| Paper | Presentation | Conference | Downloads | Author |
|---|---|---|---|
| Automatically Creating Realistic Targets for Digital Forensics Investigation | DFRWS USA 2005 | Frank Adelstein, Ph.D. (ATC-NY), Yun Gao, and Golden Richard III, Ph.D. (University of New Orleans) | |
| Scalpel – A Frugal, High Performance File Carver | DFRWS USA 2005 | Golden Richard III, Ph.D. (University of New Orleans), Vassil Roussev, Ph.D. (University of New Orleans) | |
| Risk Sensitive Digital Evidence Collection | DFRWS USA 2005 | Erin Kenneally (San Diego Supercomputer Center), Christopher Brown (Technology Pathways) | |
| Reproducibility of Digital Evidence in Forensic Investigations | DFRWS USA 2005 | Lei Pan (Deakin University), Lynn Batten (Deakin University) | |
| Network Forensics Analysis with Evidence Graphs | DFRWS USA 2005 | Wei Wang (Iowa State University), Thomas Daniels (Iowa State University) | |
| Forensic Discovery | DFRWS USA 2005 | Wietse Venema, Ph.D. (IBM Research) | |
| Evaluating Commercial Counter-Forensic Tools | DFRWS USA 2005 | Matthew Geiger (Carnegie Mellon University) | |
| Design and Implementation of Zeitline – a Forensic Timeline Editor | DFRWS USA 2005 | Florian Buchholz (Purdue University), Courtney Falk (Purdue University) | |
| Data Hiding in Journaling File Systems | DFRWS USA 2005 | Knut Eckstein (NATO NC3A), Marko Jahnke (FGAN/FKIE Germany) | |
| Automated Digital Evidence Target Definition Using Outlier Analysis and Existing Evidence | DFRWS USA 2005 | Brian Carrier, Ph.D. (Purdue University), Prof. Eugene Spafford (Purdue University) | |
| Self-Reported Computer Criminal Behavior – A Psychological Analysis | DFRWS USA 2006 | Marcus K. Rogers (Purdue University), Kathryn Seigfried (John Jay College), and Kirti Tidke (Purdue University) | |
| FORZA – Digital Forensics Investigation Framework That Incorporate Legal Issues | DFRWS USA 2006 | Ricci Sze-Chung Ieong (eWalker Consulting Ltd) | |
| Categories of Digital Investigation Analysis Techniques Based On The Computer History Model | DFRWS USA 2006 | Brian Carrier, Ph.D. (Purdue University) and Prof. Eugene Spafford (Purdue University) | |
| A Strategy for Testing Hardware Write Block Devices | DFRWS USA 2006 | James Lyle (NIST) | |
| A Correlation Method for Establishing Provenance of Timestamps in Digital Evidence | DFRWS USA 2006 | Bradley Schatz (Queensland University of Technology), George Mohay (Queensland University of Technology), Andrew Clark (Queensland University of Technology) | |
| XIRAF – Ultimate Forensic Querying | DFRWS USA 2006 | W. Alink (Netherlands Forensic Insitute), R.A.F. Bhoedjang (Netherlands Forensic Insitute), P.A. Boncz (Centrum voor Wiskunde en Informatica), A.P. de Vries (Centrum voor Wiskunde en Informatica) | |
| Selective and Intelligent Imaging using Digital Evidence Bags | DFRWS USA 2006 | Philip Turner (QinetiQ) | |
| Searching for Processes and Threads in Microsoft Windows Memory Dumps | DFRWS USA 2006 | Andreas Schuster (Deutsche Telekom AG) | |
| md5bloom – Forensic Filesystem Hashing Revisited | DFRWS USA 2006 | Vassil Roussev (University of New Orleans), Yixin Chen, (University of New Orleans), Timothy Bourg (University of New Orleans), Golden Richard III (University of New Orleans) | |
| Knowledge Exploration, Analysis, and Discovery Workshop | DFRWS USA 2006 | Mark Maybury, Penny Chase | |
| Issues in Building the Digital Forensics Bridge From Computer Science to Judicial Science | DFRWS USA 2006 | Michael Losavio, Deborah Wilson, Adel Elmaghraby, James Graham, S. Srinivasan, David Elder, Marcus Rogers | |
| Identifying Almost Identical Files Using Context Triggered Piecewise Hashing | DFRWS USA 2006 | Jesse Kornblum (ManTech SMA) | |
| Detecting False Captioning Using Common Sense Reasoning | DFRWS USA 2006 | Sangwon Lee (Northwestern University), David A. Shamma (Northwestern University), Bruce Gooch (Northwestern University) | |
| Current Cyber Investigation Challenges in Digital Forensics | DFRWS USA 2006 | Ted Lindsey | |
| Cross-Drive Analysis | DFRWS USA 2006 | Simson Garfinkel (Harvard University) | |
| Arriving at an Anti-forensics Consensus – Examining How to Define and Control the Anti-forensics Problem | DFRWS USA 2006 | Ryan Harris (Purdue University) | |
| An Empirical Study of Automatic Event Reconstruction Systems | DFRWS USA 2006 | Sundararaman Jeyaraman (Purdue University), Mikhail J. Atallah (Purdue University) | |
