Storage and exchange formats for digital evidence

被引:6
|
作者
Flaglien, Anders O. [1 ]
Mallasvik, Aleksander [1 ]
Mustorp, Magnus [1 ]
Arnes, Andre [1 ,2 ]
机构
[1] Gjovik Univ Coll, Norwegian Informat Secur Lab, Gjovik, Norway
[2] Telenor Grp, N-0131 Oslo, Norway
关键词
Digital evidence; Digital forensics; Storage formats; Exchange formats; Intelligent analysis; SYSTEM;
D O I
10.1016/j.diin.2011.09.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital evidence is becoming increasingly important in a wide variety of criminal investigations. The formats used to store and exchange evidence can have a large impact on both the trustworthiness of evidence and the efficiency of the tools processing the evidence. Many digital evidence formats exist today, and it is important to evaluate the suitability of these formats based on their technical capabilities. We perform a comparative evaluation of the suitability of different formats by evaluating them against a set of evaluation criteria. Further, we discuss research based storage and exchange formats that aim to improve the representation, processing, and presentation of the evidence. These formats are key initiatives in developing new and more intelligent forensic analysis tools that take advantage of cloud computing and service oriented systems. (C) 2011 Elsevier Ltd. All rights reserved.
引用
收藏
页码:122 / 128
页数:7
相关论文
共 50 条