Open source forensic tools for linux hard disk investigation
As the adoption of the Linux operating system is continually increasing there is a need to document the procedures for forensically examining its hard disk, which is arguably the most valuable source of criminal evidence in a computer system. The presently available material can be described as bein...
Saved in:
Main Author: | |
---|---|
Format: | Thesis |
Language: | English |
Published: |
2010
|
Subjects: | |
Online Access: | http://eprints.utm.my/id/eprint/12067/1/BasharAminMareeMFSKSM2010.pdf |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
id |
my-utm-ep.12067 |
---|---|
record_format |
uketd_dc |
spelling |
my-utm-ep.120672018-05-30T02:49:15Z Open source forensic tools for linux hard disk investigation 2010-04 Amin Maree, Bashar (Moh'd Walid) QA75 Electronic computers. Computer science As the adoption of the Linux operating system is continually increasing there is a need to document the procedures for forensically examining its hard disk, which is arguably the most valuable source of criminal evidence in a computer system. The presently available material can be described as being too technical, scattered and in some instances outdated. This project aims to highlight the procedures needed to forensically investigate a Linux hard disk using open source tools. Current guidelines have been reviewed in an attempt to extract focal areas that need attention in terms of forensic investigation. The adopted methodology, in this project, consisted of compiling a series of experiments using various open source tools to demonstrate the stages of a complete hard disk digital investigation. The flow of the experiments exhibited the basic concepts needed for understanding volume and file system investigation on a Linux system. The main forensic stages that were covered are the preparation, imaging, volume analysis and file system analysis stages. Additionally the work also exhibited the feasibility of using open source forensic technology. The outcome of this project was a set of clearly defined procedures for the purpose of facilitating the task of a forensic practitioner to digitally investigate a Linux environment. It demonstrated the use of open source forensic methods using the most recent Linux platform at the time of writing. The main advantage of such an approach is its potential to be academically verified and improved and possibly to be eventually adopted in law enforcement agencies. Moreover, it enables unrestricted control of code and development rights of a highly needed security technology without the constraints of a commercially driven market. 2010-04 Thesis http://eprints.utm.my/id/eprint/12067/ http://eprints.utm.my/id/eprint/12067/1/BasharAminMareeMFSKSM2010.pdf application/pdf en public masters Universiti Teknologi Malaysia, Faculty of Computer Science and Information Systems Faculty of Computer Science and Information System |
institution |
Universiti Teknologi Malaysia |
collection |
UTM Institutional Repository |
language |
English |
topic |
QA75 Electronic computers Computer science |
spellingShingle |
QA75 Electronic computers Computer science Amin Maree, Bashar (Moh'd Walid) Open source forensic tools for linux hard disk investigation |
description |
As the adoption of the Linux operating system is continually increasing there is a need to document the procedures for forensically examining its hard disk, which is arguably the most valuable source of criminal evidence in a computer system. The presently available material can be described as being too technical, scattered and in some instances outdated. This project aims to highlight the procedures needed to forensically investigate a Linux hard disk using open source tools. Current guidelines have been reviewed in an attempt to extract focal areas that need attention in terms of forensic investigation. The adopted methodology, in this project, consisted of compiling a series of experiments using various open source tools to demonstrate the stages of a complete hard disk digital investigation. The flow of the experiments exhibited the basic concepts needed for understanding volume and file system investigation on a Linux system. The main forensic stages that were covered are the preparation, imaging, volume analysis and file system analysis stages. Additionally the work also exhibited the feasibility of using open source forensic technology. The outcome of this project was a set of clearly defined procedures for the purpose of facilitating the task of a forensic practitioner to digitally investigate a Linux environment. It demonstrated the use of open source forensic methods using the most recent Linux platform at the time of writing. The main advantage of such an approach is its potential to be academically verified and improved and possibly to be eventually adopted in law enforcement agencies. Moreover, it enables unrestricted control of code and development rights of a highly needed security technology without the constraints of a commercially driven market. |
format |
Thesis |
qualification_level |
Master's degree |
author |
Amin Maree, Bashar (Moh'd Walid) |
author_facet |
Amin Maree, Bashar (Moh'd Walid) |
author_sort |
Amin Maree, Bashar (Moh'd Walid) |
title |
Open source forensic tools for linux hard disk investigation |
title_short |
Open source forensic tools for linux hard disk investigation |
title_full |
Open source forensic tools for linux hard disk investigation |
title_fullStr |
Open source forensic tools for linux hard disk investigation |
title_full_unstemmed |
Open source forensic tools for linux hard disk investigation |
title_sort |
open source forensic tools for linux hard disk investigation |
granting_institution |
Universiti Teknologi Malaysia, Faculty of Computer Science and Information Systems |
granting_department |
Faculty of Computer Science and Information System |
publishDate |
2010 |
url |
http://eprints.utm.my/id/eprint/12067/1/BasharAminMareeMFSKSM2010.pdf |
_version_ |
1747814892744736768 |