Title
An Evidence Acquisition Tool for Live Systems
Abstract
Evidence acquisition is concerned with the collection of evidence from digital devices for subsequent analysis and presentation. It is extremely important that the digital evidence is collected in a forensically-sound manner using acquisition tools that do not affect the integrity of the evidence. This paper describes a. forensic acquisition tool that may 1)e used to access files on a live system without compromising the state of the files in question. This is done in the context of the Reco Platform, an open source forensic framework that was used to develop the prototype evidence acquisition tool both quickly and efficiently. The paper also discusses the implementation of the prototype and the results obtained.
Year
DOI
Venue
2008
10.1007/978-0-387-84927-0_25
ADVANCES IN DIGITAL FORENSICS IV
Keywords
Field
DocType
live systems,evidence acquisition,Reco Platform
Data science,Computer science,Digital evidence
Conference
Volume
ISSN
Citations 
285
1571-5736
1
PageRank 
References 
Authors
0.40
9
2
Name
Order
Citations
PageRank
Renico Koen130.98
Martin S. Olivier246573.94