Applying forensic approach to live investigation using XeBag

Kyung Soo Lim, Changhoon Lee

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

The law enforcement agencies in the worldwide are confiscating or retaining computer systems involved in a crime/civil case at the preliminary investigation stage, even though the case does not involve a cyber-crime. They are collecting digital evidences from the suspects's systems and using them in the essential investigation procedure. It requires much time, though, to collect, duplicate and analyze disk images in general crime cases, especially in cases in which rapid response must be taken such as kidnapping and murder cases. It is efficient and effective to selectively collect only traces of the behavior of the user activities on operating systems or particular files in focus of triage investigation in live system. On the other hand, if we just acquire essential files from target computer, it is not suitable forensically soundness. Therefore, we need to use standard digital evidence container to prove integrity and probative of evidence from various digital sources. In this article, we describe a forensic approach to live investigation using Xebeg, which is easily able to preserve collected digital evidences selectively for using general technology such as XML and PKZIP compression technology, which is satisfied with generality, integrity, unification, scalability and security.

Original languageEnglish
Title of host publicationComputer Science and Its Applications, CSA 2012
Pages389-397
Number of pages9
DOIs
StatePublished - 2012
Event4th FTRA International Conference on Computer Science and Its Applications, CSA 2012 - Jeju Island, Korea, Republic of
Duration: 22 Nov 201225 Nov 2012

Publication series

NameLecture Notes in Electrical Engineering
Volume203 LNEE
ISSN (Print)1876-1100
ISSN (Electronic)1876-1119

Conference

Conference4th FTRA International Conference on Computer Science and Its Applications, CSA 2012
Country/TerritoryKorea, Republic of
CityJeju Island
Period22/11/1225/11/12

Keywords

  • Digital evidence container
  • Digital forensics
  • Incident response
  • Live investigation

Fingerprint

Dive into the research topics of 'Applying forensic approach to live investigation using XeBag'. Together they form a unique fingerprint.

Cite this