skip to main content
article
Free Access

Risks of live digital forensic analysis

Published:01 February 2006Publication History
Skip Abstract Section

Abstract

Live analysis tools have made a significant difference in capturing evidence during forensic investigations. Such tools, however, are far from infallible.

References

  1. Carrier, B.D. File System Forensic Analysis. Addison Wesley, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Carrier, B.D. The Sleuth Kit; www.sleuthkit.org/.Google ScholarGoogle Scholar
  3. Carrier, B.D. and Grand, J. A. hardware-based memory acquisition procedure for digital investigations. J. Digital Investigation 1, 1 (Mar. 2004). Google ScholarGoogle ScholarDigital LibraryDigital Library
  4. Cogswell, B. and Russinovich, M. RootkitRevealer; www.sysinternals.com.Google ScholarGoogle Scholar
  5. Guidance Software. EnCase Enterprise; www.encase.com.Google ScholarGoogle Scholar
  6. Hoglund, G. and Butler, J. Rootkits: Subverting the Windows Kernel. Addison Wesley, 2005. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. Mandia, K., Prosise, C. and Pepe, M. Incident Response and Computer Forensics 2nd Ed. McGraw-Hill, 2003. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Petroni, Jr., N.L., Fraser, T., Molina, J., and Arbaugh, W.A. Copilot---A coprocessor-based kernel runtime integrity monitor. In Proceedings of 13th Annual USENIX Security Symposium (Aug. 2004). Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. Skoudis, E. Malware: Fighting Malicious Code. Prentice Hall, 2004. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. Technology Pathways. ProDiscover Incident Response; www.techpathways.com/.Google ScholarGoogle Scholar
  11. Thompson, K. Reflections on trusting trust. Commun. ACM 27, 8 (Aug. 1984). Google ScholarGoogle ScholarDigital LibraryDigital Library
  12. Wang, Y-M, Beck, D., Vo, B., Roussev, R., and Verbowski, C. Detecting stealth software with strider GhostBuster. In Proceedings of 2005 International Conference on Dependable Systems and Networks (June 2005). Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. Risks of live digital forensic analysis

          Recommendations

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in

          Full Access

          • Published in

            cover image Communications of the ACM
            Communications of the ACM  Volume 49, Issue 2
            Next-generation cyber forensics
            February 2006
            127 pages
            ISSN:0001-0782
            EISSN:1557-7317
            DOI:10.1145/1113034
            Issue’s Table of Contents

            Copyright © 2006 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 1 February 2006

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • article

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader

          HTML Format

          View this article in HTML Format .

          View HTML Format