{"id":{"repo_id":"wvu","oai_identifier":"oai:researchrepository.wvu.edu:etd-2426"},"canonical_url":"https://search.dev.ndltd.org/etd/wvu/oai:researchrepository.wvu.edu:etd-2426","repository":{"repo_id":"wvu","name":"West Virginia University","base_url":"https://researchrepository.wvu.edu/do/oai/"},"display":{"title":"Software for efficient file elimination in computer forensics investigations","abstract":"Computer forensics investigators, much more than with any other forensic discipline, must process an ever continuing increase of data. Fortunately, computer processing speed has kept pace and new processes are continuously being automated to sort through the voluminous amount of data. There exists an unfulfilled need for a simple, streamlined, standalone public tool for automating the computer forensics analysis process for files on a hard disk drive under investigation. A software tool has been developed to dramatically reduce the number of files that an investigator must individually examine. This tool utilizes the National Institute of Standards and Technology (NIST) National Software Reference Library (NSRL) database to automatically identify files by comparing hash values of files on the hard drive under investigation to \"known good\" files (e.g., unaltered application files) and \"known bad\" files (e.g., exploits). This tool then provides a much smaller list of \"unknown\" files to be closely examined.","abstract_html":"Computer forensics investigators, much more than with any other forensic discipline, must process an ever continuing increase of data. Fortunately, computer processing speed has kept pace and new processes are continuously being automated to sort through the voluminous amount of data. There exists an unfulfilled need for a simple, streamlined, standalone public tool for automating the computer forensics analysis process for files on a hard disk drive under investigation. A software tool has been developed to dramatically reduce the number of files that an investigator must individually examine. This tool utilizes the National Institute of Standards and Technology (NIST) National Software Reference Library (NSRL) database to automatically identify files by comparing hash values of files on the hard drive under investigation to &quot;known good&quot; files (e.g., unaltered application files) and &quot;known bad&quot; files (e.g., exploits). This tool then provides a much smaller list of &quot;unknown&quot; files to be closely examined.","abstract_has_math":false,"creators":["Davis, Chad Werner"],"institution":null,"degree_name":"MS","degree_level":"Thesis","degree_discipline":"Lane Department of Computer Science and Electrical Engineering","degree_department":null,"school":null,"contributors":["Roy S. Nutter, Jr."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2004,"date_issued":"2004-05-01T07:00:00Z","date_published":"2004-05-01T07:00:00Z","updated_at":"2026-07-24T06:15:40Z","subjects":["Electrical engineering","Computer science"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["https://researchrepository.wvu.edu/etd/1423"],"render_values":[{"text":"https://researchrepository.wvu.edu/etd/1423","href":"https://researchrepository.wvu.edu/etd/1423","code":true}]}]},"links":{"outbound_url":"https://doi.org/10.33915/etd.1423","outbound_label":"DOI","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Roy S. Nutter, Jr."]},{"key":"dc:creator","label":"Author","values":["Davis, Chad Werner"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2019-01-17T08:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Lane Department of Computer Science and Electrical Engineering"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["MS"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical engineering","Computer science"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://doi.org/10.33915/etd.1423","https://researchrepository.wvu.edu/etd/1423"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Computer forensics investigators, much more than with any other forensic discipline, must process an ever continuing increase of data. Fortunately, computer processing speed has kept pace and new processes are continuously being automated to sort through the voluminous amount of data. There exists an unfulfilled need for a simple, streamlined, standalone public tool for automating the computer forensics analysis process for files on a hard disk drive under investigation. A software tool has been developed to dramatically reduce the number of files that an investigator must individually examine. This tool utilizes the National Institute of Standards and Technology (NIST) National Software Reference Library (NSRL) database to automatically identify files by comparing hash values of files on the hard drive under investigation to \"known good\" files (e.g., unaltered application files) and \"known bad\" files (e.g., exploits). This tool then provides a much smaller list of \"unknown\" files to be closely examined."]},{"key":"dc:title","label":"Title","values":["Software for efficient file elimination in computer forensics investigations"]}]}],"canonical_facts":{"dc:contributor":["Roy S. Nutter, Jr."],"dc:creator":["Davis, Chad Werner"],"dc:date.available":["2019-01-17T08:00:00Z"],"dc:description.abstract":["Computer forensics investigators, much more than with any other forensic discipline, must process an ever continuing increase of data. Fortunately, computer processing speed has kept pace and new processes are continuously being automated to sort through the voluminous amount of data. There exists an unfulfilled need for a simple, streamlined, standalone public tool for automating the computer forensics analysis process for files on a hard disk drive under investigation. A software tool has been developed to dramatically reduce the number of files that an investigator must individually examine. This tool utilizes the National Institute of Standards and Technology (NIST) National Software Reference Library (NSRL) database to automatically identify files by comparing hash values of files on the hard drive under investigation to \"known good\" files (e.g., unaltered application files) and \"known bad\" files (e.g., exploits). This tool then provides a much smaller list of \"unknown\" files to be closely examined."],"dc:identifier":["https://doi.org/10.33915/etd.1423","https://researchrepository.wvu.edu/etd/1423"],"dc:subject":["Electrical engineering","Computer science"],"dc:title":["Software for efficient file elimination in computer forensics investigations"],"thesis:degree_discipline":["Lane Department of Computer Science and Electrical Engineering"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["MS"]},"updated_at":"2026-07-24T06:15:40Z"}