• DocumentCode
    147341
  • Title

    Towards a prototype for guidance and implementation of a standardized digital forensic investigation process

  • Author

    Valjarevic, Aleksandar ; Venter, H.S. ; Ingles, Melissa

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Pretoria, Pretoria, South Africa
  • fYear
    2014
  • fDate
    13-14 Aug. 2014
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Performing a digital forensic investigation requires a standardized and formalized process to be followed. There currently is neither an international standard formalizing such process nor does a global, harmonized digital forensic investigation process exist. Further, there exists no application that would guide a digital forensic investigator to efficiently implement such a process. This paper proposes the implementation of such a prototype in order to cater for this need. A comprehensive and harmonized digital forensic investigation process model has been proposed by the authors in their previous work and this model is used as a basis of the prototype. The prototype is in the form of a software application which would have two main functionalities. The first functionality would be to act as an expert system that can be used for guidance and training of novice investigators. The second functionality would be to enable reliable logging of all actions taken within the processes proposed in a comprehensive and harmonized digital forensic investigation process model. Ultimately, the latter functionality would enable the validation of use of a proper process. The benefits of such prototype include possible improvement in efficiency and effectiveness of an investigation due to the fact that clear guidelines will be provided when following the process for the course of the investigation. Another benefit includes easier training of novice investigators. The last, and possibly most important benefit, includes that higher admissibility of digital evidence as well as results and conclusions of digital forensic investigations will be possible due to the fact that it will be easier to show that the correct standardized process was followed.
  • Keywords
    authorisation; digital forensics; standardisation; comprehensive harmonized digital forensic investigation process model; digital evidence admissibility; digital forensic investigations; expert system; international standard; novice investigator guidance; novice investigator training; process validation; reliable action logging; software application; standardized-formalized digital forensic investigation process; Analytical models; Cryptography; Irrigation; ISO/IEC 27043; digital forensic investigation process model; digital forensics; harmonization; implementation prototype; standardization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Security for South Africa (ISSA), 2014
  • Conference_Location
    Johannesburg
  • Print_ISBN
    978-1-4799-3383-9
  • Type

    conf

  • DOI
    10.1109/ISSA.2014.6950488
  • Filename
    6950488