Download presentation
Presentation is loading. Please wait.
Published byLarry Atnip Modified over 10 years ago
1
Complex Recovery/ Data Reduction DFRWS 2002
2
Technical Issues Lots of info to be recovered in in deleted file space Partial data recovery: does this give us hints to missing data? Prosecutorial view vs. in-house investigation Data dependencies
3
Technical Issues, II Understanding the OS data structures is important for getting the data of interest Some of the science is actually art: not everything can be automated in a tractable manner
4
Legal Issues Preserving privacy for multi-user machines: only investigate the suspects: need tools to grab only the relevant data Scope of search: warrant amendment when new evidence surfaces
5
Policy Issues Acceptable use policies in corporate settings: make sure policies are in place BEFOREHAND so that there isnt a privacy problem collecting the data
6
Near Term Goals Development of toolkits to recover Collaboration among forensic examiners to suggest tool features LE needs tools to help do the job faster (huge hard drives; lots of cases): do image and hash in parallel; analyze while making image?
7
Longer Term Tools that implement expert systems Provide way to script rules for newly formed forensics techniques
Similar presentations
© 2024 SlidePlayer.com Inc.
All rights reserved.