Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Forensic Science and Technology (22)
- Legal Studies (22)
- Social and Behavioral Sciences (22)
- Computer Engineering (19)
- Engineering (19)
-
- Law (19)
- Computer Law (18)
- Electrical and Computer Engineering (18)
- Artificial Intelligence and Robotics (3)
- Criminology (2)
- Criminology and Criminal Justice (2)
- Cybersecurity (2)
- Sociology (2)
- Business (1)
- Business Law, Public Responsibility, and Ethics (1)
- Data Science (1)
- Evidence (1)
- Other Computer Engineering (1)
- Other Computer Sciences (1)
- Other Engineering (1)
- Science and Technology Law (1)
- Statistics and Probability (1)
- Theory and Algorithms (1)
- Institution
- Publication Year
- Publication
- Publication Type
Articles 31 - 34 of 34
Full-Text Articles in Information Security
The Impact Of Hard Disk Firmware Steganography On Computer Forensics, Iain Sutherland, Gareth Davies, Nick Pringle, Andrew Blyth
The Impact Of Hard Disk Firmware Steganography On Computer Forensics, Iain Sutherland, Gareth Davies, Nick Pringle, Andrew Blyth
Journal of Digital Forensics, Security and Law
The hard disk drive is probably the predominant form of storage media and is a primary data source in a forensic investigation. The majority of available software tools and literature relating to the investigation of the structure and content contained within a hard disk drive concerns the extraction and analysis of evidence from the various file systems which can reside in the user accessible area of the disk. It is known that there are other areas of the hard disk drive which could be used to conceal information, such as the Host Protected Area and the Device Configuration Overlay. There …
An Evaluation Of Windows-Based Computer Forensics Application Software Running On A Macintosh, Gregory H. Carlton
An Evaluation Of Windows-Based Computer Forensics Application Software Running On A Macintosh, Gregory H. Carlton
Journal of Digital Forensics, Security and Law
The two most common computer forensics applications perform exclusively on Microsoft Windows Operating Systems, yet contemporary computer forensics examinations frequently encounter one or more of the three most common operating system environments, namely Windows, OS-X, or some form of UNIX or Linux. Additionally, government and private computer forensics laboratories frequently encounter budget constraints that limit their access to computer hardware. Currently, Macintosh computer systems are marketed with the ability to accommodate these three common operating system environments, including Windows XP in native and virtual environments. We performed a series of experiments to measure the functionality and performance of the two …
The Forensics Aspects Of Event Data Recorders, Jeremy S. Daily, Nathan Singleton, Elizabeth Downing, Gavin W. Manes
The Forensics Aspects Of Event Data Recorders, Jeremy S. Daily, Nathan Singleton, Elizabeth Downing, Gavin W. Manes
Journal of Digital Forensics, Security and Law
The proper generation and preservation of digital data from Event Data Recorders (EDRs) can provide invaluable evidence to automobile crash reconstruction investigations. However, data collected from the EDR can be difficult to use and authenticate, complicating the presentation of such information as evidence in legal proceedings. Indeed, current techniques for removing and preserving such data do not meet the court’s standards for electronic evidence. Experimentation with an EDR unit from a 2001 GMC Sierra pickup truck highlighted particular issues with repeatability of results. Fortunately, advances in the digital forensics field and memory technology can be applied to EDR analysis in …
Providing A Foundation For Analysis Of Volatile Data Stores, Timothy Vidas
Providing A Foundation For Analysis Of Volatile Data Stores, Timothy Vidas
Journal of Digital Forensics, Security and Law
Current threats against typical computer systems demonstrate a need for forensic analysis of memory-resident data in addition to the conventional static analysis common today. Certain attacks and types of malware exist solely in memory and leave little or no evidentiary information on nonvolatile stores such as a hard disk drive. The desire to preserve system state at the time of response may even warrant memory acquisition independent of perceived threats and the ability to analyze the acquired duplicate.
Tools capable of duplicating various types of volatile data stores are becoming widely available. Once the data store has been duplicated, current …