Skip to main content

2018 | OriginalPaper | Buchkapitel

12. Digital Forensic Tools Catalogue, a Reference Point for the Forensic Community

verfasst von : Mattia Epifani, Fabrizio Turchi

Erschienen in: Handling and Exchanging Electronic Evidence Across Europe

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

In the digital forensics community, there is no a general agreement on how to classify forensic tools related to the acquisition and analysis phases. The Digital Forensic Tools Catalogue has been developed flowing a bottom-up approach. Each tool has been distinguished on the basis of its own features and later it has been structured and classified in a coherent and sensible way. At the moment, the Catalogue, available on the web, includes about 1500 tools divided into two main branches: tools for the acquisition and tools for the analysis activities.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Fußnoten
1
European Informatics Data Exchange Framework for Court and Evidence, www.​evidenceproject.​eu.
 
2
Figure 12.2 represents a simplified view of the overall processes involved in a digital evidence handling , because it is not a sequential flow but it may be circular in some points, for example during the Analysis process, it may be possible to realize that some pieces of evidence have been disregarded, so it is necessary to come back to the Acquisition phase to perform a new acquisition activity.
 
3
LNK files, known as link files, allow to quickly access to files stored in different locations. They assume the features of the file they point to.
 
4
JumpList, part of the Windows systems starting with version 7, allow to swiftly access to the most used folders.
 
5
Artifact includes all the information stored in the registry of the system, related to users or system activities, In Windows system examples of artifact are: file download, file opening/creation, programs. execution, USB or Drive usages, Account usage, Browser usage, etc.
 
6
The total number does not correspond to the algebraic sum of the acquisition and analysis tools, because some tools belong to both branches.
 
7
The chronological representation of the events occurred in a given time frame, rebuilt through digital traces left on a digital device.
 
9
Il National Institute of Standards and Technology. NIST is a government agency of the USA that deals with technologies.
 
Literatur
Zurück zum Zitat ISO/IEC 27037: Information technology – Security techniques – Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence. http://www.iso.org/iso/catalogue_detail?csnumber=44381 (2012) ISO/IEC 27037: Information technology – Security techniques – Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence. http://​www.​iso.​org/​iso/​catalogue_​detail?​csnumber=​44381 (2012)
Zurück zum Zitat ISO/IEC 27042: Information Technology – Security Techniques – Guidelines for the Analysis and Interpretation of Digital Evidence. http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=44406 (2015) ISO/IEC 27042: Information Technology – Security Techniques – Guidelines for the Analysis and Interpretation of Digital Evidence. http://​www.​iso.​org/​iso/​iso_​catalogue/​catalogue_​tc/​catalogue_​detail.​htm?​csnumber=​44406 (2015)
Zurück zum Zitat ISO/IEC 27043: Information Technology – Security Techniques – Incident Investigation Principles and Processes. http://www.iso.org/iso/catalogue_detail.htm?csnumber=44407 (2015) ISO/IEC 27043: Information Technology – Security Techniques – Incident Investigation Principles and Processes. http://​www.​iso.​org/​iso/​catalogue_​detail.​htm?​csnumber=​44407 (2015)
Metadaten
Titel
Digital Forensic Tools Catalogue, a Reference Point for the Forensic Community
verfasst von
Mattia Epifani
Fabrizio Turchi
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-74872-6_12