April 26, 2007
Conference Paper

Establishing Tap Reliability in Expert Witness Testimony: Using Scenarios to Identify Calibration Needs

Abstract

In this paper we expand work initially described in calibrating low-level network taps, where we used examples of how one might establish the degree of soundness for network data gathering devices, using low-level tap calibration as our example. Our approach in this paper is adapted from Weismann's Flaw Hypothesis Methodology for penetration testing design, and extends the earlier work by considering a broader range of typical misuse and attack scenarios, again with respect to lower layer network devices.

Revised: June 8, 2010 | Published: April 26, 2007

Citation

Endicott-Popovsky B.E., J.D. Fluckiger, and D.A. Frincke. 2007. Establishing Tap Reliability in Expert Witness Testimony: Using Scenarios to Identify Calibration Needs. In Proceedings of the Second International Workshop on Systematic Approaches to Digital Forensic Engineering (SADFE 2007), 131-146. Los Alamitos, California:IEEE Computer Society. PNNL-SA-53566. doi:10.1109/SADFE.2007.10