Book Image

Big Data Forensics: Learning Hadoop Investigations

Book Image

Big Data Forensics: Learning Hadoop Investigations

Overview of this book

Table of Contents (15 chapters)
Big Data Forensics – Learning Hadoop Investigations
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
Index

Summary


In this chapter, we covered the elements of performing filesystem-level analysis and data carving. The topics we discussed included taking the data from a forensic image or performing a logical file collection, various analysis techniques, and data extraction methods. The analysis techniques, such as timeline analysis and keyword analysis, may be sufficient for an investigation where a key event or a small set of data is required for the investigation. In other cases, the analysis performed in this chapter can be part of a larger investigation that includes both Hadoop data and data from other systems.

Regardless of the role of the analysis, the information must be presented. Taking the analysis and putting that into an illustrative and accessible presentation format is critical for conveying the results. The presentation of this type of information is covered in Chapter 8, Presenting Forensic Findings.

Some of the data extraction methods are performed in order to prepare data for...