Extending the advanced forensic format to accommodate multiple data sources, logical evidence, arbitrary information and forensic workflow

被引:39
作者
Cohen, Michael [1 ]
Garfinkel, Simson [1 ]
Schatz, Bradley [1 ]
机构
[1] Australian Fed Police, High Tech Crime Operat, Brisbane, Qld 4001, Australia
关键词
Digital forensics; Image; Hard disk Imaging; Digital Evidence Management; Distributed Storage; Distributed Forensic Analysis; Forensic File Format; Evidence Archiving; Cryptography; Forensic Integrity;
D O I
10.1016/j.diin.2009.06.010
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Forensic analysis requires the acquisition and management of many different types of evidence, including individual disk drives, RAID sets, network packets, memory images, and extracted files. Often the same evidence is reviewed by several different tools or examiners in different locations. We propose a backwards-compatible redesign of the Advanced Forensic Format-an open, extensible file format for storing and sharing of evidence, arbitrary case related information and analysis results among different tools. The new specification, termed AFF4, is designed to be simple to implement, built upon the well supported ZIP file format specification. Furthermore, the AFF4 implementation has downward comparability with existing AFF files. (C) 2009 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.
引用
收藏
页码:S57 / S68
页数:12
相关论文
共 23 条
[1]  
[Anonymous], 1994, Uniform Resource Locators (URL), document RFC 1738
[2]  
[Anonymous], 2005, 4122 RFC
[3]  
*BS, 2008, NTI FOR SOURC SAF BI
[4]  
Carrier B., 2004, DIG FOR RES WORKSH
[5]  
COHEN M, 2008, LOAD RAID SET PYFLAG
[6]   Advanced carving techniques [J].
Cohen, M. I. .
DIGITAL INVESTIGATION, 2007, 4 (3-4) :119-128
[7]  
COHEN MI, 2008, E FORENSICS 08, P1
[8]  
COHEN MI, 2008, P 2008 DIG FOR RES W
[9]  
Fielding R., 1999, Tech. Rep
[10]  
Fielding Roy T., 1995, 1808 RFC