Comparison of the Data Recovery Function of Forensic Tools

4Citations
Citations of this article
31Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Commercially-available digital forensic tools are often large, expensive, complex software products, offering a range of functions to assist in the investigation of digital artifacts. Several authors have raised concerns about the reliability of evidence derived from these tools. This is of particular importance because many forensic tools are closed source and, therefore, are only subject to black box evaluation. In addition, many of the individual functions integrated into forensic tools are available as standalone products, typically at a much lower cost or even free. This paper compares - rather than individually evaluates - the data recovery function of two forensic suites and three standalone non-forensic commercial applications. Experimental results demonstrate that all the tools have comparable performance with respect to the data recovery function. However, some variation exists in the data recovered by the tools. © IFIP International Federation for Information Processing 2013.

Cite

CITATION STYLE

APA

Buchanan-Wollaston, J., Storer, T., & Glisson, W. (2013). Comparison of the Data Recovery Function of Forensic Tools. In IFIP Advances in Information and Communication Technology (Vol. 410, pp. 331–347). https://doi.org/10.1007/978-3-642-41148-9_22

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free