The development of the Live Forensic discipline instigates the development of a method that allows forensically sound acquisition to stand fast in a court of law. The study presents the development of a comprehensive model for forensically sound Live Forensic Acquisition, the Liforac model. The Liforac model presents a number of concepts that are already available within the Cyber Forensics discipline, combined as a single document. It composes four distinct dimensions: laws and regulations, timeline, knowledge and scope. These dimensions combine to present a wide ranging model to guide first responders and forensic investigators in acquiring forensically sound digital evidence. The dimensions were identified as part of an intense research study on the current application of live forensics and the associated problems and suggested controls. The Liforac model is an inclusive model that presents all aspects related to live forensic acquisition, suggesting ways in which a live forensic acquisition should take place to ensure forensic soundness. At the time of writing, this Liforac model is the first document of this nature that could be found for analysis. It serves as a foundation for future models that can refine the current processes.
Reference:
Grobler, MM and Von Solms, SH. 2009. Best practice approach to live forensic acquisition. ISSA 2009 (Information Security for South Africa), University of Johannesburg, Gauteng, South Africa, 6-8 July, 2009. pp 12
Grobler, M., & Von Solms, S. (2009). Best practice approach to live forensic acquisition. http://hdl.handle.net/10204/3509
Grobler, MM, and SH Von Solms. "Best practice approach to live forensic acquisition." (2009): http://hdl.handle.net/10204/3509
Grobler M, Von Solms S, Best practice approach to live forensic acquisition; 2009. http://hdl.handle.net/10204/3509 .
Author:Grobler, MM; Von Solms, SHDate:Jun 2009This paper discusses the development of a South African model for Live Forensic Acquisition - Liforac. The Liforac model is a comprehensive model that presents a range of aspects related to Live Forensic Acquisition. The model provides forensic ...Read more
Author:Ngobeni, Sipho J; Venter, H; Burke, Ivan DDate:Jun 2012Over the past decade, wireless mobile communication technology based on the IEEE 802.11 Wireless Local Area Networks (WLANs) has been adopted worldwide on a massive scale. However, as the number of wireless users has soared, so has the ...Read more
Author:Dlamini, I; Olivier, MDate:Jul 2009Currently, network evidence used in a court of law can be lacking and inadequate for prosecution purposes, due to a loss of packets during the network transmission. This packet loss in turn may be caused by the congestion of data transmitted ...Read more