Skip to main content

Overview of Performance Evaluation of Keyword Search Utilities in Forensic/E-Discovery Software

  • Conference paper
  • First Online:
  • 2890 Accesses

Part of the book series: Lecture Notes in Computer Science ((LNISA,volume 10658))

Abstract

Digital forensics has been modeled into a number of stages, which include examination and analysis. Keyword search is a popular tactic used by investigators during evidence examination and analysis. However, the belief that the success of forensic analysis depends on the examiner’s knowledge and experience has a strong hold in the digital forensic domain. It does imply the adequate awareness of the capabilities and limitations of the tools used by the examiner. Keyword search enables the examiner to quickly locate the existence of data items related to a case. This reduces investigation duration and eases the investigation process. This paper discusses the concepts of keyword search and the various keyword search techniques available. It highlights the algorithms on which they are based. In addition to the overview of, and argument for thorough understanding and evaluation of this technique in forensic utilities, this article also provides evaluation procedures to serve as direction for future evaluation/validation studies to ensure examiners know just how much to trust their software, as far as keyword searching is concerned.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   84.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

References

  1. Johnson, T.: Forensic Computer Crime Investigation. Taylor & Francis, Florida (2006)

    Google Scholar 

  2. Sheetz, M.: Computer Forensics: An Essential Guide for Accountants, Lawyers and Managers. Wiley, Florida (2007)

    Google Scholar 

  3. Casey, E.: Handbook of Digital Forensics and Investigations. Elsevier Academic Press, London (2009)

    Google Scholar 

  4. Association of Chief Police Officers: The Good Practice Guide for Computer-Based Electronic Evidence 4th version. http://www.7safe.com/electronic_evidence/ACPO_guidelines_computer_evidence_v4_web.pdf. Accessed 12 Sep 2017

  5. Jee, H., Lee, J., Hong, D.: High speed bitwise search for digital forensic system. In: World Academy of Science, Engineering and Technology, vol. 32 (2007)

    Google Scholar 

  6. Lee, J.: Proposal for efficient searching and presentation in digital forensics. In: Proceedings of 3rd International Conference on Availability, Reliability and Security, pp. 1–5 (2008)

    Google Scholar 

  7. Carrier, B.: NTFS Keyword Search Test #1. Digital Forensic Tool Testing. http://dftt.sourceforge.net. Accessed 25 Aug 2017

  8. Casey, E.: Handbook of Digital Forensics and Investigations. Elsevier Academic Press, London (2010)

    Google Scholar 

  9. Beebe, N.: Digital forensic research: the good, the bad and the unaddressed. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2009. IAICT, vol. 306, pp. 17–36. Springer, Heidelberg (2009). https://doi.org/10.1007/978-3-642-04155-6_2

    Chapter  Google Scholar 

  10. Pollitt, M., Shenoi, S. (eds.): Advances in Digital Forensics, vol. 194. Springer, Orlando (2005). https://doi.org/10.1007/0-387-31163-7

    Google Scholar 

  11. Guidance Software: EnCase Essentials: Forensic User Manual Version 8. http://www.guidancesoftware.com/products/ef_index.asp. Accessed 13 July 2017

  12. Python Software Foundation: Keyword Searching and Indexing of Forensic Images. http://pyflag.sourceforge.net/Documentation/articles/indexing/index.html. Accessed 17 Aug 2017

  13. Beckett, J., Slay, J.: Digital forensics: validation and verification in a dynamic work environment. In: Proceedings of the 40th Hawaii International Conference on System Sciences, pp. 1–10 (2007)

    Google Scholar 

  14. Casey, E.: Handbook of Computer Crime Investigation: Forensic Tools and Technology. Elsevier Academic Press, San Diego (2002)

    Google Scholar 

  15. Carrier, B.: File System Forensic Analysis. Addison-Wesley, Upper Saddle River (2005)

    Google Scholar 

  16. Craiger, P., Pollitt, M., Swauger, J.: Law enforcement and digital evidence. In: Bidgoli, H. (ed.) Handbook of Information Security. Wiley, New York (2005)

    Google Scholar 

  17. CFTT: Forensic String Searching Tool Requirements Specification Version 1.0. http://www.cftt.nist.gov/ss-req-sc-draft-v1_0.pdf. Accessed 5 June 2017

  18. Garfinkel, S.: Digital forensics research: the next 10 years. Digit. Investig. 7, S64–S73 (2010)

    Article  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Adedayo M. Balogun .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2017 Springer International Publishing AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Balogun, A.M., Zuva, T. (2017). Overview of Performance Evaluation of Keyword Search Utilities in Forensic/E-Discovery Software. In: Wang, G., Atiquzzaman, M., Yan, Z., Choo, KK. (eds) Security, Privacy, and Anonymity in Computation, Communication, and Storage. SpaCCS 2017. Lecture Notes in Computer Science(), vol 10658. Springer, Cham. https://doi.org/10.1007/978-3-319-72395-2_74

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-72395-2_74

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-72394-5

  • Online ISBN: 978-3-319-72395-2

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics