Abstract | ||
---|---|---|
Evidence acquisition is concerned with the collection of evidence from digital devices for subsequent analysis and presentation. It is extremely important that the digital evidence is collected in a forensically-sound manner using acquisition tools that do not affect the integrity of the evidence. This paper describes a. forensic acquisition tool that may 1)e used to access files on a live system without compromising the state of the files in question. This is done in the context of the Reco Platform, an open source forensic framework that was used to develop the prototype evidence acquisition tool both quickly and efficiently. The paper also discusses the implementation of the prototype and the results obtained. |
Year | DOI | Venue |
---|---|---|
2008 | 10.1007/978-0-387-84927-0_25 | ADVANCES IN DIGITAL FORENSICS IV |
Keywords | Field | DocType |
live systems,evidence acquisition,Reco Platform | Data science,Computer science,Digital evidence | Conference |
Volume | ISSN | Citations |
285 | 1571-5736 | 1 |
PageRank | References | Authors |
0.40 | 9 | 2 |
Name | Order | Citations | PageRank |
---|---|---|---|
Renico Koen | 1 | 3 | 0.98 |
Martin S. Olivier | 2 | 465 | 73.94 |