{"id":218,"date":"2015-06-22T13:41:36","date_gmt":"2015-06-22T18:41:36","guid":{"rendered":"https:\/\/fbreitinger.de\/?page_id=218"},"modified":"2021-12-06T01:51:01","modified_gmt":"2021-12-06T06:51:01","slug":"tools","status":"publish","type":"page","link":"https:\/\/fbreitinger.de\/?page_id=218","title":{"rendered":"Tools"},"content":{"rendered":"<p>Here is a list of tools that we created over time. For more information about the actual implementation or collaboration, see the corresponding publication (c+p the title(s) into the search):<\/p>\n<h2>mrsh &amp; co.<\/h2>\n<table style=\"width: 99.24953095684803%;\" width=\"100%\">\n<tbody>\n<tr>\n<td style=\"width: 16.68473851312946%;\" width=\"150\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2015\/06\/mrsh_cuckoo.zip\">mrsh_cuckoo<\/a><br \/>\n(last update 2015\/04\/10)<\/td>\n<td style=\"width: 82.56479244371857%;\">is a similiartiy hashing \/ approximate matching tool equal to mrsh-net but uses Cuckoo filter instead of Bloom filter. This increases runtime efficiency and needs less memory.<br \/>\n<div id=\"publications-link-218\" class=\"sh-link publications-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('publications', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"publications-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"publications-content-218\" class=\"sh-content publications-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">Vikas Gupta, Frank Breitinger: <\/span> <span class=\"tp_single_title\">How Cuckoo Filter Can Improve Existing Approximate Matching Techniques<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span> James, Joshua I.;  Breitinger, Frank (Ed.): <span class=\"tp_pub_additional_booktitle\">Digital Forensics and Cyber Crime, <\/span><span class=\"tp_pub_additional_pages\">pp. 39-52, <\/span><span class=\"tp_pub_additional_publisher\">Springer International Publishing, <\/span><span class=\"tp_pub_additional_year\">2015<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 978-3-319-25511-8<\/span><span class=\"tp_pub_additional_note\">, (bf Best Paper Award)<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 16.68473851312946%;\"><\/td>\n<td style=\"width: 82.56479244371857%;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 16.68473851312946%;\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2015\/06\/mrsh_net.zip\">mrsh_net<\/a><br \/>\n(last update 2014\/11\/12)<\/td>\n<td style=\"width: 82.56479244371857%;\">is the network implementation of mrsh-v2 which has a single huge Bloom filter for the signature.<br \/>\n<div id=\"mrshnet-link-218\" class=\"sh-link mrshnet-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('mrshnet', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"mrshnet-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"mrshnet-content-218\" class=\"sh-content mrshnet-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">Frank Breitinger, Ibrahim Baggili: <\/span> <span class=\"tp_single_title\">File Detection On Network Traffic Using Approximate Matching<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Journal of Digital Forensics, Security and Law (JDFSL), <\/span><span class=\"tp_pub_additional_volume\">vol. 9, <\/span><span class=\"tp_pub_additional_number\">no. 2, <\/span><span class=\"tp_pub_additional_pages\">pp. 23\u201336, <\/span><span class=\"tp_pub_additional_year\">2014<\/span><span class=\"tp_pub_additional_note\">, (bf Best Paper Award)<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 16.68473851312946%;\"><\/td>\n<td style=\"width: 82.56479244371857%;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"width: 16.68473851312946%;\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2018\/07\/mrsh_v2.0.zip\">mrsh_v2.0<\/a><br \/>\n(last update 2013\/10\/04)<\/td>\n<td style=\"width: 82.56479244371857%;\">is the original similarity hashing tool that allows to compares files \/ folders with each other.