English

Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing

Cryptography and Security 2025-05-23 v1

Abstract

The acquisition of data from main memory or from hard disk storage is usually one of the first steps in a forensic investigation. We revisit the discussion on quality criteria for "forensically sound" acquisition of such storage and propose a new way to capture the intent to acquire an instantaneous snapshot from a single target system. The idea of our definition is to allow a certain flexibility into when individual portions of memory are acquired, but at the same time require being consistent with causality (i.e., cause/effect relations). Our concept is much stronger than the original notion of atomicity defined by Vomel and Freiling (2012) but still attainable using copy-on-write mechanisms. As a minor result, we also fix a conceptual problem within the original definition of integrity.

Cite

@article{arxiv.2505.15921,
  title  = {Defining Atomicity (and Integrity) for Snapshots of Storage in Forensic Computing},
  author = {Jenny Ottmann and Frank Breitinger and Felix Freiling},
  journal= {arXiv preprint arXiv:2505.15921},
  year   = {2025}
}

Comments

Proceedings of the Digital Forensics Research Conference Europe (DFRWS EU), March 29-April 1, 2022

R2 v1 2026-07-01T02:29:37.100Z