TY - GEN
T1 - A stepwise methodology for tracing computer usage
AU - Lee, Seung Bong
AU - Bang, Jewan
AU - Lim, Kyung Soo
AU - Kim, Jongsung
AU - Lee, Sangjin
PY - 2009
Y1 - 2009
N2 - In digital forensics investigation, a general method of investigating the suspect's computer was to duplicate storage media or image and then obtain the case-related data from these. However, the increase in the capacity of storage media made this method take much longer time. Also, this implies that more data can exist in the suspect's computer so that finding relevant data will take a lot of time and efforts. Moreover, in case where imaging of the entire disk is not possible due to legal matters, selective acquisition of data is needed. In this paper, we propose methods for selective acquisition of file system metadata, registry & prefetch files, web browser files, specific document files without duplicating or imaging the storage media. Furthermore, we suggest a method to analyze the acquired data stepwise and quickly and effectively trace the use of computer in the crime scene.
AB - In digital forensics investigation, a general method of investigating the suspect's computer was to duplicate storage media or image and then obtain the case-related data from these. However, the increase in the capacity of storage media made this method take much longer time. Also, this implies that more data can exist in the suspect's computer so that finding relevant data will take a lot of time and efforts. Moreover, in case where imaging of the entire disk is not possible due to legal matters, selective acquisition of data is needed. In this paper, we propose methods for selective acquisition of file system metadata, registry & prefetch files, web browser files, specific document files without duplicating or imaging the storage media. Furthermore, we suggest a method to analyze the acquired data stepwise and quickly and effectively trace the use of computer in the crime scene.
KW - PIM
KW - Pre-investigation
KW - Selectively acquisition
UR - http://www.scopus.com/inward/record.url?scp=73549122376&partnerID=8YFLogxK
U2 - 10.1109/NCM.2009.246
DO - 10.1109/NCM.2009.246
M3 - Conference contribution
AN - SCOPUS:73549122376
SN - 9780769537696
T3 - NCM 2009 - 5th International Joint Conference on INC, IMS, and IDC
SP - 1852
EP - 1857
BT - NCM 2009 - 5th International Joint Conference on INC, IMS, and IDC
T2 - NCM 2009 - 5th International Joint Conference on Int. Conf. on Networked Computing, Int. Conf. on Advanced Information Management and Service, and Int. Conf. on Digital Content, Multimedia Technology and its Applications
Y2 - 25 August 2009 through 27 August 2009
ER -