首页> 外文OA文献 >Methods for creating realistic disk images for forensics tool testing and education
【2h】

Methods for creating realistic disk images for forensics tool testing and education

机译:为取证工具测试和教育创建逼真的磁盘映像的方法

摘要

Both testing of computer storage forensics tools, and education in conducting computer forensics require reference drive images with known characteristics. Without a known ground-truth it is not possible to fully verify the ability of a tool or a student's analytical technique on whether they capture the important data residing on the drive. Due to privacy concerns existing corpa of drive images from real users cannot be used, so we must construct drive images that do not contain any privacy-related information. This paper discusses methods to generate drive images constructively and the concerns that must be taken into account to ensure they are realistic, reflecting not only the particular testing scenario desired, but also appropriate background noise. Further we discuss competing methods to accomplish this and propose a means of automating the entire process.
机译:计算机存储取证工具的测试以及进行计算机取证的教育都需要具有已知特征的参考驱动器映像。没有已知的事实,就无法完全验证工具或学生的分析技术是否能够捕获驱动器上的重要数据的能力。出于隐私方面的考虑,无法使用来自真实用户的现有驱动器映像的corpa,因此我们必须构造不包含任何与隐私相关的信息的驱动器映像。本文讨论了建设性地生成驱动器映像的方法,以及为确保它们逼真而必须考虑的问题,不仅反映了所需的特定测试场景,还反映了适当的背景噪声。此外,我们讨论了实现此目的的竞争方法,并提出了使整个过程自动化的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号