,对法医调查员是完全透明的。此外,可以在法庭上对监护权或人工制品有效性链没有负面影响的情况下添加它们,并在实际的用例中对其进行评估。此外,我们通过显示减少的文件数量和存储数量的显着减少,说明了我们提出的方法在现实语料库上的有效性。版权所有(c)2016 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号