Digital Forensics and Cyber Crime. Second International ICST Conference, ICDF2C 2010, Abu Dhabi, United Arab Emirates, October 4-6, 2010, Revised Selected Papers

Research Article

Defining a Standard for Reporting Digital Evidence Items in Computer Forensic Tools

Download
683 downloads
  • @INPROCEEDINGS{10.1007/978-3-642-19513-6_7,
        author={Hamda Bariki and Mariam Hashmi and Ibrahim Baggili},
        title={Defining a Standard for Reporting Digital Evidence Items in Computer Forensic Tools},
        proceedings={Digital Forensics and Cyber Crime. Second International ICST Conference, ICDF2C 2010, Abu Dhabi, United Arab Emirates, October 4-6, 2010, Revised Selected Papers},
        proceedings_a={ICDF2C},
        year={2012},
        month={5},
        keywords={digital evidence item reports in forensic tools digital forensics standard report},
        doi={10.1007/978-3-642-19513-6_7}
    }
    
  • Hamda Bariki
    Mariam Hashmi
    Ibrahim Baggili
    Year: 2012
    Defining a Standard for Reporting Digital Evidence Items in Computer Forensic Tools
    ICDF2C
    Springer
    DOI: 10.1007/978-3-642-19513-6_7
Hamda Bariki1, Mariam Hashmi1, Ibrahim Baggili1,*
  • 1: Zayed University
*Contact email: Ibrahim.Baggili@zu.ac.ae

Abstract

Due to the lack of standards in reporting digital evidence items, investigators are facing difficulties in efficiently presenting their findings. This paper proposes a standard for digital evidence to be used in reports that are generated using computer forensic software tools. The authors focused on developing a standard digital evidence items by surveying various digital forensic tools while keeping in mind the legal integrity of digital evidence items. Additionally, an online questionnaire was used to gain the opinion of knowledgeable and experienced stakeholders in the digital forensics domain. Based on the findings, the authors propose a standard for digital evidence items that includes data about the case, the evidence source, evidence item, and the chain of custody. Research results enabled the authors in creating a defined XML schema for digital evidence items.