CENTRALIZED DIGITAL FORENSIC ANALYTICAL SYSTEM: RATIONALIZATION USING OPEN-SOURCE SOFTWARE OF GENERAL PURPOSES
Keywords:
digital forensics, open-source tools, NoSQL database, Bash scriptAbstract
Digital forensics is a part of the everyday work of law enforcement agencies and corporate security and has numerous challenges. Forensic investigators need to make a continual investment in new tools and methods of extracting data from a large number of different devices. They can save financial resources in the second critical phase of the digital forensics process, which is an analysis and search for evidence. This paper discusses the possibilities of development of a forensic analytical system which primarily enables cross-search through data and collaboration of investigators by using general purpose open-source tools. The main feature of the open-source tool is that they are mostly free of charge and free to use, which provides a significant saving. Bash scripts that organize tools and commands execution on the specific task allow a forensic investigator to create custom tools that meet their needs and increase job efficiency.
References
2. Garfinkel, S.L. (2010). Digital forensics research: The next 10 years. Digital Investigation, 7, 64-73.
3. Cohen, M.I., Bilby, D. & Caronni, G. (2011). Distributed forensics and incident response in the enterprise. Digital Investigation, 8, 101-110.
4. Hibshi, H., Vidas, T. & Cranor, L. (2011). Usability of Forensics Tools: A User Study. Sixth International Conference on IT Security Incident Management and IT Forensics, conference publications (Page 81-91). Stuttgart, Germany: Institute of Electrical and Electronics Engineers.
5. Bassett, R., Bass, L. & O’Brien, P. (2006). Computer Forensics: An Essential Ingredient for Cyber Security. Journal of Information Science and The Technology, 3(1), 22-32.
6. Meyers, M. & Rogers, M. (2005). Digital Forensics: Meeting the Challenges of Scientific Evidence. IFIP International Conference on Digital Forensics, conference publications (Page 43-50). Orlando, Florida, United States of America: National Center for Forensic Science.
7. Brian Carrier (2002) Open Source Digital Forensics Tools, The Legal Argument, Downloaded May 14, 2019 https://pdfs.semanticscholar.org/2825/a02f96a7962cff236443fbdd1d61931a071e.pdf.
8. Yates, M. (2010). Practical Investigations of Digital Forensics Tools for Mobile Devices. Information Security Curriculum Development Conference, conference publications (Page 156-162). Kennesaw, Georgia, United States of America: InfoSecCD ‘10.
9. Goode, S. (2005). Something for nothing: management rejection of open source software in Australia’s top firms. Information & Management, 42, 669–681.
10. Vidas, T., Kaplan, B. & Geiger, M. (2014). OpenLV: Empowering investigators and first-responders in the digital forensics process. Digital Investigation, 11, 45–53.
11. Raghavan, S. (2013). Digital forensic research: current state of the art. CSI Transactions on ICT, 1(1), 91-114.
12. Horsman, G. (2019). Tool testing and reliability issues in the field of digital forensics. Digital Investigation, 28, 163-175.
13. Federici, C. (2013). AlmaNebula: a computer forensics framework for the Cloud. Procedia Computer Science, 19, 139 – 146.
14. Roussev, V. (2011). Building Open and Scalable Digital Forensic Tools. Sixth IEEE International Workshop on Systematic Approaches to Digital Forensic Engineering. Oakland, California, United States of America: Institute of Electrical and Electronics Engineers.
15. Gyorodi, C., Gyorodi, R., Pecherle, G. & Olah, A. (2015). A Comparative Study: MongoDB vs. MySQL. 13th International Conference on Engineering of Modern Electric Systems, conference publications (Page 189). Oradea, Romania: Institute of Electrical and Electronics Engineers.
16. Wang, L. & Alexander, C. A. (2015). Big Data in Distributed Analytics, Cybersecurity, Cyber Warfare and Digital Forensics. Digital Technologies, 1(1), 22-27.
17. Boicea, A., Radulescu, F. & Agapin, L. I. (2012). MongoDB vs Oracle - database comparison. 3rd International Conference on Emerging Intelligent Data and Web Technologies, conference publications (Page 330-335). Bucharest, Romania: Institute of Electrical and Electronics Engineers.
18. Hirwani M., Pan Y. , Stackpole W. & Johnson D. (2012). Forensic Acquisition and Analysis of VM ware Virtual Hard Disks. International Conference on Security and Management. Las Vegas, Nevada, United States of America: University of Detroit Mercy.
19. Wu C. M., Huang, Y. F. & Lee, J. (2015). Comparisons Between MongoDB and MS-SQL Databases on the TWC Website. American Journal of Software Engineering and Applications, 4(2), 35-41.
20. Garfinkel, S. L. (2009). Automating Disk Forensic Processing with SleuthKit, XML and Python. Fourth International Systematic Approaches to Digital Forensic Engineering, International
Workshop. Oakland, California, United States of America: Institute of Electrical and Electronics Engineers.
21. Stadlinger, J. & Dewald, A. (2017). A Forensic Email Analysis Tool Using Dynamic Visualization . Journal of Digital Forensics, Security and Law, 1(12), 7-14.