Paper | Presentation | Conference | Downloads | Author |
---|
File Marshal – Automatic Extraction of Peer-to-Peer Data | DFRWS USA 2007 |
| Frank Adelstein (ATC-NY), Rob Joyce (ATC-NY) |
Forensic Data Recovery and Examination of Magnetic Swipe Card Cloning Devices | DFRWS USA 2007 |
| Gerry Masters(QinetiQ), Philip Turner (QinetiQ,) |
Forensic Memory Analysis – From Stack and Code to Execution History | DFRWS USA 2007 |
| Ali Reza Arasteh (Concordia University), Mourad Debbabi (Concordia University) |
Introducing the Microsoft Vista Log File Format | DFRWS USA 2007 |
| Andreas Schuster (Deutsche Telekom AG) |
Issues with Imaging Drives Containing Faulty Sectors | DFRWS USA 2007 |
| James R. Lyle (National Institute of Standards and Technology), Mark Wozar (National Institute of Standards and Technology) |
Specifying Digital Forensics – A Forensics Policy Approach | DFRWS USA 2007 |
| Carol Taylor (University of Idaho), Barbara Endicott-Popovsky (University of Washington), Deborah A. Frincke (Pacific Northwest National Laboratory) |
The VAD Tree – A Process-Eye View of Physical Memory | DFRWS USA 2007 |
| Brendan Dolan-Gavitt (MITRE Corporation) |
A Brief Study of Time | DFRWS USA 2007 |
| Florian Buchholz (James Madison University) and Brett Tjaden (James Madison University) |
BodySnatcher – Towards Reliable Volatile Memory Acquisition by Software | DFRWS USA 2007 |
| Bradley Schatz (Evimetry) |
Capture – A Tool for Behavioral Analysis of Applications and Documents | DFRWS USA 2007 |
| Christian Seifert (Victoria University of Wellington), Ramon Steenson (Victoria University of Wellington), Ian Welch (Victoria University of Wellington), Peter Komisarczuk (Victoria University of Wellington), and Barbara Endicott-Popovsky (University of Washington) |
Carving Contiguous and Fragmented Files with Object Validation | DFRWS USA 2007 |
| Simson Garfinkel, Ph.D. (Naval Postgraduate School, Harvard University) |
Digital Forensic Text String Searching – Improving Information Retrieval Effectiveness by Thematically Clustering Search Results | DFRWS USA 2007 |
| Nicole Beebe, Ph.D. (UTSA) and Jan Guynes Clark (UTSA) |
Massive Threading – Using GPUs to Increase the Performance of Digital Forensics Tools | DFRWS USA 2007 |
| Lodovico Marziale (University of New Orleans), Golden G. Richard III (University of New Orleans), and Vassil Roussev (University of New Orleans) |
Multi-Resolution Similarity Hashing | DFRWS USA 2007 | | Vassil Roussev (University of New Orleans), Golden G. Richard III (University of New Orleans), and Lodovico Marziale (University of New Orleans) |
A Cyber Forensics Ontology – Creating a New Approach to Studying Cyber Forensics | DFRWS USA 2006 |
| Ashley Brinson (Purdue University), Abigail Robinson (Purdue University), Marcus Rogers (Purdue University) |
A Survey of Forensic Characterization Methods for Physical Devices | DFRWS USA 2006 |
| Nitin Khanna (Purdue University), Aravind K. Mikkilineni (Purdue University), Anthony F. Martone (Purdue University), Gazi N. Ali (Purdue University), George T.-C. Chiu (Purdue University), Jan P. Allebach (Purdue University), Edward J. Delp (Purdue University) |
An Empirical Study of Automatic Event Reconstruction Systems | DFRWS USA 2006 |
| Sundararaman Jeyaraman (Purdue University), Mikhail J. Atallah (Purdue University) |
Arriving at an Anti-forensics Consensus – Examining How to Define and Control the Anti-forensics Problem | DFRWS USA 2006 |
| Ryan Harris (Purdue University) |
Cross-Drive Analysis | DFRWS USA 2006 |
| Simson Garfinkel (Harvard University) |
Current Cyber Investigation Challenges in Digital Forensics | DFRWS USA 2006 |
| Ted Lindsey |
Detecting False Captioning Using Common Sense Reasoning | DFRWS USA 2006 |
| Sangwon Lee (Northwestern University), David A. Shamma (Northwestern University), Bruce Gooch (Northwestern University) |
Identifying Almost Identical Files Using Context Triggered Piecewise Hashing | DFRWS USA 2006 |
| Jesse Kornblum (ManTech SMA) |
Issues in Building the Digital Forensics Bridge From Computer Science to Judicial Science | DFRWS USA 2006 |
| Michael Losavio, Deborah Wilson, Adel Elmaghraby, James Graham, S. Srinivasan, David Elder, Marcus Rogers |
Knowledge Exploration, Analysis, and Discovery Workshop | DFRWS USA 2006 |
| Mark Maybury, Penny Chase |
md5bloom – Forensic Filesystem Hashing Revisited | DFRWS USA 2006 |
| Vassil Roussev (University of New Orleans), Yixin Chen, (University of New Orleans), Timothy Bourg (University of New Orleans), Golden Richard III (University of New Orleans) |
Searching for Processes and Threads in Microsoft Windows Memory Dumps | DFRWS USA 2006 |
| Andreas Schuster (Deutsche Telekom AG) |
Selective and Intelligent Imaging using Digital Evidence Bags | DFRWS USA 2006 |
| Philip Turner (QinetiQ) |
XIRAF – Ultimate Forensic Querying | DFRWS USA 2006 |
| W. Alink (Netherlands Forensic Insitute), R.A.F. Bhoedjang (Netherlands Forensic Insitute), P.A. Boncz (Centrum voor Wiskunde en Informatica), A.P. de Vries (Centrum voor Wiskunde en Informatica) |
A Correlation Method for Establishing Provenance of Timestamps in Digital Evidence | DFRWS USA 2006 |
| Bradley Schatz (Queensland University of Technology), George Mohay (Queensland University of Technology), Andrew Clark (Queensland University of Technology) |
A Strategy for Testing Hardware Write Block Devices | DFRWS USA 2006 |
| James Lyle (NIST) |