{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:14:15Z","timestamp":1750220055166,"version":"3.41.0"},"reference-count":25,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,2,28]],"date-time":"2023-02-28T00:00:00Z","timestamp":1677542400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2023,2,28]]},"abstract":"<jats:p>This article presents our experience updating the high-performance Digital forensics tool BE (bulk_extractor) a decade after its initial release. Between 2018 and 2022, we updated the program from C++98 to C++17. We also performed a complete code refactoring and adopted a unit test framework. DF tools must be frequently updated to keep up with changes in the ways they are used. A description of updates to the bulk_extractor tool serves as an example of what can and should be done.<\/jats:p>","DOI":"10.1145\/3587827","type":"journal-article","created":{"date-parts":[[2023,3,28]],"date-time":"2023-03-28T17:25:11Z","timestamp":1680024311000},"page":"30-56","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Sharpening Your Tools"],"prefix":"10.1145","volume":"21","author":[{"given":"Simson","family":"Garfinkel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jon","family":"Stewart","sequence":"additional","affiliation":[{"name":"Aon Cyber Solutions"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,3,28]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.4103\/IJPSYM.IJPSYM_334_18"},{"volume-title":"Transitioning the use of cryptographic algorithms and key lengths","author":"Barker R.","key":"e_1_2_1_2_1","unstructured":"Barker, R., Roginsky, A. 2019. Transitioning the use of cryptographic algorithms and key lengths. National Institute of Standards and Technology, Special Publication 800-131A, revision 2; https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-131Ar2.pdf."},{"volume-title":"Test-Driven Development: By Example","author":"Beck K.","key":"e_1_2_1_3_1","unstructured":"Beck, K. 2002. Test-Driven Development: By Example. Addison-Wesley Professional."},{"key":"e_1_2_1_4_1","unstructured":"BitCurator; https:\/\/bitcurator.net\/."},{"volume-title":"The Mythical Man-Month?Essays on Software Engineering","author":"Brooks F. P.","key":"e_1_2_1_5_1","unstructured":"Brooks, F. P. 1975. The Mythical Man-Month?Essays on Software Engineering. Addison-Wesley."},{"key":"e_1_2_1_6_1","unstructured":"Catch2. GitHub; https:\/\/github.com\/catchorg\/Catch2."},{"key":"e_1_2_1_7_1","unstructured":"Cellebrite. Blackbag technology software user license agreements; https:\/\/cellebrite.com\/en\/blackbag-agreements\/."},{"key":"e_1_2_1_8_1","unstructured":"cxxopts. GitHub; https:\/\/github.com\/jarro2783\/cxxopts."},{"key":"e_1_2_1_9_1","unstructured":"Donnelly C. Stallman R. M. Bison?the Yacc-compatible parser generator. Free Software Foundation; https:\/\/www.gnu.org\/software\/bison\/manual\/; ftp:\/\/ftp.gnu.org\/pub\/gnu\/bison\/."},{"key":"e_1_2_1_10_1","unstructured":"Flex?fast lexical analyzer generator GNU software package; https:\/\/github.com\/westes\/flex."},{"key":"e_1_2_1_11_1","volume-title":"Refactoring: Improving the Design of Existing Code","author":"Fowler M.","year":"2018","unstructured":"Fowler, M. 2018. Refactoring: Improving the Design of Existing Code, Second Edition. Addison-Wesley Professional."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1511\/2013.104.370"},{"key":"e_1_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Garfinkel S. L. 2013. Digital media triage with bulk data analysis and bulk_extractor. Computers and Security 32(C) 56?72; https:\/\/dl.acm.org\/doi\/10.5555\/2748150.2748581.","DOI":"10.1016\/j.cose.2012.09.011"},{"key":"e_1_2_1_14_1","volume-title":"Version 2.0, Simson Garfinkel and Associates","author":"Garfinkel S.","year":"1992","unstructured":"Garfinkel, S. 1992. SBook: Simson Garfinkel's Address Book, Version 2.0, Simson Garfinkel and Associates; https:\/\/simson.net\/ref\/1992\/SBook20.pdf."