Domain-Specific Optimization in Digital Forensics

  • Jeroen van den Bos
  • Tijs van der Storm
Conference paper

DOI: 10.1007/978-3-642-30476-7_8

Volume 7307 of the book series Lecture Notes in Computer Science (LNCS)
Cite this paper as:
van den Bos J., van der Storm T. (2012) Domain-Specific Optimization in Digital Forensics. In: Hu Z., de Lara J. (eds) Theory and Practice of Model Transformations. ICMT 2012. Lecture Notes in Computer Science, vol 7307. Springer, Berlin, Heidelberg

Abstract

File carvers are forensic software tools used to recover data from storage devices in order to find evidence. Every legal case requires different trade-offs between precision and runtime performance. The resulting required changes to the software tools are performed manually and under the strictest deadlines.

In this paper we present a model-driven approach to file carver development that enables these trade-offs to be automated. By transforming high-level file format specifications into approximations that are more permissive, forensic investigators can trade precision for performance, without having to change source.

Our study shows that performance gains up to a factor of three can be achieved, at the expense of up to 8% in precision and 5% in recall.

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

Copyright information

© Springer-Verlag Berlin Heidelberg 2012

Authors and Affiliations

  • Jeroen van den Bos
    • 1
    • 2
  • Tijs van der Storm
    • 1
  1. 1.Centrum Wiskunde & InformaticaAmsterdamThe Netherlands
  2. 2.Netherlands Forensic InstituteDen HaagThe Netherlands