Skip to main content
Article
Testing the forensic soundness of forensic examination environments on bootable media
Digital Investigation
  • Ahmed Fathy Abdul Latif Mohamed, Zayed University
  • Andrew Marrington, Zayed University
  • Farkhund Iqbal, Zayed University
  • Ibrahim Baggili, University of New Haven
Document Type
Conference Proceeding
Publication Date
1-1-2014
Abstract

In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is performed on the image files. The differential analysis allows us to quantify and explain the alterations made to the image files by the bootable CD/DVD examination. Our approach can be used to experimentally validate new bootable CD/DVD distributions as forensically sound.

Publisher
Digital Forensic Research Workshop
Disciplines
Keywords
  • Computer crime,
  • Computer hardware,
  • Computer operating systems,
  • Electronic crime countermeasures,
  • Hash functions,
  • Image acquisition,
  • Image analysis,
  • Bootable CD,
  • Bootable examination environment,
  • Differential analysis,
  • Forensic analysis,
  • Forensic examinations,
  • Hash value,
  • Image files,
  • Linux distributions,
  • Computer forensics
Scopus ID

84904624668

Creative Commons License
Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International
Indexed in Scopus
Yes
Open Access
Yes
Open Access Type
Hybrid: This publication is openly available in a subscription-based journal/series
Citation Information
Ahmed Fathy Abdul Latif Mohamed, Andrew Marrington, Farkhund Iqbal and Ibrahim Baggili. "Testing the forensic soundness of forensic examination environments on bootable media" Digital Investigation Vol. 11 Iss. 2 (2014) p. S22 - S29 ISSN: <p><a href="https://v2.sherpa.ac.uk/id/publication/issn/1742-2876" target="_blank">1742-2876</a></p>
Available at: http://works.bepress.com/andrew-marrington/34/