Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ottmann, Jenny, Breitinger, Frank, Freiling, Felix
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913851906195456
author Ottmann, Jenny
Breitinger, Frank
Freiling, Felix
author_facet Ottmann, Jenny
Breitinger, Frank
Freiling, Felix
contents The acquisition of data from main memory or from hard disk storage is usually one of the first steps in a forensic investigation. We revisit the discussion on quality criteria for "forensically sound" acquisition of such storage and propose a new way to capture the intent to acquire an instantaneous snapshot from a single target system. The idea of our definition is to allow a certain flexibility into when individual portions of memory are acquired, but at the same time require being consistent with causality (i.e., cause/effect relations). Our concept is much stronger than the original notion of atomicity defined by Vomel and Freiling (2012) but still attainable using copy-on-write mechanisms. As a minor result, we also fix a conceptual problem within the original definition of integrity.
format Preprint
id arxiv_https___arxiv_org_abs_2505_15921
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing
Ottmann, Jenny
Breitinger, Frank
Freiling, Felix
Cryptography and Security
The acquisition of data from main memory or from hard disk storage is usually one of the first steps in a forensic investigation. We revisit the discussion on quality criteria for "forensically sound" acquisition of such storage and propose a new way to capture the intent to acquire an instantaneous snapshot from a single target system. The idea of our definition is to allow a certain flexibility into when individual portions of memory are acquired, but at the same time require being consistent with causality (i.e., cause/effect relations). Our concept is much stronger than the original notion of atomicity defined by Vomel and Freiling (2012) but still attainable using copy-on-write mechanisms. As a minor result, we also fix a conceptual problem within the original definition of integrity.
title Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing
topic Cryptography and Security
url https://arxiv.org/abs/2505.15921