High speed search for large-scale digital forensic investigation

  • Authors:
  • Hyungkeun Jee;Jooyoung Lee;Dowon Hong

  • Affiliations:
  • ETRI, Gajeong-dong, Yuseong-gu, Daejeon, Korea;ETRI, Gajeong-dong, Yuseong-gu, Daejeon, Korea;ETRI, Gajeong-dong, Yuseong-gu, Daejeon, Korea

  • Venue:
  • Proceedings of the 1st international conference on Forensic applications and techniques in telecommunications, information, and multimedia and workshop
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The most common forensic activity is searching a hard disk for string of data. Nowadays, investigators and analysts are increasingly experiencing large, even terabyte sized data sets when conducting digital investigations. Therefore consecutive searching can take weeks to complete successfully. There are two primary search methods: index-based search and bitwise search. Index-based searching is very fast after the initial indexing but initial indexing takes a long time. In this paper, we discuss a high speed bitwise search model for large-scale digital forensic investigations. We used pattern matching board, which is generally used for network security, to search for string and complex regular expressions. Our results indicate that in many cases, the use of pattern matching board can substantially increase the performance of digital forensic search tools.