论文标题
现代数字法医成像软件的功能比较
A Feature Comparison of Modern Digital Forensic Imaging Software
论文作者
论文摘要
当数字调查相对较小时,开发了数字法医研究(例如磁盘成像)的基本过程。随着数字法医流程和程序的成熟,这些基本工具是重置数据处理和分析阶段的支柱,在很大程度上保持不变。这项工作是对现代数字法医成像软件工具的研究。具体来说,我们将研究现代数字法医成像工具的功能集,以及它们的开发和释放周期,以了解基本工具开发的模式。根据这项调查,我们显示了当前数字调查的弱点,随着时间的流逝,基本软件开发和维护。我们还提供有关如何改善基本工具的建议。
Fundamental processes in digital forensic investigation, such as disk imaging, were developed when digital investigation was relatively young. As digital forensic processes and procedures matured, these fundamental tools, that are the pillars of the reset of the data processing and analysis phases of an investigation, largely stayed the same. This work is a study of modern digital forensic imaging software tools. Specifically, we will examine the feature sets of modern digital forensic imaging tools, as well as their development and release cycles to understand patterns of fundamental tool development. Based on this survey, we show the weakness in current digital investigation fundamental software development and maintenance over time. We also provide recommendations on how to improve fundamental tools.