Find in Library
Search millions of books, articles, and more
Indexed Open Access Databases
Adaptation of PyFlag to Efficient Analysis of Overtaken Computer Data Storage
oleh: Aleksander Byrski, Wojciech Stryjewski, Bartłomiej Czechowicz
| Format: | Article |
|---|---|
| Diterbitkan: | Association of Digital Forensics, Security and Law 2010-03-01 |
Deskripsi
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: 200%;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">Based on existing software aimed at investigation support in the analysis of computer data storage overtaken during investigation (PyFlag), an extension is proposed involving the introduction of dedicated components for data identification and filtering. Hash codes for popular software contained in NIST/NSRL database are considered in order to avoid unwanted files while searching and to classify them into several categories. The extension allows for further analysis, e.g. using artificial intelligence methods. The considerations are illustrated by the overview of the system's design.</span></span></span></p>