U.S. flag

An official website of the United States government, Department of Justice.

NCJRS Virtual Library

The Virtual Library houses over 235,000 criminal justice resources, including all known OJP works.
Click here to search the NCJRS Virtual Library

Unix System Analysis (From Handbook of Computer Crime Investigation: Forensic Tools and Technology, P 167-199, 2002, Eoghan Casey, ed, -- See NCJ-195111)

NCJ Number
195118
Author(s)
Keith K. Seglem; Mark E. Luque; Sigurd E. Murphy
Date Published
2002
Length
33 pages
Annotation
This chapter is to assist the computer forensic examiner in the recovery and analysis of electronic data in the Unix environment.
Abstract
The author of this chapter notes that recovering and reconstructing electronic data can be a daunting task for even very experienced computer administrators, especially in the Unix environment. This chapter seeks to aid the computer forensic examiner with their analysis in the Unix environment. The author explains the successive stages involved in the recovery and analysis of such data, including the imaging of original data, the extraction of the data from the media, and how to copy this data into a more accessible form. Included in this chapter is a discussion by a different author, Mark E. Luque, on the logical level analysis of Unix Systems. Similarly, author Sigurd E. Murphy offers a discussion of relational reconstruction. Tables, figures