Title :
Improving Performance in Digital Forensics: A Case Using Pattern Matching Board
Author :
Lee, Jooyoung ; Un, Sungkyung ; Hong, Dowon
Author_Institution :
Cryptography Res. Team, Electron. & Telecommun. Res. Inst., Daejeon
Abstract :
Due to recent advanced technology in the field of HDD, forensic investigators and analysts are dealing with terabyte data sets and spending tremendous time and effort in forensic investigations. It makes "Speed" one of the hot issues in digital forensics. To get speed up or to improve efficiency, some approaches have been proposed. One of them getting attention is a hardware-based approach. However, such a way is limitedly used in the field of evidence cloning or password cracking while rarely applied in search and analysis for the digital evidence. A general approach to the forensic search is to find specific text strings by comparing every byte of the digital evidence at the physical level. Besides, alternative approaches have been proposed for speedup of search and analysis process. They are usually based on the technologies such like indexing algorithms, distributed processing, and data mining. However, these methods have some drawbacks. Some require a lot of initial time for preprocessing, others are impractical. In order to solve this problem, we have already proposed an efficient and practical approach for forensic analysis in. In this paper, we present the system architecture and show feasibility and scalability of our approach by comparing its performance to those of a popular forensic tool currently on the market.
Keywords :
disc drives; hard discs; pattern matching; security of data; data mining; digital evidence; digital forensics; distributed processing; evidence cloning; forensic analysis; forensic search; hard disk drive; hardware-based approach; indexing algorithms; password cracking; pattern matching board; Availability; Cloning; Commercialization; Computer aided manufacturing; Digital forensics; Hard disks; Hardware; Image analysis; Image sequence analysis; Pattern matching; analysis; digital forensics; hardware-based approach; high-speed search tool; search mechanism;
Conference_Titel :
Availability, Reliability and Security, 2009. ARES '09. International Conference on
Conference_Location :
Fukuoka
Print_ISBN :
978-1-4244-3572-2
Electronic_ISBN :
978-0-7695-3564-7
DOI :
10.1109/ARES.2009.156