PHAT: a P2P history analysis tool
John Cannatella, Sean J. Geoghegan · Journal of computing sciences in colleges · 2009
Peer-to-peer file sharing applications are used by many Internet users to quickly and efficiently copy files around the world. Many different tools provide the user with the ability to search for files based on keywords or file type and download files. Because files can be copied easily and efficiently by the general public, crimes that rely on the transfer of large amounts of data are becoming much more common. For example, music and movie piracy has greatly increased over the last several years. Currently, digital investigators follow a time-consuming manual process to analyze a suspect's hard drive for evidence of crimes committed via file sharing applications. Popular file sharing applications, such as LimeWire, were analyzed to determine the type and location of evidence that can be retrieved from the application's data files. A tool was developed to automatically extract this evidence and present it to the user in a form that is easily understood by digital investigators, attorneys, and jury members.