Title
A scalable file based data store for forensic analysis
Abstract
In the field of remote forensics, the GRR Response Rig has been used to access and store data from thousands of enterprise machines. Handling large numbers of machines requires efficient and scalable storage mechanisms that allow concurrent data operations and efficient data access, independent of the size of the stored data and the number of machines in the network. We studied the available GRR storage mechanisms and found them lacking in both speed and scalability. In this paper, we propose a new distributed data store that partitions data into database files that can be accessed independently so that distributed forensic analysis can be done in a scalable fashion. We also show how to use the NSRL software reference database in our scalable data store to avoid wasting resources when collecting harmless files from enterprise machines.
Year
DOI
Venue
2015
10.1016/j.diin.2015.01.016
Digital Investigation
Keywords
Field
DocType
sqlite,distributed database,distributed computing,incident response,evidence analysis
Data mining,Computer security,Reference database,Computer science,Software,Distributed database,Incident response,Distributed data store,Data operations,Data access,Database,Operating system,Scalability
Journal
Volume
Issue
ISSN
12
S1
1742-2876
Citations 
PageRank 
References 
3
0.41
11
Authors
3
Name
Order
Citations
PageRank
Flávio Cruz130.41
Andreas Moser230.41
Michael I. Cohen330.41