DFRWS 2013 Agenda

The DFRWS 2013 Agenda below summarizes the program of discussion and research. This years conference is held in cooperation with the Association for Computing Machinery (ACM) and its Special Interest Group on Security, Audit and Control (SIGSAC). .

Sunday, August 4, 2013

11:30am Registration Opens
 Workshop Track 1Workshop Track 2
12:30pm Advanced Smartphone Forensics & Incident Response
(Note: this session is all afternoon, 12:30-5:00pm)
Eoghan Casey and Bradley Schatz
Intrusion Forensics
(Note: this session is all afternoon, 12:30-5:00pm)
Cory Altheide
2:30pm Break
3:00pm --continued-- --continued--
5:30pm Registration closes

Monday, August 5, 2013

8:00am Registration
9:00am Opening Remarks - Florian Buchholz
9:10am Keynote Address
Morgan Marquis-Boire (Google)
CuteCats.exe and Protecting Citizens of the Internet
10:00am Break
10:15am SESSION 1: Mobile Forensics
Chair: Clay Shields
  • "Android forensics: automated data collection and reporting from a mobile device" Justin Grover ( paper | pres )
  • "Automated Identification of Installed Malicious Android Applications" Mark Guido, Justin Grover, Jared Ondricek, Dave Wilburn, Drew Hunt and Thanh Nguyen ( paper | pres )
  • "A Study of User Data Integrity During Acquisition of Android Devices" Namheun Son, Yunho Lee, Dohyun Kim, Joshua I. James, Sangjin Lee and Kyungho Lee. ( paper | pres )
11:45am Lunch on your own
1:45pm SESSION 2: Multi-Language Processing
Chair: Wietse Venema
  • "Unicode Search of Dirty Data, Or: How I Learned to Stop Worrying and Love Unicode Technical Standard #18" Jon Stewart and Joel Uckelman. ( paper | pres )
  • "Language Translation for File Paths" Neil Rowe, Riqui Schwamm and Simson Garfinkel. ( paper | pres )
    Best Paper (tie)
2:45pm Break
3:00pm Panel Discussion
Title: Is Digital Forensics a Science or not?
Moderator: Eoghan Casey
  • Cindy Murphy
  • Dave Baker
  • Ovie Carroll
4:30pm Five-Minute Teasers for Tool Demos and poster session
5:00pm Welcome Reception(Poster and Demo session)

Tuesday, August 6, 2013

8:00am Registration
9:00am Administrative Remarks
9:05am Keynote Address
Cindy Murphy (Madison, Wisconsin Police Department)
Strangers in a Strange Land - a local cop's perspective on policing the high tech beat
10:00am Break
10:15am SESSION 3: File and fragment processing
Chair: Joel Young
  • "Improved Recovery and Reconstruction of DEFLATEd Files" Ralf Brown ( paper | pres )
    Best Paper (tie)
  • "FRASH: A framework to test algorithms of similarity hashing" Frank Breitinger, Georgios Stivaktakis and Harald Baier. ( paper | pres )
  • "File Fragment Encoding Classification:An Empirical Approach" Vassil Roussev and Candice Quates. ( paper | pres )
11:45am Lunch on your own
1:45pm Panel Discussion: Approximate Matching of Digital Artifacts
Moderator: Barbara Guttman, NIST
  • Frank Breitinger, CASED, Germany
  • Simson Garfinkel, Naval Postgraduate School
  • Jesse Kornblum, Facebook
  • Clay Shields, Georgetown University
3:15pm Break
3:30pm SESSION 4: New forensic environments
Chair: Elizabeth Schweinsberg
  • "Design and Implementation of FROST: Digital Forensic Tools for the OpenStack Cloud Computing Platform" Josiah Dykstra and Alan Sherman ( paper | pres )
  • "Modern Ships Voyage Data Recorders: a Forensics Perspective on the Costa Concordia Shipwreck" Mario Piccinelli and Paolo Gubian. ( paper | pres )
4:30pm DFRWS 2013 Forensic Challenge presentations and prizes
Wietse Venema
6:00pm Banquet
  • Best Paper Award
7:30pm Forensic Rodeo

Wednesday, August 7, 2013

9:00am SESSION 5: Memory Forensics
Chair: Florian Buchholz
  • "An Evaluation Platform for Forensic Memory Acquisition Software" Stefan Voemel and Johannes Stuettgen. ( paper | pres )
  • "Integrity Verification of User Space Code" Andrew White, Bradley Schatz and Ernest Foo. ( paper | pres )
  • "Anti-Forensic Resilient Memory Acquisition" Johannes Stuettgen and Michael Cohen. ( paper | pres )
10:30am Short Presentations & Works in Progress
(5 minutes each)
Daryl Pfeif
11:15am Closing Comments
11:30am Lunch on your own
 Workshop Track 1Workshop Track 2
13:30pm Timeline Analysis with l2t and plaso
(Note: this session is all afternoon, 12:30-5:00pm)
Kristinn Gudjonsson and Elizabeth Schweinsberg
Small data forensics on a large scale
Candice Quates and Vassil Roussev
2:30pm Break
3:00pm --continued-- Memory Forensics to Defeat Encryption, Find Malware, and Help You Lose Weight
Jesse Kornblum
6:30pm Dinner & DFRWS 2014 / 2015 Planning Session
(Not Included in Registration Fee)

©2001-2016 DFRWS   |   dfrws [at] dfrws [dot] org  

DFRWS is a US 501(c)(3) non-profit organization.