Forensics
Grounded in years of research and real-world experience, CERT's forensics team focuses on "gap areas"
not addressed by commercial tools or standard techniques. Some of
their current work includes
- Resource Amplification
With computers now being used to facilitate nearly every aspect of
criminal activity, skilled computer forensic investigators are swamped
by the backlog of machines waiting for analysis. We are searching for
ways to empower traditional investigators to perform triage and
initial examinations. Live View is our first step in this
direction.
- Memory Extraction and Analysis
As the standard amount of installed RAM increases, the amount and
importance of volatile data rises proportionally. The ability to
quickly extract and understand this data is critical for forensic
examiners.
- Encryption Counter-Measures
Law enforcement agencies and other investigators are discovering
that an increasing amount of gathered digital data is unusable because
of the pervasive use of strong encryption. We are developing methods
and tools to adapt the data acquisition process and recover encrypted
data in real-world scenarios.
|
|