• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

在数字调查中,计算机取证工具值得信赖吗?

Can computer forensic tools be trusted in digital investigations?

作者信息

Bhat Wasim Ahmad, AlZahrani Ali, Wani Mohamad Ahtisham

机构信息

Faculty of Computer & Information Systems, Islamic University of Madinah, Saudi Arabia; Department of Computer Sciences, University of Kashmir, India.

Faculty of Computer & Information Systems, Islamic University of Madinah, Saudi Arabia.

出版信息

Sci Justice. 2021 Mar;61(2):198-203. doi: 10.1016/j.scijus.2020.10.002. Epub 2020 Oct 28.

DOI:10.1016/j.scijus.2020.10.002
PMID:33736854
Abstract

This paper investigates whether computer forensic tools (CFTs) can extract complete and credible digital evidence from digital crime scenes in the presence of file system anti-forensic (AF) attacks. The study uses a well-established six stage forensic tool testing methodology based on black-box testing principles to carry out experiments that evaluate four leading CFTs for their potential to combat eleven different file system AF attacks. Results suggest that only a few AF attacks are identified by all the evaluated CFTs, while as most of the attacks considered by the study go unnoticed. These AF attacks exploit basic file system features, can be executed using simple tools, and even attack CFTs to accomplish their task. These results imply that evidences collected by CFTs in digital investigations are not complete and credible in the presence of AF attacks. The study suggests that practitioners and academicians should not absolutely rely on CFTs for evidence extraction from a digital crime scene, highlights the implications of doing so, and makes many recommendations in this regard. The study also points towards immediate and aggressive research efforts that are required in the area of computer forensics to address the pitfalls of CFTs.

摘要

本文研究了在存在文件系统反取证(AF)攻击的情况下,计算机取证工具(CFT)能否从数字犯罪现场提取完整且可信的数字证据。该研究采用了一种基于黑盒测试原则的成熟的六阶段取证工具测试方法,开展实验以评估四种领先的CFT应对十一种不同文件系统AF攻击的潜力。结果表明,所有评估的CFT仅能识别少数几种AF攻击,而该研究考虑的大多数攻击都未被察觉。这些AF攻击利用基本的文件系统功能,可使用简单工具执行,甚至能攻击CFT以完成其任务。这些结果意味着,在存在AF攻击的情况下,CFT在数字调查中收集的证据并不完整且不可信。该研究表明,从业者和学者不应绝对依赖CFT从数字犯罪现场提取证据,强调了这样做的影响,并在这方面提出了许多建议。该研究还指出,计算机取证领域需要立即开展积极的研究工作,以解决CFT的缺陷。

相似文献

1
Can computer forensic tools be trusted in digital investigations?在数字调查中,计算机取证工具值得信赖吗?
Sci Justice. 2021 Mar;61(2):198-203. doi: 10.1016/j.scijus.2020.10.002. Epub 2020 Oct 28.
2
When finding nothing may be evidence of something: Anti-forensics and digital tool marks.当一无所获可能成为某种证据时:反取证与数字工具痕迹
Sci Justice. 2019 Sep;59(5):565-572. doi: 10.1016/j.scijus.2019.06.004. Epub 2019 Jun 3.
3
Digital forensics: an analytical crime scene procedure model (ACSPM).数字取证:一种分析性犯罪现场程序模型 (ACSPM)。
Forensic Sci Int. 2013 Dec 10;233(1-3):244-56. doi: 10.1016/j.forsciint.2013.09.007. Epub 2013 Sep 13.
4
Crowdsourcing forensics: Creating a curated catalog of digital forensic artifacts.众包取证:创建一个经过策划的数字取证工具目录。
J Forensic Sci. 2022 Sep;67(5):1846-1857. doi: 10.1111/1556-4029.15053. Epub 2022 Jul 11.
5
The use of self-organising maps for anomalous behaviour detection in a digital investigation.自组织映射在数字调查中用于异常行为检测的应用。
Forensic Sci Int. 2006 Oct 16;162(1-3):33-7. doi: 10.1016/j.forsciint.2006.06.046. Epub 2006 Jul 27.
6
Digital forensic investigation methodology for Storage Space: Based on the NIST digital forensic process.
J Forensic Sci. 2022 May;67(3):989-1001. doi: 10.1111/1556-4029.14992. Epub 2022 Jan 28.
7
A toolbox for the rapid prototyping of crime scene reconstructions in virtual reality.虚拟现实中犯罪现场重建快速原型制作工具集。
Forensic Sci Int. 2019 Dec;305:110006. doi: 10.1016/j.forsciint.2019.110006. Epub 2019 Oct 24.
8
A glance at digital forensic academic research demographics.数字取证学术研究人口统计学概览。
Sci Justice. 2020 Sep;60(5):399-402. doi: 10.1016/j.scijus.2020.06.003. Epub 2020 Jun 18.
9
The invisible evidence: Digital forensics as key to solving crimes in the digital age.无形的证据:数字取证是解决数字时代犯罪的关键。
Forensic Sci Int. 2024 Sep;362:112133. doi: 10.1016/j.forsciint.2024.112133. Epub 2024 Jul 15.
10
Fingermarks in wildlife forensics: A review.野生动物法庭科学中的指纹:综述。
Forensic Sci Int. 2023 Sep;350:111781. doi: 10.1016/j.forsciint.2023.111781. Epub 2023 Jul 4.

引用本文的文献

1
Interpol review of digital evidence for 2019-2022.国际刑警组织对2019年至2022年数字证据的审查。
Forensic Sci Int Synerg. 2023 Jan 31;6:100313. doi: 10.1016/j.fsisyn.2022.100313. eCollection 2023.