Most digital investigations rely on textual evidence. This is obviously due to the fact that most stored digital data is linguistic, for example, logged conversation. A lot of important text-based evidence can be gathered while dumping strings from images (smartphone memory dumps); this can include e-mails, instant messaging, address books, browsing history, and more. Most of the currently available digital forensic tools rely on match and indexing algorithms to search for textual evidence at the physical level, so they search every byte to locate specific text strings.
Finding accurate hits is a critical need in every digital forensic case. In contrast to searching individual key terms or single words, things are much more complicated when an investigator wants to perform an advanced search such as for credit card numbers or phone number. Even if most digital forensic tools offer the capability to use regular expression for searching, the main difficulty resides...