},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the Ninth Annual Digital Forensic Research Workshop 6 (supplement); https:\/\/www.sciencedirect.com\/science\/article\/pii\/S1742287609000346","author":"Garfinkel S. L.","year":"2009","unstructured":"Garfinkel, S. L., Farrell, P., Roussev, V., Dinolt, G. 2009. Bringing science to digital forensics with standardized forensic corpora. In Digital Investigation, Proceedings of the Ninth Annual Digital Forensic Research Workshop 6 (supplement); https:\/\/www.sciencedirect.com\/science\/article\/pii\/S1742287609000346."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/2748150.2748581"},{"key":"e_1_2_1_17_1","volume-title":"Remembrance of data passed","author":"Garfinkel S.","year":"2003","unstructured":"Garfinkel, S., Shelat, A. 2003. Remembrance of data passed. IEEE Security and Privacy 1(1), 17?27; https:\/\/dl.acm.org\/doi\/abs\/10.1109\/MSECP.2003.1176992."},{"key":"e_1_2_1_18_1","unstructured":"Liu J. Moore R. T. 2015. An overview of the NSA's declassified intelligence oversight board reports. Lawfare; https:\/\/www.lawfareblog.com\/overview-nsas-declassified-intelligence-oversight-board-reports."},{"key":"e_1_2_1_19_1","unstructured":"Marlinspike M. 2021. Exploiting vulnerabilities in cellebrite UFED and physical analyzer from an app's perspective. Signal; https:\/\/signal.org\/blog\/cellebrite-vulnerabilities\/."},{"key":"e_1_2_1_20_1","volume-title":"Forensic examination of digital evidence: a guide for law enforcement","author":"National Institute of Justice. 2004.","year":"1994","unstructured":"National Institute of Justice. 2004. Forensic examination of digital evidence: a guide for law enforcement; https:\/\/www.ojp.gov\/pdffiles1\/nij\/199408.pdf."},{"key":"e_1_2_1_21_1","volume-title":"Systems Engineering","author":"Office","year":"2011","unstructured":"Office of Deputy Assistant Secretary of Defense, Systems Engineering. 2011. Value engineering: a guidebook of best practices and tools; https:\/\/www.usace.army.mil\/Portals\/2\/docs\/Value%20Engineering\/DoD%20SD-24_VE%20Handbook.pdf."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the Usenix Annual Technical Conference, 28; https:\/\/dl.acm.org\/doi\/10","author":"Serebryany K.","year":"2012","unstructured":"Serebryany, K., Bruening, D., Potapenko, A., Vyukov, D. 2012. AddressSanitizer: a fast address sanity checker. In Proceedings of the Usenix Annual Technical Conference, 28; https:\/\/dl.acm.org\/doi\/10.5555\/2342821.2342849."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1791194.1791203"},{"volume-title":"The C++ Programming Language","author":"Stroustrup B.","key":"e_1_2_1_24_1","unstructured":"Stroustrup, B. 2013. The C++ Programming Language, Fourth Edition. Addison-Wesley; https:\/\/www.stroustrup.com\/4th.html."},{"key":"e_1_2_1_25_1","unstructured":"Young W. D. Boebert W. Kain R. 1985. Proving a computer system secure. The Scientific Honeyweller 6(2) 18?27."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3587827","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3587827","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:08:27Z","timestamp":1750183707000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3587827"}},"subtitle":["Updating bulk_extractor for the 2020s"],"short-title":[],"issued":{"date-parts":[[2023,2,28]]},"references-count":25,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,2,28]]}},"alternative-id":["10.1145\/3587827"],"URL":"https:\/\/doi.org\/10.1145\/3587827","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"type":"print","value":"1542-7730"},{"type":"electronic","value":"1542-7749"}],"subject":[],"published":{"date-parts":[[2023,2,28]]},"assertion":[{"value":"2023-03-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}