FriendlyRoboCopy: A GUI to RoboCopy for computer forensic investigators

被引:3
|
作者
LaVelle, Claire [1 ]
Konrad, Almudena
机构
[1] USN, Postgrad Sch, Monterey, CA 93940 USA
[2] Mills Coll, Dept Math & Comp Sci, Oakland, CA 94613 USA
关键词
digital forensics; network forensics; drive mapping; RoboCopy application; microsoft OS forensics; network system administration; NAS; computer cluster; graphical user interface; perl; open source application;
D O I
10.1016/j.diin.2007.01.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the most pressing challenges in digital investigations today is the extraction and forensic preservation of a subset of data on computer clusters and other large storage systems. As the number and capacity of computer systems increases, it is no longer feasible to create forensic duplicates of every system in their entirety. Although forensic tools are being developed to cope with such situations, they do not support all file systems. Experienced digital investigators use tools such as RoboCopy to preserve a subset of data on target systems, and take steps to document their process and results. This paper explores the need for these tools in digital investigations, and demonstrates the strengths and weaknesses of using RoboCopy to acquire data on a network share. This paper then introduces FriendlyRoboCopy, which provides an effective, user-friendly interface to RoboCopy that addresses the requirements of forensic preservation. (c) 2007 Elsevier Ltd. All rights reserved.
引用
收藏
页码:16 / 23
页数:8
相关论文
共 50 条