首页> 外文OA文献 >Portable Storage Forensics: enhancing the value of USB device analysis and reporting
【2h】

Portable Storage Forensics: enhancing the value of USB device analysis and reporting

机译:便携式存储取证:增强UsB设备分析和报告的价值

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

USB based memory storage devices are an easy means of collecting and storing both legitimate and unlawful data. Due to their storage capacity and popularity of use, USB storage devices provide an important source of evidence to both law enforcement and corporate investigations. Digital forensic practitioners are frequently called upon to preserve, analyse, and report USB devices’ past connectivity history on Windows® based computer systems. Existing research and forensic analysis techniques have largely focused on USB artifacts related to the Windows® XP operating system. The release of the Windows® 7 operating system has created new avenues of USB artifact discovery for the digital forensics practitioner. Existing USB and related forensic software tools are plentiful; however, their source code and validation methods are rarely released for public or legal scrutiny. Likewise, there have been no published systematic toolset evaluations of the capabilities and functionality of existing toolsets related to USB device forensics. Consequently practitioners are limited in making the best toolset choices for their analysis needs. The problem area is USB memory storage device forensics. The purpose of this research was to provide a formal toolset evaluation of existing USB device analysis tools, and to develop a working prototype tool for use in future digital forensic examinations. A set of evaluation criteria was developed in order to identify gaps in existing tools’ functionality and reporting standards. The toolset evaluations found each of the tool samples had limitations in forensic functionality or reporting of USB storage devices. A Gap analysis identified three potential areas of improvement in analysis and reporting performance within the sample toolset. These gaps provided sufficient scope for the development of a new software reporting tool in order to add value to and enhance modern USB based forensic recovery techniques. A working prototype tool named USBForensicReporter© was specifically created as part of the research to support Windows® 7-based USB forensic examinations. The USBForensicReporter© tool provides both accurate and in-depth reporting of USB artifacts. The tool’s design has a unique physical USB device to evidence set comparative analysis method for associating USB storage devices to collected Windows® operating system and registry artifacts. None of evaluated sample tools had this level of comparative analysis whilst employing a single tool interface. In summary, the software development process was found to add examination value to the discipline of USB based memory device forensics. The developed prototype tool enhanced existing tool functions and providing new comparison analysis and reporting methods for digital forensic practitioners to utilise in the field. Recommendations for future research include releasing a final production version of the prototype software, developing additional tool support for older Windows® operating systems such as Windows® XP, and the anticipated release of the next version, Windows® 8. The toolset benchmarking process also has the potential to be expanded to include a greater range of USB forensic tools for digital forensic practitioners to evaluate.
机译:基于USB的存储设备是收集和存储合法和非法数据的简便方法。由于其存储容量和使用的普遍性,USB存储设备为执法和企业调查提供了重要的证据来源。经常要求数字取证从业人员在基于Windows®的计算机系统上保存,分析和报告USB设备的过去连接历史记录。现有的研究和取证分析技术主要集中在与Windows®XP操作系统有关的USB工件上。 Windows®7操作系统的发布为数字取证从业人员创造了USB伪影发现的新途径。现有的USB和相关的取证软件工具丰富;但是,很少公开其源代码和验证方法以进行公开或法律审查。同样,也没有公开的系统工具集评估与USB设备取证相关的现有工具集的功能。因此,从业人员在为他们的分析需求做出最佳工具集选择方面受到限制。问题区域是USB存储器存储设备取证。这项研究的目的是提供对现有USB设备分析工具的正式工具集评估,并开发一种可用于未来数字取证检查的工作原型工具。为了确定现有工具的功能和报告标准之间的差距,制定了一套评估标准。工具集评估发现,每个工具样本在取证功能或USB存储设备报告方面均存在局限性。差距分析确定了样本工具集中分析和报告性能方面三个潜在的改进领域。这些差距为开发新的软件报告工具提供了足够的空间,以便为基于现代USB的取证恢复技术增加价值并增强其价值。作为研究的一部分,专门创建了一个名为USBForensicReporter©的工作原型工具,以支持基于Windows®7的USB取证检查。 USBForensicReporter©工具可提供有关USB工件的准确和深入的报告。该工具的设计具有独特的物理USB设备,可提供证据集比较分析方法,以将USB存储设备与收集的Windows®操作系统和注册表工件相关联。在采用单个工具界面时,没有经过评估的样本工具具有这种水平的比较分析。总而言之,发现软件开发过程为基于USB的存储设备取证的学科增加了检查价值。开发的原型工具增强了现有工具的功能,并提供了新的比较分析和报告方法,供数字法医从业人员在现场使用。对未来研究的建议包括发布原型软件的最终生产版本,为较旧的Windows®操作系统(例如Windows®XP)开发其他工具支持,以及下一版本Windows®8的预期发布。工具集基准测试过程还具有潜力将扩大到包括更多种类的USB取证工具,供数字取证从业人员评估。

著录项

  • 作者

    Simms Mark;

  • 作者单位
  • 年度 2012
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号