A proposal for automating investigations in live forensics

作者:Lee Seokhee; Savoldi Antonio; Lim Kyoung Soo; Park Jong Hyuk; Lee Sangjin
来源:Computer Standards & Interfaces, 2010, 32(5-6): 246-255.
DOI:10.1016/j.csi.2009.09.001

摘要

In this paper we present an XML-based framework, called XLIVE, which provides an efficient way to collect data in live forensic cases, according to well-known crime categories. XLIVE is a forensic automated framework that can be used in live forensic investigations for gathering live data on a Windows-based system. In addition, we have also implemented a proof-of-concept, called LRDS (Live Resource Detection System). This approach of examination will be used extensively to deal with terabyte/petabyte digital systems, where other approaches, such as a post-mortem analysis, cannot be adopted.

  • 出版日期2010-10