Forensic Cop Journal Volume 1(2), Oct 2009
Similarities and Differences between Ubuntu and Windows onForensic Applications
by Muhammad Nuh Al-Azhar, CHFI
MSc in Forensic Informatics from the University of Strathclyde, UKForensic Investigator at Forensic Laboratory Centre of Indonesian National Police HQ.
In dealing with computer crime, the forensic investigators are faced to volatile digitalevidence which must be discovered as soon as possible because sooner it can be recovered,better the criminal investigators handle the case, even it can make the duty of theinvestigators become easy to locate and catch the perpetrators. There are many ways tocarry out forensic investigation on cases of computer crime. Although there is a bunch of various different techniques for this purpose, essentially they have same goal, namely torecover the digital evidence, and then serve it for court.There are two conditions in which the forensic investigators often deal with; they areforensic analysis under Microsoft Windows and under Linux OS such as Ubuntu. In this case,Ms Windows and Ubuntu have their own advantages and disadvantages regarding withcomputer forensic examination. In some extent, they have similarities, but in the othercases, they also have differences. This journal
will describe the topic about “
similarities anddifferences between Ubuntu and Ms Windows on forensic applications
. The descriptionsalso include practical samples of forensic tools in order to support the opinion.
In order to run this research on the track, I make some experiments based on my experiencein investigating the case of computer crime by setting up 4 GB flash disk as experimentalobject. I configure it to be 3 partitions by using Partition Editor application from Ubuntu. Thefirst partition is FAT32 with the size of 1000 Mbyte in which I install Helix Forensics by usingUSB Startup Creator from Intrepid so that it becomes bootable flash disk to run HelixForensics live, then I also put some files which have different file extensions such as pdf, doc,odt, ppt, jpg, odp and so on in different folders, some of these files are then deleted. Thefirst partition becomes one of the objects of experiments. To be more focus on analysing, Ilimit the similarities in 5 points of view and differences in 3 points of view.
Based on the explanations supported by experience and some experiments performed,there are at least 5 points of similarities between Ubuntu and Ms Windows regarding withforensic analysis. They are:1.