Towards automated preprocessing of bulk data in digital forensic investigations using hash functions

Harald Baier · it - Information Technology · 2015

Abstract Handling bulk data (e. g. some terabytes of data) is a issue in contemporary digital forensics. Separating relevant data structures from irrelevant ones resembles finding the needle in the haystack. The article at hand presents and assesses automatic hash-based techniques to preprocess the input data with the goal to facilitate the investigator's job. We discuss concepts like blacklisting and whitelisting based on cryptographic hash functions and approximate matching, respectively. In case of two established process models for a lab and an on-site investigation, respectively, we describe how to jointly use these techniques to automatically get a pointer to the needle.

Read the paper · More papers on PaperTik