Přístupnostní navigace
E-application
Search Search Close
Master's Thesis
Author of thesis: Ing. Dominik Sabota
Acad. year: 2025/2026
Supervisor: doc. Ing. Zdeněk Martinásek, Ph.D.
Reviewer: Ing. Willi Lazarov
Digital forensic analysis is critical for investigating crimes and security incidents, yet tools ensuring systematic compliance with international standards and Czech legal framework are absent. This thesis proposes, implements and empirically verifies three interactive checklists for key scenarios: Police Interrogation with Chain of Custody, Photo Recovery from Damaged Media, and Malware Incident Investigation. Each workflow contains 8–25 atomic steps with decision points implementing NIST SP 800-86 and ISO/IEC 27037:2012 requirements. Comparative analysis revealed no universal workflow exists—each scenario requires a tailored approach reflecting specific legal and technical constraints. The proposed procedures were implemented as the ptforensictoolkit suite of 17 Python scripts and 40 work cards covering all 40 atomic steps and validated on the BUTCA platform. The thesis provides a reference model for forensic laboratories, law enforcement agencies, and academic institutions in the Czech environment.
Chain of Custody, cryptographic hashing, digital forensics, forensic integrity, interactive checklist, ISO/IEC 27037, malware investigation, NIST SP 800-86, photo recovery, ptforensictoolkit, reproducibility, standardization, verification, workflow automation
Date of defence
09.06.2026
Result of the defence
Defended (thesis was successfully defended)
Grading
A
Process of defence
Student prezentoval výsledky své práce a komise byla seznámena s posudky. Student obhájil diplomovou práci a odpověděl na otázky členů komise a oponenta. Otázky: 1) Validace funkčnosti proběhla na médiích o kapacitě v řádech gigabajtů, přičemž výkonová charakteristika u terabajtových úložišť nebyla ověřena. Které kroky vašich pracovních postupů považujete za nejkritičtější z hlediska škálovatelnosti na reálné forenzní případy a jaké problémy by mohly u větších úložišť nastat? 2) Slovník REPAIR_SUCCESS_RATES přiřazuje každému typu poškození pevnou míru úspěšnosti opravy. Uvažoval jste o tom, aby se tyto hodnoty adaptivně aktualizovaly na základě skutečných výsledků oprav při běhu nástroje, a jaká rizika z hlediska forenzní reprodukovatelnosti by to přineslo? 3) Vy jste zmiňoval, že se dá scénář použít v praxi, ne vždy je to triviální. Byl u toho konzultován nějaký právník? 4) Používali jste komerční, nebo open-source nástroje ve scénáři?
Language of thesis
Czech
Faculty
Fakulta elektrotechniky a komunikačních technologií
Department
Department of Telecommunications
Study programme
Information Security (MPC-IBE)
Composition of Committee
prof. Ing. Jan Hajný, Ph.D. (předseda) JUDr. Ing. František Kasl, Ph.D. (místopředseda) Ing. Jan Látal, Ph.D. (člen) Ing. Petr Ilgner, Ph.D. (člen) Ing. František Urban, Ph.D. (člen) Ing. Willi Lazarov (člen) Ing. Peter Balušík (člen) doc. Ing. Karol Molnár, Ph.D. (člen)
Supervisor’s reportdoc. Ing. Zdeněk Martinásek, Ph.D.
Grade proposed by supervisor: A
Reviewer’s reportIng. Willi Lazarov
Grade proposed by reviewer: A
Responsibility: Mgr. et Mgr. Hana Odstrčilová