Subscribe

OSS: The alternative in digital forensics?

By Dave Glazier, ITWeb journalist
Johannesburg, 10 Mar 2006

Open source software (OSS) tools can be credible and reliable in digital forensics, says Cobus Venter, senior researcher at The Cyber Security Science Centre, a division of the Council for Scientific and Industrial Research (CSIR).

Digital forensics is the analysis and validation of sources of digital evidence, primarily used to determine whether the evidence may be used in legal cases.

According to SA`s Electronic Communications and Transactions Act of 2002, verifiable digital information can be used in court cases and internal disciplinary hearings.

Speaking yesterday at the ITWeb Security Summit, Venter said OSS should be regarded as more credible than proprietary software. "Testing something where you have the source code is far easier than testing commercial software.

"Open source software has been accepted in court," he said, but added that there is limited usage of OSS tools in forensic investigations both locally and around the world.

"People have the misconception that digital evidence will not stand up in court unless you have the backing of a large software company`s name behind you," said Venter.

He explained that software that has been published and reviewed by peers should be regarded as valid in investigations.

Open source is also a cheaper alternative, he noted.

Venter added, however, that OSS digital forensic tools may take longer to learn how to use and implement than commercial tools.

Share