Tehničko veleučilište u Zagrebu · Zagreb

Linux Forensic Triage: Overview of Process and Tools

izvorni znanstveni rad

izvorni znanstveni rad

Linux Forensic Triage: Overview of Process and Tools

Vrsta prilog sa skupa (u zborniku)
Tip izvorni znanstveni rad
Godina 2020
Nadređena publikacija 2020 43rd International Convention on Information, Communication and Electronic Technology (MIPRO) - proceedings
Stranice str. 1230-1235
DOI 10.23919/MIPRO48935.2020.9245304
ISSN 2623-8764
EISSN 2049-2177
Status objavljeno

Sažetak

Digital forensics dates back into the 1980s, but the importance of Linux forensics was not taken into place until recently. Linux forensics is a distinctive world compared to example Microsoft Windows forensics. Although it is commonly used as a name for the entire operating system, Linux is just the name of the kernel, a piece of software that handles interactions between the hardware and end-user applications. Its popularity has not reached the popularity of the Windows operating system, therefore, without many reliable tools on the market, it represents a bigger challenge for digital forensics investigators. Digital triage is the process in which an investigator collects, assembles, analyzes, and prioritizes digital evidence from a crime. Since there are not many available tools on the market for performing Linux triage, the most important part is to understand the tool and its capabilities in order to know which one to use for a certain situation. This paper will describe how the Linux system is structured, what its architecture contains, how should one correctly approach and acquire the system, and how to understand the tools and results they provide

Ključne riječi

digital triage ; Linux architecture ; Linux forensics