Trusted by 2+ million users, 1000+ happy students everyday
Showing pages 1 to 1 of 2 pages
IntroductionMy project is to develop a forensic tool that is capable of mounting digital forensic evidence file of expert witness format (.E01) and perform simple searches on the evidence file while sharing of information is enabled between different users of the system. The basic understanding of the system will be that it will work similarly to a typical digital forensic tool but with limited functionalities as it is just a proof of concept. Real World ProblemsAlthough digital forensics field is considered a very professional and small field, there are still multiple major digital forensic tools available in the market both off the shelf and freeware. They each have their own strengths and weaknesses but they all share one common which is lack of customizability and sharing of information. These digital forensic tools that are commonly used are usually used the way it isas it is purchased or downloaded, users lack the capabilities of customizing the system for functions that they require or might not require. Furthermore, there is a lack of communication between these digital forensic tools which at times causes redundancy in work due to lack of communication. Forensic investigators are unable to communicate or check on the work done by others efficiently which may result slow progress in the investigation. SolutionsThe solution to solving the mentioned problem is to provide users with a system with customizability which enables the user to only select modules or functions that are required by the user to develop a system that fits the requirements of the user as best as possible. Another solution is to include a moduleor function that allows the communication between investigators to share notes or follow ups on the same case at the same time also implementing user access control. Modules Proposed to be included in the systemThe modules proposed are to be included into the system with minimal functionalities to proof the concept of the system. Mounting – The system is capable of mounting digital evidence files. The system will be able to mount files of Expert Witness Format (.E01) as a proof of concept with write-block capabilities. After mounting the evidence file, the evidence file will not be tampered with in any way while investigating which can be checked using the hash.Create .dd image – The system will not be mounting the original evidence file onto the filesystem to prevent contaminating the original evidence file. Hence, a .dd image will be created based on the original evidence file and the image created will be used to mount onto the filesystem where all investigation process will take place. The image created will be identical to the original digital evidence.Generate Hash – The system is capable of generating a hash value of the selected evidence file to be compared with the original hash value which is included in the original evidence file. Both hashes will be compared to prove that they are identical.
Found this document preview useful?
You are reading a preview Upload your documents to download or Become a Desklib member to get accesss