Jesse Kornblum

Jesse Kornblum

Jesse Kornblum (1975-) is a former government computer investigator and now computer forensics researcher who has written a number of papers and tools to advance the field. These papers include "Preservation of Fragile Digital Evidence by First Responders" in 2002 which presented the first automated tools for incident response. These tools allow an examiner to gather evidence with a minimum of disruption to the system and maximize the ability to take evidence to court. His other major paper, "Exploiting the Rootkit Paradox with Windows Memory Analysis" from 2006 highlighted the power of examining physical memory when searching for malware.

In addition to papers, Jesse has authored a number of valuable computer forensics tools. His most notable, ssdeep, made use of a combination of hashing algorithms to help identify highly similar but not identical files; a vexing problem with no previous solutions. Although the idea was borrowed from Andrew Tridgell's spamchecker, it was the first use of such a technique in computer forensics and opened the field to similarity matching. The tool was accompanied by the paper "Identifying Almost Identical Files Using Context Triggered Piecewise Hashing."

Papers

* [http://dx.doi.org/10.1016/j.diin.2006.12.002 Using Every Part of the Buffalo in Windows Memory Analysis]
* [http://www.csa.syr.edu/Jesse_Kornblum.pdf Preservation of Fragile Digital Evidence by First Responders]
* [http://dfrws.org/2006/proceedings/12-Kornblum.pdf Identifying Almost Identical Files Using Context Triggered Piecewise Hashing]
* [http://www.utica.edu/academic/institutes/ecii/publications/articles/EFE2FC4D-0B11-BC08-AD2958256F5E68F1.pdf Exploiting the Rootkit Paradox with Windows Memory Analysis]

Tools

* [http://foremost.sf.net Foremost] - file carving
* md5deep - Recursive MD5, SHA-1, SHA-256, Tiger and Whirlpool client.
* [http://ssdeep.sf.net ssdeep] - Context Triggered Piecewise Hashing


Wikimedia Foundation. 2010.

Игры ⚽ Нужна курсовая?

Look at other dictionaries:

  • Kornblum — may refer to:cience*Kornblum Oxidation A chemical reaction of a primary halide with dimethyl sulfoxide (DMSO) to form an aldehyde. *Kornblum DeLaMare Rearrangement A rearrangement reaction in organic chemistry in which a primary or secondary… …   Wikipedia

  • Kornblum — ist der Name folgender Personen: Allan Kornblum (1938–2010), US amerikanischer Bundesrichter Jesse Kornblum (* 1975), US amerikanische Forscherin John Kornblum (* 1943), US amerikanischer Diplomat Siehe auch: Kornblum Regel, Konzept der… …   Deutsch Wikipedia

  • List of people called Jesse — Infobox Given Name Revised name = Jesse imagesize= caption= pronunciation= gender = Usually male meaning = region = origin = related names = Jessie, Jessica footnotes = Jesse is a common first name in many English speaking countries. This… …   Wikipedia

  • md5deep — Original author(s) Jesse Kornblum Developer(s) Jesse Kornblum Stable release 3.9 / April 21, 2011; 5 months ago (2011 04 21) …   Wikipedia

  • Foremost — Entwickler Kris Kendall, Jesse Kornblum, Nick Mikus Aktuelle Version 1.5.7 (6. Mai 2009) Betriebssystem Unix ähnliche (GNU/Linux, xBSD, Mac OS X, ...) Programmier­ …   Deutsch Wikipedia

  • Md5deep — Infobox Software name = md5deep caption = collapsible = developer = latest release version = 3.1 latest release date = release date|2008|7|23 operating system = Cross platform programming language = C genre = license = Public Domain website =… …   Wikipedia

  • Comparison of file verification software — The following tables compare file verification software that typically use checksums to confirm the integrity or authenticity of a file. Contents 1 General 2 Program hash function support 3 Program features 4 …   Wikipedia

  • Dave Morice — Birth name David Jennings Patrick Morice Born September 10, 1946 St. Louis, MO Dave Morice (born September 10, 1946) is a …   Wikipedia

  • Richard Holbrooke — United States Special Envoy for Afghanistan and Pakistan In office January 22, 2009 – December 13, 2010 President Barack Obama …   Wikipedia

  • Scientific phenomena named after people — This is a list of scientific phenomena and concepts named after people (eponymous phenomena). For other lists of eponyms, see eponym. NOTOC A* Abderhalden ninhydrin reaction Emil Abderhalden * Abney effect, Abney s law of additivity William de… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”