Abstract
In this paper we present an XML-based framework, called XLIVE, which provides an efficient way to collect data in live forensic cases, according to well-known crime categories. XLIVE is a forensic automated framework that can be used in live forensic investigations for gathering live data on a Windows-based system. In addition, we have also implemented a proof-of-concept, called LRDS (Live Resource Detection System). This approach of examination will be used extensively to deal with terabyte/petabyte digital systems, where other approaches, such as a post-mortem analysis, cannot be adopted.
Original language | English |
---|---|
Pages (from-to) | 246-255 |
Number of pages | 10 |
Journal | Computer Standards and Interfaces |
Volume | 32 |
Issue number | 5-6 |
DOIs | |
Publication status | Published - 2010 Oct |
Bibliographical note
Funding Information:This work was supported by the IT R&D program of MKE/IITA [ 2007-S019-03 , Development of Digital Forensic System for Information Transparency]. We also thank anonymous referees for the valuable comments on our research.
Keywords
- Automated digital investigation process
- Digital evidence collection
- Live forensics
- XML technology
ASJC Scopus subject areas
- Software
- Hardware and Architecture
- Law