Legal Cyber Academy
Paper or reportFreeCurrent

Defining Digital Forensic Examination and Analysis Tool Using Abstraction Layers

International Journal of Digital Evidence · 2003

Access and status

Cost

Free

Free to read or download at source. No account, no purchase.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

Brian Carrier's paper in IJDE 2003, Volume 1, Issue 4, which modelled forensic tools as stacks of abstraction layers — bytes to file system to file to application content — and pointed out that every layer translation introduces potential error that the tool's output hides. Note that the IJDE table of contents prints 'Tool' singular even though the paper is usually cited as 'Tools'.

Who it is for, and when

This is the clearest short explanation of where tool error actually comes from, and it gives you the vocabulary for saying which layer a disputed finding depends on. That matters on the stand: a challenge to a carved file is a different challenge from one to a file system interpretation, and this paper is why examiners distinguish them. It also underpins the argument for testing tools at each layer rather than end to end.

What it does not cover

It is a conceptual model, not a test methodology — no procedures, no reference data, no measured error rates. There is no DOI and no live publisher copy; use the Internet Archive capture of the issue.

Go to the source

Open at web.archive.org (opens in a new tab)

https://web.archive.org/web/20111001000000/http://www.utica.edu/academic/institutes/ecii/ijde/articles.cfm?action=issue&id=4

Details

Type
Paper or report
Written for
AdvancedWorking examinerAdvanced, Working examiner
Publisher
International Journal of Digital Evidence
Year
2003
Topics
tool-testing, validation, error-rates, foundations
Checked at source
  • A defunct early journal of the field. IJDE published from Volume 1, Issue 1 (Spring 2002) to Volume 6, Issue 1 (Spring 2007) out of Utica College's Economic Crime Institute, and then stopped; the original utica.edu address now redirects away and there is no live journal site.

  • A NIST repository of documented simulated digital evidence — images and data sets with known ground truth — developed with National Institute of Justice support. Holdings include scenario images (hacking case, data leakage case), Windows registry and Unicode string-search sets, Mac and mobile images, memory images, file carving and deleted-file-recovery sets, and reference/control drives.

  • NIST's long-running programme that builds tool specifications, test assertions, test procedures and test data for categories of forensic function — disk imaging, hardware and software write blocking, deleted file recovery, file carving, string searching, media preparation, mobile device and cloud data extraction, Windows registry and SQLite tools — and publishes the resulting test reports with DHS Science and Technology.

  • A CFTT offshoot that packages NIST's test methodology so labs can run it themselves and optionally share results: distributed as bootable Linux ISOs and a portable Windows web-server build, with report templates. Current suites cover disk imaging, forensic media preparation, hardware write blocking, string searching, SQLite recovery, mobile device acquisition and cloud data extraction, with companion datasets in CFReDS.

  • A fully open-access journal in Elsevier's Forensic Science International family, indexed in DOAJ under Creative Commons licences and funded by article processing charges rather than subscriptions. It deliberately takes the cross-cutting material — policy, quality management, education, interpretation and reporting — that the discipline-specific FSI titles do not.