Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations

Digital forensics is the science concerned with discovering, preserving, and analyzing evidence on digital devices. The intent is to be able to determine what events have taken place, when they occurred, who performed them, and how they were performed. In order for an investigation to be effectiv...

Full description

Bibliographic Details
Main Author: Marziale, Lodovico
Format: Others
Published: ScholarWorks@UNO 2009
Subjects:
Online Access:http://scholarworks.uno.edu/td/1027
http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=2008&context=td
id ndltd-uno.edu-oai-scholarworks.uno.edu-td-2008
record_format oai_dc
spelling ndltd-uno.edu-oai-scholarworks.uno.edu-td-20082016-10-21T17:05:02Z Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations Marziale, Lodovico Digital forensics is the science concerned with discovering, preserving, and analyzing evidence on digital devices. The intent is to be able to determine what events have taken place, when they occurred, who performed them, and how they were performed. In order for an investigation to be effective, it must exhibit several characteristics. The results produced must be reliable, or else the theory of events based on the results will be flawed. The investigation must be comprehensive, meaning that it must analyze all targets which may contain evidence of forensic interest. Since any investigation must be performed within the constraints of available time, storage, manpower, and computation, investigative techniques must be efficient. Finally, an investigation must provide a coherent view of the events under question using the evidence gathered. Unfortunately the set of currently available tools and techniques used in digital forensic investigations does a poor job of supporting these characteristics. Many tools used contain bugs which generate inaccurate results; there are many types of devices and data for which no analysis techniques exist; most existing tools are woefully inefficient, failing to take advantage of modern hardware; and the task of aggregating data into a coherent picture of events is largely left to the investigator to perform manually. To remedy this situation, we developed a set of techniques to facilitate more effective investigations. To improve reliability, we developed the Forensic Discovery Auditing Module, a mechanism for auditing and enforcing controls on accesses to evidence. To improve comprehensiveness, we developed ramparser, a tool for deep parsing of Linux RAM images, which provides previously inaccessible data on the live state of a machine. To improve efficiency, we developed a set of performance optimizations, and applied them to the Scalpel file carver, creating order of magnitude improvements to processing speed and storage requirements. Last, to facilitate more coherent investigations, we developed the Forensic Automated Coherence Engine, which generates a high-level view of a system from the data generated by low-level forensics tools. Together, these techniques significantly improve the effectiveness of digital forensic investigations conducted using them. 2009-12-20T08:00:00Z text application/pdf http://scholarworks.uno.edu/td/1027 http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=2008&context=td University of New Orleans Theses and Dissertations ScholarWorks@UNO Computer Forensics Digital Forensics Digital Investigation File Carving Live Forensics RAM Forensics Forensic Discovery Forensic Discovery Auditing
collection NDLTD
format Others
sources NDLTD
topic Computer Forensics
Digital Forensics
Digital Investigation
File Carving
Live Forensics
RAM Forensics
Forensic Discovery
Forensic Discovery Auditing
spellingShingle Computer Forensics
Digital Forensics
Digital Investigation
File Carving
Live Forensics
RAM Forensics
Forensic Discovery
Forensic Discovery Auditing
Marziale, Lodovico
Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations
description Digital forensics is the science concerned with discovering, preserving, and analyzing evidence on digital devices. The intent is to be able to determine what events have taken place, when they occurred, who performed them, and how they were performed. In order for an investigation to be effective, it must exhibit several characteristics. The results produced must be reliable, or else the theory of events based on the results will be flawed. The investigation must be comprehensive, meaning that it must analyze all targets which may contain evidence of forensic interest. Since any investigation must be performed within the constraints of available time, storage, manpower, and computation, investigative techniques must be efficient. Finally, an investigation must provide a coherent view of the events under question using the evidence gathered. Unfortunately the set of currently available tools and techniques used in digital forensic investigations does a poor job of supporting these characteristics. Many tools used contain bugs which generate inaccurate results; there are many types of devices and data for which no analysis techniques exist; most existing tools are woefully inefficient, failing to take advantage of modern hardware; and the task of aggregating data into a coherent picture of events is largely left to the investigator to perform manually. To remedy this situation, we developed a set of techniques to facilitate more effective investigations. To improve reliability, we developed the Forensic Discovery Auditing Module, a mechanism for auditing and enforcing controls on accesses to evidence. To improve comprehensiveness, we developed ramparser, a tool for deep parsing of Linux RAM images, which provides previously inaccessible data on the live state of a machine. To improve efficiency, we developed a set of performance optimizations, and applied them to the Scalpel file carver, creating order of magnitude improvements to processing speed and storage requirements. Last, to facilitate more coherent investigations, we developed the Forensic Automated Coherence Engine, which generates a high-level view of a system from the data generated by low-level forensics tools. Together, these techniques significantly improve the effectiveness of digital forensic investigations conducted using them.
author Marziale, Lodovico
author_facet Marziale, Lodovico
author_sort Marziale, Lodovico
title Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations
title_short Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations
title_full Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations
title_fullStr Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations
title_full_unstemmed Advanced Techniques for Improving the Efficacy of Digital Forensics Investigations
title_sort advanced techniques for improving the efficacy of digital forensics investigations
publisher ScholarWorks@UNO
publishDate 2009
url http://scholarworks.uno.edu/td/1027
http://scholarworks.uno.edu/cgi/viewcontent.cgi?article=2008&context=td
work_keys_str_mv AT marzialelodovico advancedtechniquesforimprovingtheefficacyofdigitalforensicsinvestigations
_version_ 1718388070444695552