|
|
|
Embedding Forensic Capabilities into Networks: Addressing Inefficiencies in Digital Forensics InvestigationsBarbara Endicott-Popovsky and Deborah FinckeThe 7th IEEE Information Assurance Workshop (IAWorkshop 2006)West Point, New York, USA, June 21-23, 2006
AbstractAbstract—When incident responders collect network forensic data, they must often decide between expending resources collecting forensically sound data, and restoring the network as quickly as possible. [1, 2] Organizational network forensic readiness has emerged as a discipline to support these choices, with suggested checklists, procedures and tools. This paper proposes a life cycle methodology for "operationalizing" organizational network forensic readiness. The methodology, and the theoretical analysis that led to its development, are offered as a conceptual framework for creating more efficient, proactive approaches to digital foreIndex Terms—digital forensics, life cycle, networks, network forensics nsics on networks.
|
|