Abstract
In this paper we present an XML-based framework, called XLIVE, which provides an efficient way to collect data in live forensic cases, according to well-known crime categories. XLIVE is a forensic automated framework that can be used in live forensic investigations for gathering live data on a Windows-based system. In addition, we have also implemented a proof-of-concept, called LRDS (Live Resource Detection System). This approach of examination will be used extensively to deal with terabyte/petabyte digital systems, where other approaches, such as a post-mortem analysis, cannot be adopted.
| Original language | English |
|---|---|
| Pages (from-to) | 246-255 |
| Number of pages | 10 |
| Journal | Computer Standards and Interfaces |
| Volume | 32 |
| Issue number | 5-6 |
| DOIs | |
| Publication status | Published - 2010 Oct |
Bibliographical note
Funding Information:This work was supported by the IT R&D program of MKE/IITA [ 2007-S019-03 , Development of Digital Forensic System for Information Transparency]. We also thank anonymous referees for the valuable comments on our research.
Keywords
- Automated digital investigation process
- Digital evidence collection
- Live forensics
- XML technology
ASJC Scopus subject areas
- Software
- General Computer Science
- Hardware and Architecture
- Computer Science Applications
- Law