Legal Cyber Academy
JournalPaywalledCurrent

Advances in Digital Forensics (IFIP WG 11.9 conference proceedings)

Springer · 2025

Identifier: ISBN 978-3-031-71024-7 (Advances in Digital Forensics XX)

Access and status

Cost

Paywalled

Behind a subscription or per-item charge. Check whether your firm, university or public library already has access before paying at the door.

Status

Current

Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.

What it is

The post-conference edited volumes of the annual IFIP Working Group 11.9 International Conference on Digital Forensics, published by Springer as the numbered Advances in Digital Forensics series. Volume XX covers the twentieth conference and appeared in 2025; the working group's site lists the twenty-third conference for January 2027, so the series is live.

Who it is for, and when

This is the most consistently academic of the digital forensics proceedings, and it runs long on themes the journals cover thinly: forensic process models, industrial control system and SCADA forensics, network and infrastructure investigation, and legal and policy papers. Useful when you need a citable treatment of a niche evidence type. The working group's own publications page is the reliable index of which volume maps to which conference year.

What it does not cover

Papers are not freely hosted anywhere official — these are Springer books, so expect to buy the volume or the chapter, or use a library. Because volumes appear after the conference, the content is typically a year or more behind the DFRWS stream.

Go to the source

Open at ifip119.org (opens in a new tab)

https://www.ifip119.org/Publications

Details

Type
Journal
Written for
AdvancedAdvanced
Publisher
Springer
Year
2025
Identifier
ISBN 978-3-031-71024-7 (Advances in Digital Forensics XX)
Topics
research-publishing, foundations, network, standards-development
Checked at source
  • The report from the first Digital Forensic Research Workshop, held in 2001, which set out a research agenda and a shared vocabulary for a field that at that point had neither. It is the document that proposed the examination process framework and the term 'digital forensic science', and it is conventionally cited as Palmer (2001); DFRWS's own page for it names no individual author.

  • The paper that introduced CASE, the Cyber-investigation Analysis Standard Expression, an open community-developed specification language aligned with the Unified Cyber Ontology for representing and exchanging cyber-investigation information. It is co-authored by a NIST researcher and supersedes the earlier DFAX approach.

  • The annual research challenges set alongside the DFRWS conferences, with scenario data, documentation and published results kept as repositories in the DFRWS GitHub organisation. Editions available there include 2005 (memory analysis), 2006, 2009 (PlayStation 3), 2012-2013, 2015, 2017 and 2018 (IoT), 2021 (multisource analysis and correlation) and 2023.

  • Simson Garfinkel's 2010 paper in Digital Investigation arguing that the 'golden age' of digital forensics was ending and naming the forces that would end it: storage volume, device and format diversity, pervasive encryption, cloud storage and mobile platforms. It is one of the most cited papers in the field.

  • How to read a packet capture with Wireshark: capture placement and filtering, the protocols you will actually meet, and worked scenarios that move from a symptom to a conclusion about what the network did.