作者: Rob Hegarty , John Haggerty
关键词: USB 、 Network forensics 、 Focus (computing) 、 Identification (information) 、 Computer forensics 、 Computer security 、 Information retrieval 、 Hash function 、 Scheme (programming language) 、 Digital forensics 、 Computer science
摘要: A digital forensics investigation may involve procedures for both live and gathering evidence from a device in laboratory. Due to the focus on capturing volatile data during investigation, tools have been developed that are aimed at specific surrounding state information. However, there be circumstances whereby non-volatile analysis, such as identification of files interest, is also required. In an ability use file-wise, or hash, signatures precluded due pre-processing requirements by tools. Therefore, this paper presents SlackStick, novel automated approach run USB memory interest triage using alternative signature scheme. Moreover, used inexpert users first-response phase investigation. The results case study presented demonstrate applicability approach.