A systematic evaluation of disk imaging in EnCase® 6.8 and LinEn 6.1

Digital Investigation(2009)

引用 5|浏览0
暂无评分
摘要
Tools for disk imaging (or more generally speaking, digital acquisition) are a foundation for forensic examination of digital evidence. Therefore it is crucial that such tools work as expected. The only way to determine whether this is the case or not is through systematic testing of each tool. In this paper we present such an evaluation of the disk imaging functions of EnCase 6.8^(R) and LinEn 6.1, conducted on behalf of the Swedish National Laboratory of Forensic Science. Although both tools performed as expected under most circumstances, we identified cases where flaws that can lead to inaccurate and incomplete acquisition results in LinEn 6.1 were exposed. We have also identified limitations in the tool that were not evident from its documentation. In addition summarizing the test results, we present our testing methodology, which has novel elements that we think can benefit other evaluation projects.
更多
查看译文
关键词
systematic testing,Swedish National Laboratory,disk imaging function,LinEn,Linux,systematic evaluation,Testing forensic tools,incomplete acquisition result,Hard drive imaging,testing methodology,Acquisition of digital data,digital evidence,disk imaging,digital acquisition,Forensic Science,evaluation project,EnCase ®
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要