The role of operating systems in computer forensics

Ewa Huebner, Frans Alexander Henskens · ACM SIGOPS Operating Systems Review · 2008

Computer forensics is a multidisciplinary field concerned with the examination of computer systems which have been involved in criminal activity, either as an object or a tool of a crime. The aim of the investigator is to find information relevant to the case in question, as well as the chain of events leading to the creation of this information. In other words the questions to be answered are "What incriminating information is present in the system?" and "How did the incriminating information get there?"

Read the paper · More papers on PaperTik