Skip to main content

Research Repository

Advanced Search

SlackStick : signature-based file identification for live digital forensics examinations

Hegarty, R; Haggerty, J

Authors

R Hegarty

J Haggerty



Abstract

A digital forensics investigation may involve procedures for both live forensics and for gathering evidence from a device in a forensics laboratory. Due to the focus on capturing volatile data during a live forensics investigation, tools have been developed that are aimed at capturing specific data surrounding state information. However, there may be circumstances whereby non-volatile data analysis, such as the identification of files of interest, is also required. In such an investigation, the ability to use file-wise, or hash, signatures is precluded due to pre-processing requirements by the forensics tools. Therefore, this paper presents SlackStick, a novel automated approach run from a USB memory device for the identification of files of interest or non-volatile evidence triage using an alternative signature scheme. Moreover, the approach may be used by inexpert users during a first-response phase of an investigation. The results of the case study presented in this paper demonstrate the applicability of the approach.

Citation

Hegarty, R., & Haggerty, J. (2015, September). SlackStick : signature-based file identification for live digital forensics examinations. Presented at 2015 European Intelligence and Security Informatics Conference, Manchester, UK

Presentation Conference Type Other
Conference Name 2015 European Intelligence and Security Informatics Conference
Conference Location Manchester, UK
Start Date Sep 7, 2015
End Date Sep 9, 2015
Acceptance Date Jun 24, 2015
Online Publication Date Jan 14, 2016
Publication Date Jan 14, 2016
Deposit Date Feb 3, 2020
Book Title 2015 European Intelligence and Security Informatics Conference
ISBN 9781479986576
DOI https://doi.org/10.1109/EISIC.2015.28
Publisher URL https://doi.org/10.1109/EISIC.2015.28
Related Public URLs http://www.eisic.eu/eisic2015/
Additional Information Event Type : Conference


Downloadable Citations