Automated network triage

被引:11
作者
Koopmans, Martin B. [1 ]
James, Joshua I. [1 ]
机构
[1] Univ Coll Dublin, Digital Forens Invest Res Grp DigitalFIRE, Dublin 4, Ireland
关键词
Digital investigation automation; Digital forensic triage analysis; Digital forensic preview analysis; Open source digital forensic investigation; On scene digital analysis; Law Enforcement;
D O I
10.1016/j.diin.2013.03.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In many police investigations today, computer systems are somehow involved. The number and capacity of computer systems needing to be seized and examined is increasing, and in some cases it may be necessary to quickly find a single computer system within a large number of computers in a network. To investigate potential evidence from a large quantity of seized computer system, or from a computer network with multiple clients, triage analysis may be used. In this work we first define triage based on the medical definition. From this definition, we describe a PXE-based client-server environment that allows for triage tasks to be conducted over the network from a central triage server. Finally, three real world cases are described in which the proposed triage solution was used. (C) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:129 / 137
页数:9
相关论文
共 14 条
  • [1] ADF, 2013, ADF TRIAG EX
  • [2] Carrier BD, 2010, SLEUTH KIT AUTOPSY F
  • [3] Carrier BD, 2005, SLEUTHKIT AUTOPSY FO
  • [4] Dell, 2011, DIG FOR SOL BLUEPR
  • [5] Dell, 2011, DIG FOR
  • [6] Dell, 2010, DELLS DIG FOR COLL S
  • [7] Goldman J, 2013, ALMOST EVERY CRIME N
  • [8] Heinz D., 2011, CLIENT MANAGEMENT BL
  • [9] James JI, 2013, PROJECT ATOM
  • [10] Koopmans M, 2010, COMPUTER SCI INFORM, P51