Automating case reports for the analysis of digital evidence

dc.contributor.advisorEagle, Chris
dc.contributor.authorCassidy, Regis H. Friend
dc.contributor.corporateNaval Postgraduate School
dc.contributor.departmentDepartment of Computer Science
dc.contributor.secondreaderDinolt, George W.
dc.date.accessioned2012-03-14T17:33:47Z
dc.date.available2012-03-14T17:33:47Z
dc.date.issued2005-09
dc.description.abstractThe reporting process during computer analysis is critical in the practice of digital forensics. Case reports are used to review the process and results of an investigation and serve multiple purposes. The investigator may refer to these reports to monitor the progress of his analysis throughout the investigation. When acting as an expert witness, the investigator will refer to organized documentation to recall past analysis. A lot of time can elapse between the analysis and the actual testimony. Specific reports may also be used in court as visual aids. Not all cases make it to court, but corporate managers will still likely want to review a case report. Since digital forensics is a relatively new field and can have a high learning curve, reports may be used as a mechanism for sharing knowledge of digital forensic practices. Existing open source forensics tools are an inexpensive alternative to commercial products, but lack the functionality to generate case reports. Open source tools are more likely to be accepted by the professional forensics community with this added capability. This thesis adds case report features to the Sleuth Kit and Autopsy Forensic Browser suite of tools, the premiere open-source forensics analysis software currently available.en_US
dc.description.distributionstatementApproved for public release; distribution is unlimited.
dc.description.urihttp://archive.org/details/automatingcasere109451993
dc.format.extentxvi, 217 p. : col. ill. ;en_US
dc.identifier.oclc62165816
dc.identifier.urihttps://hdl.handle.net/10945/1993
dc.publisherMonterey, California. Naval Postgraduate Schoolen_US
dc.subject.lcshComputer scienceen_US
dc.subject.lcshComputer crimesen_US
dc.subject.lcshInvestigationen_US
dc.titleAutomating case reports for the analysis of digital evidenceen_US
dc.typeThesisen_US
dspace.entity.typePublication
etd.thesisdegree.disciplineComputer Scienceen_US
etd.thesisdegree.grantorNaval Postgraduate Schoolen_US
etd.thesisdegree.levelMastersen_US
etd.thesisdegree.nameM.S.en_US
etd.verifiednoen_US
Files