Validation and verification of computer forensic software tools-Searching Function

被引:36
作者
Guo, Yinghua [1 ]
Slay, Jill [1 ]
Beckett, Jason [1 ]
机构
[1] Univ S Australia, Def & Syst Inst, Adelaide, SA 5095, Australia
关键词
Electronic evidence; Computer forensics; Validation; Verification; Searching;
D O I
10.1016/j.diin.2009.06.015
中图分类号
TP [自动化技术、计算机技术];
学科分类号
080201 [机械制造及其自动化];
摘要
The process of using automated software has served law enforcement and the courts very well, and experienced detectives and investigators have been able to use their well-developed policing skills, in conjunction with the automated software, so as to provide sound evidence. However, the growth in the computer forensic field has created a demand for new software ( or increased functionality to existing software) and a means to verify that this software is truly "forensic'' i.e. capable of meeting the requirements of the 'trier of fact'. In this work, we present a scientific and systemical description of the computer forensic discipline through mapping fundamental functions required in the computer forensic investigation process. Based on the function mapping, we propose a more detailed functionality orientated validation and verification framework of computer forensic tools. We focus this paper on the searching function. We specify the requirements and develop a corresponding reference set to test any tools that possess the searching function. (C) 2009 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S12 / S22
页数:11
相关论文
共 29 条
[1]
[Anonymous], 2004, Digital Data Acquisition Tool Specification"
[2]
[Anonymous], 2009, STRENGTH FOR SCI US
[3]
[Anonymous], 2007, SOFTWARE VERIFICATIO
[4]
[Anonymous], GOOD PRACTICE GUIDE
[5]
APPEL E, 2005, REPORT DIGITAL EVIDE
[6]
BECKETT J, 2007, DIGITAL FORENSICS VA, P266
[7]
A hierarchical, objectives-based framework for the digital investigations process [J].
Beebe, Nicole Lang ;
Clark, Jan Guynes .
DIGITAL INVESTIGATION, 2005, 2 (02) :147-167
[8]
BOEHM BW, 1997, P C RES DIR SOFTW TE
[9]
BOGEN C, 2005, P 1 INT WORKSH SYST
[10]
BRIAN C, 2005, DIGITAL FORENSICS TO