<br \/>\n<div id=\"mrsh2-link-218\" class=\"sh-link mrsh2-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('mrsh2', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"mrsh2-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"mrsh2-content-218\" class=\"sh-content mrsh2-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">Frank Breitinger, Harald Baier: <\/span> <span class=\"tp_single_title\">Similarity Preserving Hashing: Eligible Properties and a New Algorithm MRSH-v2<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span> Rogers, Marcus;  Seigfried-Spellar, KathrynC. (Ed.): <span class=\"tp_pub_additional_booktitle\">Digital Forensics and Cyber Crime, <\/span><span class=\"tp_pub_additional_pages\">pp. 167-182, <\/span><span class=\"tp_pub_additional_publisher\">Springer Berlin Heidelberg, <\/span><span class=\"tp_pub_additional_year\">2013<\/span>, <span class=\"tp_pub_additional_isbn\">ISBN: 978-3-642-39890-2<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<h2><\/h2>\n<h2>Further tools &amp; data<\/h2>\n<table style=\"height: 250px; width: 99.24953095684803%;\" width=\"100%\">\n<tbody>\n<tr style=\"height: 72px;\">\n<td style=\"width: 16.924546666606677%; height: 72px;\" width=\"150\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2017\/04\/FRASH_1.01.zip\">FRASH_v1.01<br \/>\n<\/a>(last update 2013\/02\/19)<\/td>\n<td style=\"width: 82.32498429024136%; height: 72px;\">is a testing framework for approximate matching algorithms. Special thanks to Georgios Stivaktakis for the development and\u00a0Edward Raff for the installations instructions.<br \/>\n<div id=\"FRASH-link-218\" class=\"sh-link FRASH-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('FRASH', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"FRASH-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"FRASH-content-218\" class=\"sh-content FRASH-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">Frank Breitinger, Georgios Stivaktakis, Harald Baier: <\/span> <span class=\"tp_single_title\">FRASH: A Framework to Test Algorithms of Similarity Hashing<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Digit. Investig., <\/span><span class=\"tp_pub_additional_volume\">vol. 10, <\/span><span class=\"tp_pub_additional_pages\">pp. S50\u2013S58, <\/span><span class=\"tp_pub_additional_year\">2014<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 1742-2876<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"height: 24px; width: 16.924546666606677%;\"><\/td>\n<td style=\"height: 24px; width: 82.32498429024136%;\"><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 16.924546666606677%; height: 24px;\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2017\/04\/GE-FANUC_controller_win_x86.zip\">Tool x86<\/a> \/ <a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2017\/04\/GE-RANUC_controller_win_x64.zip\">Tool x64<\/a><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2017\/04\/FRASH_1.01.zip\"><br \/>\n<\/a>(last update 2013\/02\/19)<\/td>\n<td style=\"width: 82.32498429024136%; height: 24px;\">an\u00a0application that allows direct network-based communication with the Programable Logic Controller GE Fanuc Series 90-30 (no intermediate server is needed). Note, in contrast to what is mentioned in the publication, we removed the write functionality for security reasons.<br \/>\n<div id=\"GEFanuc-link-218\" class=\"sh-link GEFanuc-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('GEFanuc', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"GEFanuc-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"GEFanuc-content-218\" class=\"sh-content GEFanuc-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">George Denton, Filip Karpisek, Frank Breitinger, Ibrahim Baggili: <\/span> <span class=\"tp_single_title\">Leveraging the SRTP protocol for over-the-network memory acquisition of a GE Fanuc Series 90-30<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 22, Supplement, <\/span><span class=\"tp_pub_additional_pages\">pp. S26 - S38, <\/span><span class=\"tp_pub_additional_year\">2017<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 1742-2876<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 16.924546666606677%; height: 24px;\"><\/td>\n<td style=\"width: 82.32498429024136%; height: 24px;\"><\/td>\n<\/tr>\n<tr style=\"height: 10px;\">\n<td style=\"width: 16.924546666606677%; height: 10px;\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2019\/02\/Timeline2GUI-master.zip\">Timeline2GUI-Tool<\/a><\/p>\n<p><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2018\/08\/Timeline2GUI_training_cases.zip\">Training Cases<br \/>\n<\/a>(last update 2018\/08\/03)<\/td>\n<td style=\"width: 82.32498429024136%; height: 10px;\">Timelin2GUI Tool and the training cases (three test cases to practice Log2Timeline). To check for updates, please see the corresponding <a href=\"https:\/\/github.com\/parvathycec\/Timeline2GUI\" target=\"_blank\" rel=\"noopener noreferrer\">github page<\/a>.