Back to results

West Virginia University

Software for efficient file elimination in computer forensics investigations

Abstract

dc:description.abstract

Computer forensics investigators, much more than with any other forensic discipline, must process an ever continuing increase of data. Fortunately, computer processing speed has kept pace and new processes are continuously being automated to sort through the voluminous amount of data. There exists an unfulfilled need for a simple, streamlined, standalone public tool for automating the computer forensics analysis process for files on a hard disk drive under investigation. A software tool has been developed to dramatically reduce the number of files that an investigator must individually examine. This tool utilizes the National Institute of Standards and Technology (NIST) National Software Reference Library (NSRL) database to automatically identify files by comparing hash values of files on the hard drive under investigation to "known good" files (e.g., unaltered application files) and "known bad" files (e.g., exploits). This tool then provides a much smaller list of "unknown" files to be closely examined.

Degree

thesis:*
Name thesis:degree_name
MS
Level thesis:degree_level
Thesis
Discipline thesis:degree_discipline
Lane Department of Computer Science and Electrical Engineering
Year dc:date.available
2004

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Davis, Chad Werner
Contributors dc:contributor
  • Roy S. Nutter, Jr.

Subjects

dc:subject × 2

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:researchrepository.wvu.edu:etd-2426

Chain of custody

source
Harvested from
West Virginia University
Base URL
researchrepository.wvu.edu/do/oai/
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Davis, Chad Werner. Software for efficient file elimination in computer forensics investigations. Thesis thesis, 2004. https://doi.org/10.33915/etd.1423