Source-linked AI summary
Current Challenges and Future Research Areas for Digital Forensic Investigation
David Lillis, Brett Becker, Tadhg O'Sullivan, Mark Scanlon
TL;DR
Digital-forensics backlogs are driven by growing evidence volumes, increasing device diversity, and difficult cloud-based sources. The paper reviews these challenges and surveys automation, distributed processing, information retrieval, and related infrastructure improvements, concluding that more efficient processing and evidence handling could help address the backlog. It also notes that GPU advantages depend on assumptions about disk-read bottlenecks.
Problem
Growing numbers of relevant devices and rapidly expanding evidence volumes create major digital-forensics backlogs and increasingly difficult acquisition, storage, and analysis tasks.
Method
The paper reviews recent research on digital-forensics challenges and discusses infrastructural approaches including automation, distributed processing, information retrieval, and Forensics-as-a-Service.
Results
The review identifies distributed, parallel, GPU, FPGA, information-retrieval, deduplication, and related processing approaches as promising directions for improving forensic efficiency.
Takeaways & Limitations
More efficient allocation of forensic expertise through improved and expedited processing could help combat the digital-evidence backlog.
Takeaways & Limitations
GPU advantages are not established under the traditional single-disk model when disk-read speed is the limiting factor.
Abstract
from arXiv · showhide
Given the ever-increasing prevalence of technology in modern life, there is a corresponding increase in the likelihood of digital devices being pertinent to a criminal investigation or civil litigation. As a direct consequence, the number of investigations requiring digital forensic expertise is resulting in huge digital evidence backlogs being encountered by law enforcement agencies throughout the world. It can be anticipated that the number of cases requiring digital forensic analysis will greatly increase in the future. It is also likely that each case will require the analysis of an increasing number of devices including computers, smartphones, tablets, cloud-based services, Internet of Things devices, wearables, etc. The variety of new digital evidence sources pose new and challenging problems for the digital investigator from an identification, acquisition, storage and analysis perspective. This paper explores the current challenges contributing to the backlog in digital forensics from a technical standpoint and outlines a number of future research topics that could greatly contribute to a more efficient digital forensic process.
1. INTRODUCTION
Digital-forensics demand is expanding as more devices and data become relevant to investigations, creating backlogs that delay legal processes. The paper reviews these pressures and proposes infrastructural improvements, including automation and distributed processing, to make investigations more efficient.
- Cloud services, IoT devices, anti-forensic techniques, and heterogeneous storage create new acquisition, storage, and analysis challenges.
- Growing case volume, device counts, and evidence-rich data have made substantial digital-evidence backlogs inevitable.The backlog reflects increases in cases involving digital evidence, devices seized per case, and data stored on each device.
- Backlogs can delay investigations for years, impair the timeliness of criminal proceedings, and sometimes contribute to dismissed prosecutions.
- The review identifies automation, Forensics-as-a-Service, heterogeneous evidence processing, remote acquisition, and cross-jurisdictional sharing as practical infrastructure improvements.These approaches are linked to processes such as visualisation, multi-device timeline resolution, deduplication, distributed investigations, and process optimisation.
2. CURRENT CHALLENGES
Digital forensics faces interconnected problems of complexity, diversity, correlation, volume, and unified timelines, intensified by mobile, IoT, cloud, encryption, and growing data quantities. These conditions impede investigations and require more standardisation, automation, and specialised approaches for emerging evidence sources.
- The field’s core challenges are complexity, diversity, consistency and correlation, volume, and unified time lining.These arise from heterogeneous low-level data, nonstandard sources and formats, limited investigative assistance, insufficient automation, and incompatible timestamps.
- Case data at 15 FBI regional laboratories grew 6.65 times from 84GB to 559GB between 2003 and 2011, while cloud services obscure data location.
- Mobile and wearable devices expand the diversity of evidence, while correlating evidence across multiple devices is often performed manually.
- 2.1 Internet-of-Things: IoT investigations face uncertain data origins and storage locations, limited persistence, heterogeneous platforms, and early-stage forensic tooling.
- 2.2 Emerging Cloud Computing or Cloud Forensic Challenges: Cloud forensics must address distributed storage, multiple jurisdictions, provider cooperation, nonstandard services, multi-tenancy, encryption, and data that can be overwritten.
- 2.2 Emerging Cloud Computing or Cloud Forensic Challenges: Cloud-related challenges continue to impede investigations, which often stall before extending from perpetrators’ devices into the cloud services they use.
3. FUTURE RESEARCH
The paper identifies distributed, high-performance, cloud-based, deduplicated, and information-retrieval techniques as promising directions for making digital forensic analysis more efficient.
- 3.1 Distributed Digital Forensics: Distributed and high-performance computing could reduce computation and human analysis time in digital forensics.The paper discusses distributed processing, HPC, GPUs, FPGAs, and heterogeneous architectures as ways to address non-I/O-bound workloads.
- 3.3 GPU-Powered Multi-threading: GPU acceleration has shown viability for inspecting multiple disks independently, although its benefits depend on whether disk-read speed remains the bottleneck.Prior work reported significant gains over simple CPU threading, while another study found no advantage when disk reading limited performance.
- 3.4 DFaaS: DFaaS can centralize storage, automate processing, support direct detective queries, and improve collaboration, but latency and upload bandwidth remain constraints.The paper proposes improving detective functionality, indexing, and on-the-fly evidence identification within the DFaaS model.
- 3.4 DFaaS: Deduplicated evidence storage could avoid repeated storage, indexing, analysis, and annotation while retaining reconstructible full disk images for admissibility.The approach would store each unique file once and remove benign files during acquisition, while preserving the ability to reconstruct a forensically sound image.
- 3.6 Applying Complementary Cutting Edge Research to Forensics: Configurable information retrieval could prioritize precision during triage and recall during later court-oriented case development.The proposed adjustment lets investigators make faster decisions about whether a device warrants full investigation.
- 3.6 Applying Complementary Cutting Edge Research to Forensics: Temporal-information extraction from unstructured text could reduce investigators’ manual workload when constructing timelines.Potential source data includes chat logs, file modification times, and email timestamps.
4. CONCLUSION
The paper concludes that interacting technical challenges, limited expertise, and growing evidence volumes have produced years-long digital forensic backlogs. It identifies distributed, parallel, GPU, FPGA, information-retrieval, and deduplication techniques as promising ways to improve efficiency.
- 4. CONCLUSION: Digital forensic backlogs have reached years for many law enforcement agencies, with future growth in cloud and Internet-of-Things evidence expected to compound the problem.The paper attributes the increase to combined technical challenges, limited expertise, and large workloads.
- 4. CONCLUSION: Distributed, parallel, GPU, FPGA, and information-retrieval techniques could improve allocation of scarce forensic expertise by accelerating the process.The paper also highlights deduplicated storage and analysis to avoid repeated processing of previously encountered content.