Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Linux tool speeds up police computer forensics

Liam Tung ZDNet Australia

Published: 06 Mar 2008 12:36 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Australian university students have developed a Linux-based data-forensics tool to help police churn through a growing backlog of computer-related criminal investigations.

The tool, developed by students at the School of Computing and Information Sciences at Edith Cowan University (ECU), will help the Western Australian Police Computer Crime Squad process their forensic investigations.

Called Simple (Simple Image Preview Live Environment), the software allows investigators to view and acquire forensic data at the scene of the crime without compromising the integrity of data as it is collected.

"It's a Linux Live CD that we have built from the ground up. We customised the kernel and the underlying operating system so that, when it runs, it's incapable of writing to the hard disk or any other storage," Peter Hannay, the software developer behind the forensic acquisition tool, told ZDNet.com.au.

The operating system has had some features removed so that investigators can view data without affecting the host machine.

"We stripped out a large amount of functionality because we want to maintain the integrity of data collected, so we removed all network support and the ability to write to disk. Also, if for some reason a disk is writeable, the system will halt automatically," Hannay said.

"Our software will launch on top of the operating system, and will interrogate the hard disk, locate all the images on system and then present those to the operator," Hannay added.

Read this

 PSCS3
Photos: The Linux car that drives itself

At CeBIT 2008, Darpa Grand Challenge finalist Caroline was on show — a car that doesn't need a driver...

Read more +

Simple searches the system for specific file types, such as MPEG or JPEG files, saving time on the often lengthy search process.

Hoping to achieve even greater automation during the collection of evidence, Simple will soon be equipped with skin-tone analysis capabilities to help detect relevant files.

The idea for the tool first originated when the Western Australia Police approached the university in 2006 because its investigators could not handle the amount of computer forensic data requests, which relate mostly to child pornography and bestiality.

Normally police need to take PCs back to the station to begin acquiring forensic data but, with this tool, according to Hannay, police will be able to collect the data on the spot.

Credit: Linux speeds up computer forensics for cops from ZDNet Australia

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
4 out of 4 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters