West Virginia University
Software for efficient file elimination in computer forensics investigations
Abstract
dc:description.abstractComputer forensics investigators, much more than with any other forensic discipline, must process an ever continuing increase of data. Fortunately, computer processing speed has kept pace and new processes are continuously being automated to sort through the voluminous amount of data. There exists an unfulfilled need for a simple, streamlined, standalone public tool for automating the computer forensics analysis process for files on a hard disk drive under investigation. A software tool has been developed to dramatically reduce the number of files that an investigator must individually examine. This tool utilizes the National Institute of Standards and Technology (NIST) National Software Reference Library (NSRL) database to automatically identify files by comparing hash values of files on the hard drive under investigation to "known good" files (e.g., unaltered application files) and "known bad" files (e.g., exploits). This tool then provides a much smaller list of "unknown" files to be closely examined.
Degree
thesis:*- Name thesis:degree_name
- MS
- Level thesis:degree_level
- Thesis
- Discipline thesis:degree_discipline
- Lane Department of Computer Science and Electrical Engineering
- Year dc:date.available
- 2004
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Davis, Chad Werner
- Contributors dc:contributor
-
- Roy S. Nutter, Jr.
Subjects
dc:subject × 2Identifiers
dc:identifier.*- Identifier
- https://researchrepository.wvu.edu/etd/1423
- OAI identifier oai:identifier
- oai:researchrepository.wvu.edu:etd-2426