| A Survey of Forensic Characterization Methods for Physical Devices | DFRWS USA 2006 | Nitin Khanna (Purdue University), Aravind K. Mikkilineni (Purdue University), Anthony F. Martone (Purdue University), Gazi N. Ali (Purdue University), George T.-C. Chiu (Purdue University), Jan P. Allebach (Purdue University), Edward J. Delp (Purdue University) | |
| A Cyber Forensics Ontology – Creating a New Approach to Studying Cyber Forensics | DFRWS USA 2006 | Ashley Brinson (Purdue University), Abigail Robinson (Purdue University), Marcus Rogers (Purdue University) | |
| Multi-Resolution Similarity Hashing | DFRWS USA 2007 | Vassil Roussev (University of New Orleans), Golden G. Richard III (University of New Orleans), and Lodovico Marziale (University of New Orleans) | |
| Massive Threading – Using GPUs to Increase the Performance of Digital Forensics Tools | DFRWS USA 2007 | Lodovico Marziale (University of New Orleans), Golden G. Richard III (University of New Orleans), and Vassil Roussev (University of New Orleans) | |
| Digital Forensic Text String Searching – Improving Information Retrieval Effectiveness by Thematically Clustering Search Results | DFRWS USA 2007 | Nicole Beebe, Ph.D. (UTSA) and Jan Guynes Clark (UTSA) | |
| Carving Contiguous and Fragmented Files with Object Validation | DFRWS USA 2007 | Simson Garfinkel, Ph.D. (Naval Postgraduate School, Harvard University) | |
| Capture – A Tool for Behavioral Analysis of Applications and Documents | DFRWS USA 2007 | Christian Seifert (Victoria University of Wellington), Ramon Steenson (Victoria University of Wellington), Ian Welch (Victoria University of Wellington), Peter Komisarczuk (Victoria University of Wellington), and Barbara Endicott-Popovsky (University of Washington) | |
| BodySnatcher – Towards Reliable Volatile Memory Acquisition by Software | DFRWS USA 2007 | Bradley Schatz (Evimetry) | |
| A Brief Study of Time | DFRWS USA 2007 | Florian Buchholz (James Madison University) and Brett Tjaden (James Madison University) | |
| The VAD Tree – A Process-Eye View of Physical Memory | DFRWS USA 2007 | Brendan Dolan-Gavitt (MITRE Corporation) | |
| Specifying Digital Forensics – A Forensics Policy Approach | DFRWS USA 2007 | Carol Taylor (University of Idaho), Barbara Endicott-Popovsky (University of Washington), Deborah A. Frincke (Pacific Northwest National Laboratory) | |
| Issues with Imaging Drives Containing Faulty Sectors | DFRWS USA 2007 | James R. Lyle (National Institute of Standards and Technology), Mark Wozar (National Institute of Standards and Technology) | |
| Introducing the Microsoft Vista Log File Format | DFRWS USA 2007 | Andreas Schuster (Deutsche Telekom AG) | |
| Forensic Memory Analysis – From Stack and Code to Execution History | DFRWS USA 2007 | Ali Reza Arasteh (Concordia University), Mourad Debbabi (Concordia University) | |
| Forensic Data Recovery and Examination of Magnetic Swipe Card Cloning Devices | DFRWS USA 2007 | Gerry Masters(QinetiQ), Philip Turner (QinetiQ,) | |
| File Marshal – Automatic Extraction of Peer-to-Peer Data | DFRWS USA 2007 | Frank Adelstein (ATC-NY), Rob Joyce (ATC-NY) | |
| Automated Windows Event Log Forensics | DFRWS USA 2007 | Rich Murphey (Applied Cognitive Solutions) | |
| Analyzing Multiple Logs for Forensic Evidence | DFRWS USA 2007 | Ali Reza Arasteh (Concordia University), Mourad Debbabi (Concordia University), Assaad Sakha (Concordia University), Mohamed Saleh (Concordia University) | |
| An Efficient Technique for Enhancing Forensic Capabilities of Ext2 File System | DFRWS USA 2007 | Mridul Sankar Barik (Jadavpur University), Gaurav Gupta (KPMG), Shubhro Sinha (Bengal Engineering and Science University), Alok Mishra (Bengal Engineering and Science University), Chandan Mazumdara (Jadavpur University) | |
| 10 Good Reasons Why You Should Shift Focus to Small Scale Digital Device Forensics | DFRWS USA 2007 | Ronald van der Knijff (Netherlands Forensic Institute) | |
| Using the HFS+ Journal For Deleted File Recovery | DFRWS USA 2008 | Aaron Burghardt (Booz Allen Hamilton), Adam J. Feldman (Booz Allen Hamilton) | |
| The Impact Of Microsoft Windows Pool Allocation Strategies On Memory Forensics | DFRWS USA 2008 | Andreas Schuster (Deutsche Telekom AG) | |
| PyFlag – An Advanced Network Forensic Framework | DFRWS USA 2008 | Michael Cohen (Australian Federal Police) |