Publication | Closed Access
A Formalization of Digital Forensics.
64
Citations
4
References
2004
Year
Unknown Venue
EngineeringInformation SecurityForensic ModelDigital InvestigationVerificationInformation ForensicsForensic Investigative ProceduresSoftware AnalysisFormal VerificationForensic SearchForensic MedicineIntrusion Detection SystemNetworked Computer SystemsComputer ScienceComputer ForensicsNetwork ForensicsData SecurityForensic ProceduresFormal MethodsDigital Forensics
Forensic investigative procedures are used in the case of an intrusion into a networked computer system to detect the scope or nature of the attack. In many cases, the forensic procedures employed are constructed in an informal manner that can impede the effectiveness or integrity of the investigation. We propose a formal model for analyzing and constructing forensic procedures, showing the advantages of formalization. A mathematical description of the model will be presented demonstrating the construction of the elements and their relationships. The model highlights definitions and updating of forensic procedures, identification of attack coverage, and portability across different platforms. The forensic model is applied in a real-world scenario with focus on Linux and OS X.
| Year | Citations | |
|---|---|---|
Page 1
Page 1