Applying filter clusters to reduce search state space

1Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Computer forensic tools must be both accurate and reliable so as not to miss vital evidence. While many investigations are conducted in sophisticated digital forensic laboratories, there is an increasing need to develop tools and techniques that could permit preliminary investigations to be carried out in the field. Pre-filtering electronic data in the field, before a computer is brought back to a laboratory for full investigation, can save valuable time. Filtering can also speed up in-house investigations by reducing search space size. This paper discusses the application of automated tools based on filters. In addition to helping reduce the search space, niters can support specific tasks such as locating and identifying encryption software and hidden, encrypted or compressed files. Filters may be used to automate tedious examinations of temporary Internet files, Windows directories or illicit images. Also, filters can facilitate customized searches based on patterns encountered in investigations of common cases. © 2006 International Federation for Information Processing.

Cite

CITATION STYLE

APA

Slay, J., & Jorgensen, K. (2006). Applying filter clusters to reduce search state space. IFIP International Federation for Information Processing, 194, 295–301. https://doi.org/10.1007/0-387-31163-7_24

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free