XIRAF - XML-based indexing and querying for digital forensics

  • Authors:
  • W. Alink;R. A. F. Bhoedjang;P. A. Boncz;A. P. De Vries

  • Affiliations:
  • Netherlands Forensic Institute (NFI), Laan van Ypenburg 6, The Hague, The Netherlands;Netherlands Forensic Institute (NFI), Laan van Ypenburg 6, The Hague, The Netherlands;Centrum voor Wiskunde en Informatica (CWI), Amsterdam, The Netherlands;Centrum voor Wiskunde en Informatica (CWI), Amsterdam, The Netherlands

  • Venue:
  • Digital Investigation: The International Journal of Digital Forensics & Incident Response
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes a novel, XML-based approach towards managing and querying forensic traces extracted from digital evidence. This approach has been implemented in XIRAF, a prototype system for forensic analysis. XIRAF systematically applies forensic analysis tools to evidence files (e.g., hard disk images). Each tool produces structured XML annotations that can refer to regions (byte ranges) in an evidence file. XIRAF stores such annotations in an XML database, which allows us to query the annotations using a single, powerful query language (XQuery). XIRAF provides the forensic investigator with a rich query environment in which browsing, searching, and predefined query templates are all expressed in terms of XML database queries.