Title
Towards a prototype for guidance and implementation of a standardized digital forensic investigation process
Abstract
Performing a digital forensic investigation requires a standardized and formalized process to be followed. There currently is neither an international standard formalizing such process nor does a global, harmonized digital forensic investigation process exist. Further, there exists no application that would guide a digital forensic investigator to efficiently implement such a process. This paper proposes the implementation of such a prototype in order to cater for this need. A comprehensive and harmonized digital forensic investigation process model has been proposed by the authors in their previous work and this model is used as a basis of the prototype. The prototype is in the form of a software application which would have two main functionalities. The first functionality would be to act as an expert system that can be used for guidance and training of novice investigators. The second functionality would be to enable reliable logging of all actions taken within the processes proposed in a comprehensive and harmonized digital forensic investigation process model. Ultimately, the latter functionality would enable the validation of use of a proper process. The benefits of such prototype include possible improvement in efficiency and effectiveness of an investigation due to the fact that clear guidelines will be provided when following the process for the course of the investigation. Another benefit includes easier training of novice investigators. The last, and possibly most important benefit, includes that higher admissibility of digital evidence as well as results and conclusions of digital forensic investigations will be possible due to the fact that it will be easier to show that the correct standardized process was followed.
Year
DOI
Venue
2014
10.1109/ISSA.2014.6950488
Information Security for South Africa
Keywords
Field
DocType
authorisation,digital forensics,standardisation,comprehensive harmonized digital forensic investigation process model,digital evidence admissibility,digital forensic investigations,expert system,international standard,novice investigator guidance,novice investigator training,process validation,reliable action logging,software application,standardized-formalized digital forensic investigation process,ISO/IEC 27043,digital forensic investigation process model,digital forensics,harmonization,implementation prototype,standardization
Harmonization,Digital forensics,Computer security,Computer science,Expert system,Digital evidence,Software,International standard,Standardization
Conference
ISSN
Citations 
PageRank 
2330-9881
0
0.34
References 
Authors
5
3
Name
Order
Citations
PageRank
Aleksandar Valjarevic150.89
Hein S. Venter2588.01
Melissa Ingles300.34