11.8 Summary


11.8 Summary

Given the large number of UNIX systems that exist, it is necessary for digital evidence examiners to be familiar with UNIX file systems. Although UNIX may appear to be more complex than Windows, this is largely because many operations involve commands rather than graphical user interface. However, UNIX systems are arguably easier to understand because they are more transparent - these systems' configuration and functions are plainly visible and it is even possible to view the source code of many Unix operating systems and utilities.

Linux is a powerful forensic platform that can be used to examine many file systems, including FAT and NTFS. Tools like The Sleuth Kit and SMART provide a graphical user interface, simplifying the process of performing digital evidence examinations using UNIX systems.




Digital Evidence and Computer Crime
Digital Evidence and Computer Crime, Second Edition
ISBN: 0121631044
EAN: 2147483647
Year: 2003
Pages: 279

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net