Legal Cyber Academy
Paper or reportPartly freeCurrent

Digital forensics research: The next 10 years

Elsevier (Digital Investigation) · 2010

Identifier: DOI 10.1016/j.diin.2010.05.009

Access and status

Cost

Partly free

Part of it is free and part is not. The entry says which part; read that before you plan around it.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

Simson Garfinkel's 2010 paper in Digital Investigation arguing that the 'golden age' of digital forensics was ending and naming the forces that would end it: storage volume, device and format diversity, pervasive encryption, cloud storage and mobile platforms. It is one of the most cited papers in the field.

Who it is for, and when

Read it to understand the structural reasons examination backlogs and 'we could not access the data' outcomes are normal rather than a mark of incompetence — a point that often needs making to clients, courts and opposing counsel. It is also the standard citation for the claim that the field faces a foreseen capability crisis, and it frames most of the research that followed. Short and readable enough to hand to a lawyer.

What it does not cover

It is a forward-looking position paper from 2010, with no method, no data and predictions you should now check against what actually happened rather than cite as current fact. The Elsevier copy is paywalled; a DFRWS-hosted or author copy is the practical route in.

Go to the source

Open at doi.org (opens in a new tab)

https://doi.org/10.1016/j.diin.2010.05.009

Details

Type
Paper or report
Written for
AdvancedWorking examinerAdvanced, Working examiner
Publisher
Elsevier (Digital Investigation)
Year
2010
Identifier
DOI 10.1016/j.diin.2010.05.009
Topics
foundations, research-publishing, cloud, mobile
Checked at source
  • The post-conference edited volumes of the annual IFIP Working Group 11.9 International Conference on Digital Forensics, published by Springer as the numbered Advances in Digital Forensics series. Volume XX covers the twentieth conference and appeared in 2025; the working group's site lists the twenty-third conference for January 2027, so the series is live.

  • Belkasoft's flagship acquisition and analysis product, covering computer, mobile, drone, vehicle, and cloud evidence in one case. It is split by customer type: Belkasoft X Forensic is offered to government customers, while Belkasoft X Corporate targets businesses for internal investigations and ediscovery. Belkasoft also publishes free Triage and Live RAM Capturer utilities.

  • Cellebrite's mobile forensics flagship, now branded Inseyets and positioned within the company's broader Case-to-Closure platform. The familiar component names persist inside it rather than having been retired: UFED, Physical Analyzer, Kiosk, CFID, Reader, and C-TEK are all listed as parts of the Inseyets suite.

  • The predecessor title of Forensic Science International: Digital Investigation. It published from 2004 to 2019 under ISSN 1742-2876 and then the title changed; there is no new content under this name.

  • A family of open-source Python parsers for mobile and returns data: iLEAPP for iOS logs, events and plists, ALEAPP for Android, and RLEAPP for returns and records from cloud and carrier providers. All three are released very frequently and are among the most actively maintained tools in mobile forensics.