A Detailed Study of Advancements in Digital Forensics
摘要
Digital forensics is a complicated process with many variables. Every case tends to be different, with varied levels of complexity. This heterogeneous nature of work comes from the sheer number of different hardware and software involved. In some cases volatile memory is paramount, while in some cases browser cache and network logs become more helpful. In more common cases deleted data from storage drives helps in solving a case. These warrant the need of a mature framework for improving correctness and velocity of solving cases through better algorithms, machine learning and automation. Several frameworks and algorithms for forensic analysis of storage media, network, and volatile memory, have emerged in the past few years. Some implement methods for carving files while others offer faster analysis through machine learning. In this paper, we discuss methods and techniques that are used to acquire, analyse, present, and maintain the integrity of evidence.