Resident Data Pattern Analysis Using Sector Clustering for Storage Drive Forensics - IFIP - Lecture Notes in Computer Science Access content directly
Conference Papers Year : 2020

Resident Data Pattern Analysis Using Sector Clustering for Storage Drive Forensics

Abstract

Storage drives are huge reservoirs of digital evidence. The acquisition and examination of storage drives for evidentiary artifacts require enormous amounts of manual effort and computing resources, leading to huge case backlogs. This chapter describes a forensic triage methodology that leverages random sampling and unsupervised clustering to provide insights about the regions of interest on a storage drive. The number of sector samples to be evaluated during triage for legitimate inferences to be drawn about drive content is also discussed. Experiments involving storage drives of various capacities illustrate the effectiveness and utility of the extracted patterns for rapid drive triage.
Fichier principal
Vignette du fichier
503209_1_En_8_Chapter.pdf (728.46 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-03657232 , version 1 (02-05-2022)

Licence

Attribution

Identifiers

Cite

Nitesh Bharadwaj, Upasna Singh, Gaurav Gupta. Resident Data Pattern Analysis Using Sector Clustering for Storage Drive Forensics. 16th IFIP International Conference on Digital Forensics (DigitalForensics), Jan 2020, New Delhi, India. pp.137-157, ⟨10.1007/978-3-030-56223-6_8⟩. ⟨hal-03657232⟩
8 View
14 Download

Altmetric

Share

Gmail Facebook X LinkedIn More