Back to Search
Start Over
Can computer forensic tools be trusted in digital investigations?
- Source :
- Science & Justice. 61:198-203
- Publication Year :
- 2021
- Publisher :
- Elsevier BV, 2021.
-
Abstract
- This paper investigates whether computer forensic tools (CFTs) can extract complete and credible digital evidence from digital crime scenes in the presence of file system anti-forensic (AF) attacks. The study uses a well-established six stage forensic tool testing methodology based on black-box testing principles to carry out experiments that evaluate four leading CFTs for their potential to combat eleven different file system AF attacks. Results suggest that only a few AF attacks are identified by all the evaluated CFTs, while as most of the attacks considered by the study go unnoticed. These AF attacks exploit basic file system features, can be executed using simple tools, and even attack CFTs to accomplish their task. These results imply that evidences collected by CFTs in digital investigations are not complete and credible in the presence of AF attacks. The study suggests that practitioners and academicians should not absolutely rely on CFTs for evidence extraction from a digital crime scene, highlights the implications of doing so, and makes many recommendations in this regard. The study also points towards immediate and aggressive research efforts that are required in the area of computer forensics to address the pitfalls of CFTs.
- Subjects :
- File system
Exploit
Computers
Computer science
White-box testing
Forensic Sciences
010401 analytical chemistry
Computer forensics
Forensic Medicine
Computer security
computer.software_genre
01 natural sciences
0104 chemical sciences
Pathology and Forensic Medicine
Task (project management)
03 medical and health sciences
0302 clinical medicine
Digital evidence
Humans
Crime scene
Crime
030216 legal & forensic medicine
computer
Subjects
Details
- ISSN :
- 13550306
- Volume :
- 61
- Database :
- OpenAIRE
- Journal :
- Science & Justice
- Accession number :
- edsair.doi.dedup.....142a3a3b8e737c6e9a0e45cf29f5cc2a