|
Customers Profile
Technology Pathways www.techpathways.com
Our Solution
ProDiscover DFT will allow the users to analyze disk information to detect fraud.
Methodology
ESN has a well-defined Software Development Life Cycle (SDLC) model that takes an iterative approach in executing a project. Each build / milestone are scheduled so that obtaining specific requirements related to the build / milestone, revision of project documents, planning, thorough testing and bug fixing are carried out incrementally.One of the team members plays the role of a Quality Analyst. The main activities of a Quality Analyst are to review and update project documents, organize testing activities and conduct regular code reviews and code walkthroughs.Designated Team Members work along with the Quality Analyst as members of the testing team continuously aiming to enhance the quality of the software delivered.
Benefits
The software has been designed and developed using object oriented principles. It can be enhanced easily to support additional disk formats.
|
Introduction
The project involves development of a tool intended to be used by Computer Security Consultants and Law Enforcement Officials in collecting and analyzing computer disk images. The tool allows the user to analyze evidence and detect fraud that has been carried out.
Features
The ProDiscover Disk Forensic Tool contains the following 4 components.
- User Interface
- Capture Module
- Analyzer Module
- Search Module
Each of these is briefly described below:
User Interface: This allows the user to interact with all the remaining backend modules to carry out the following tasks:
- Copying the seized disk to another disk
- Capturing the image
- Analyzing the cluster information
- Analyzing the list of files
- Searching and
- Report generation
Capture Module: Capture module will read the data from the seized disk and create an image file or a copy of the disk that is the input for the Analyser. This currently supports FAT16, FAT32 and NTFS disks.
Analyzer Module: This module reads the data from the image file or a disk created by the Capture module and analyzes the data. This will analyze the data in two ways:
- Analyzing the cluster information by displaying the contents of the clusters
- Analyzing the files by displaying the list of files and their attributes
Search Module: This module searches the image file or the disk for a text or binary pattern supplied by the user and gives the results.
Tools and
Technologies
Windows 2000, VC++. Visual Source Safe for version control, MS Project for Project Scheduling, Installshield for installation, Third party tools for compression etc.
- Ten Day Report
- UM Activity Report
- Event Summary Report
- Case Summary Report
- Case Manager Internal QA Report
- Utilization Management Report
- UM Production Report
- TSO Report
Conclusion
This is a really useful and versatile tool for Disk Forensics. The client has appreciated the contributions in creating this tool within the specified timeframe.
|