<div id=\"timeline2gui-link-218\" class=\"sh-link timeline2gui-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('timeline2gui', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"timeline2gui-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"timeline2gui-content-218\" class=\"sh-content timeline2gui-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">Mark Debinski, Frank Breitinger, Parvathy Mohan: <\/span> <span class=\"tp_single_title\">Timeline2GUI: A Log2Timeline CSV parser and training scenarios<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 28, <\/span><span class=\"tp_pub_additional_pages\">pp. 34 - 43, <\/span><span class=\"tp_pub_additional_year\">2018<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 1742-2876<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 16.924546666606677%; height: 24px;\"><\/td>\n<td style=\"width: 82.32498429024136%; height: 24px;\"><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 16.924546666606677%; height: 24px;\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2020\/05\/ToolsTable.xlsx\">Digital Forensics Tool Table<\/a><br \/>\n(last update 2020\/06\/11)<\/td>\n<td style=\"width: 82.32498429024136%; height: 24px;\">is a list of forensics tools identified while reviewing almost 800 research articles from various digital forensic venues (2014-2019).<div id=\"dfTools-link-218\" class=\"sh-link dfTools-link sh-hide\"><a href=\"#\" onclick=\"showhide_toggle('dfTools', 218, 'Show relevant publications', 'Hide relevant publications'); return false;\" aria-expanded=\"false\"><span id=\"dfTools-toggle-218\">Show relevant publications<\/span><\/a><\/div><div id=\"dfTools-content-218\" class=\"sh-content dfTools-content sh-hide\" style=\"display: none;\"><div class=\"tp_single_publication\"><span class=\"tp_single_author\">Tina Wu, Frank Breitinger, Stephen O'Shaughnessy: <\/span> <span class=\"tp_single_title\">Digital forensic tools: Recent advances and enhancing the status quo<\/span>. <span class=\"tp_single_additional\"><span class=\"tp_pub_additional_in\">In: <\/span><span class=\"tp_pub_additional_journal\">Forensic Science International: Digital Investigation, <\/span><span class=\"tp_pub_additional_volume\">vol. 34, <\/span><span class=\"tp_pub_additional_pages\">pp. 300999, <\/span><span class=\"tp_pub_additional_year\">2020<\/span>, <span class=\"tp_pub_additional_issn\">ISSN: 2666-2817<\/span>.<\/span><\/div><\/div><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 16.924546666606677%; height: 24px;\"><\/td>\n<td style=\"width: 82.32498429024136%; height: 24px;\"><\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 16.924546666606677%; height: 24px;\"><a href=\"https:\/\/fbreitinger.de\/wp-content\/uploads\/2021\/12\/Fast-LD.zip\">Estimate Levenshtein Distance<\/a><br \/>\n(last update 2021\/10\/14)<\/td>\n<td style=\"width: 82.32498429024136%; height: 24px;\">is a tool (written in GoLang) that can estimate the Levenshtein Distance (LD) between two or more documents and is significantly faster than the original LD as it works on compressed signatures.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Here is a list of tools that we created over time. For more information about the actual implementation or collaboration, see the corresponding publication (c+p the title(s) into the search): mrsh &amp; co. mrsh_cuckoo (last update 2015\/04\/10) is a similiartiy hashing \/ approximate matching tool equal to mrsh-net but uses Cuckoo filter instead of Bloom [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":70,"comment_status":"closed","ping_status":"closed","template":"page-full-width.php","meta":{"footnotes":""},"class_list":["post-218","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/218","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=218"}],"version-history":[{"count":53,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/218\/revisions"}],"predecessor-version":[{"id":1129,"href":"https:\/\/fbreitinger.de\/index.php?rest_route=\/wp\/v2\/pages\/218\/revisions\/1129"}],"wp:attachment":[{"href":"https:\/\/fbreitinger.de\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}