2012
DOI: 10.1016/j.diin.2012.05.003
|View full text |Cite
|
Sign up to set email alerts
|

A general strategy for differential forensic analysis

Abstract: a b s t r a c tThe dramatic growth of storage capacity and network bandwidth is making it increasingly difficult for forensic examiners to report what is present on a piece of subject media. Instead, analysts are focusing on what characteristics of the media have changed between two snapshots in time. To date different algorithms have been implemented for performing differential analysis of computer media, memory, digital documents, network traces, and other kinds of digital evidence. This paper presents an ab… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
8
0

Year Published

2014
2014
2023
2023

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 33 publications
(8 citation statements)
references
References 14 publications
0
8
0
Order By: Relevance
“…In order to quantify the changes made by the Windows PE operating system mounting process, a differential analysis was performed on the hard drive images taken before and after running Forensics2020. Differential analysis allows a forensic examiner to focus on the changes brought about as a result of the activity that takes place between the acquisition of an image A and the acquisition of an image B at a subsequent point in time [6]. Note that no images were acquired in the previous experiments.…”
Section: Methodsmentioning
confidence: 99%
“…In order to quantify the changes made by the Windows PE operating system mounting process, a differential analysis was performed on the hard drive images taken before and after running Forensics2020. Differential analysis allows a forensic examiner to focus on the changes brought about as a result of the activity that takes place between the acquisition of an image A and the acquisition of an image B at a subsequent point in time [6]. Note that no images were acquired in the previous experiments.…”
Section: Methodsmentioning
confidence: 99%
“…More generally, the primary deductive tool of forensics is differential analysis [7], which allows us to build a knowledge base of state transitions that are of significance, and gives us a framework for approaching new situations.…”
Section: What Is Forensic Computing?mentioning
confidence: 99%
“…The PMF approach is based upon the concept of differential forensic analysis, as described by Garfinkel, Nelson, and Young . Automated differential analysis techniques used in PMF involve the comparison of forensic images taken at different times or the comparison of forensic images to a common baseline (i.e., “gold image”).…”
Section: Related Workmentioning
confidence: 99%