Open source forensic tools for linux hard disk investigation

As the adoption of the Linux operating system is continually increasing there is a need to document the procedures for forensically examining its hard disk, which is arguably the most valuable source of criminal evidence in a computer system. The presently available material can be described as bein...

Full description

Saved in:
Bibliographic Details
Main Author: Amin Maree, Bashar (Moh'd Walid)
Format: Thesis
Language:English
Published: 2010
Subjects:
Online Access:http://eprints.utm.my/id/eprint/12067/1/BasharAminMareeMFSKSM2010.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
id my-utm-ep.12067
record_format uketd_dc
spelling my-utm-ep.120672018-05-30T02:49:15Z Open source forensic tools for linux hard disk investigation 2010-04 Amin Maree, Bashar (Moh'd Walid) QA75 Electronic computers. Computer science As the adoption of the Linux operating system is continually increasing there is a need to document the procedures for forensically examining its hard disk, which is arguably the most valuable source of criminal evidence in a computer system. The presently available material can be described as being too technical, scattered and in some instances outdated. This project aims to highlight the procedures needed to forensically investigate a Linux hard disk using open source tools. Current guidelines have been reviewed in an attempt to extract focal areas that need attention in terms of forensic investigation. The adopted methodology, in this project, consisted of compiling a series of experiments using various open source tools to demonstrate the stages of a complete hard disk digital investigation. The flow of the experiments exhibited the basic concepts needed for understanding volume and file system investigation on a Linux system. The main forensic stages that were covered are the preparation, imaging, volume analysis and file system analysis stages. Additionally the work also exhibited the feasibility of using open source forensic technology. The outcome of this project was a set of clearly defined procedures for the purpose of facilitating the task of a forensic practitioner to digitally investigate a Linux environment. It demonstrated the use of open source forensic methods using the most recent Linux platform at the time of writing. The main advantage of such an approach is its potential to be academically verified and improved and possibly to be eventually adopted in law enforcement agencies. Moreover, it enables unrestricted control of code and development rights of a highly needed security technology without the constraints of a commercially driven market. 2010-04 Thesis http://eprints.utm.my/id/eprint/12067/ http://eprints.utm.my/id/eprint/12067/1/BasharAminMareeMFSKSM2010.pdf application/pdf en public masters Universiti Teknologi Malaysia, Faculty of Computer Science and Information Systems Faculty of Computer Science and Information System
institution Universiti Teknologi Malaysia
collection UTM Institutional Repository
language English
topic QA75 Electronic computers
Computer science
spellingShingle QA75 Electronic computers
Computer science
Amin Maree, Bashar (Moh'd Walid)
Open source forensic tools for linux hard disk investigation
description As the adoption of the Linux operating system is continually increasing there is a need to document the procedures for forensically examining its hard disk, which is arguably the most valuable source of criminal evidence in a computer system. The presently available material can be described as being too technical, scattered and in some instances outdated. This project aims to highlight the procedures needed to forensically investigate a Linux hard disk using open source tools. Current guidelines have been reviewed in an attempt to extract focal areas that need attention in terms of forensic investigation. The adopted methodology, in this project, consisted of compiling a series of experiments using various open source tools to demonstrate the stages of a complete hard disk digital investigation. The flow of the experiments exhibited the basic concepts needed for understanding volume and file system investigation on a Linux system. The main forensic stages that were covered are the preparation, imaging, volume analysis and file system analysis stages. Additionally the work also exhibited the feasibility of using open source forensic technology. The outcome of this project was a set of clearly defined procedures for the purpose of facilitating the task of a forensic practitioner to digitally investigate a Linux environment. It demonstrated the use of open source forensic methods using the most recent Linux platform at the time of writing. The main advantage of such an approach is its potential to be academically verified and improved and possibly to be eventually adopted in law enforcement agencies. Moreover, it enables unrestricted control of code and development rights of a highly needed security technology without the constraints of a commercially driven market.
format Thesis
qualification_level Master's degree
author Amin Maree, Bashar (Moh'd Walid)
author_facet Amin Maree, Bashar (Moh'd Walid)
author_sort Amin Maree, Bashar (Moh'd Walid)
title Open source forensic tools for linux hard disk investigation
title_short Open source forensic tools for linux hard disk investigation
title_full Open source forensic tools for linux hard disk investigation
title_fullStr Open source forensic tools for linux hard disk investigation
title_full_unstemmed Open source forensic tools for linux hard disk investigation
title_sort open source forensic tools for linux hard disk investigation
granting_institution Universiti Teknologi Malaysia, Faculty of Computer Science and Information Systems
granting_department Faculty of Computer Science and Information System
publishDate 2010
url http://eprints.utm.my/id/eprint/12067/1/BasharAminMareeMFSKSM2010.pdf
_version_ 1747814892744736768