Distributed Processing: Impressive Test Results!
In testing, AccessData fully processed
a massive data set, including 62,649,383 items, of which there were well over
2 million emails and a total of 97,431
archive files that needed to be broken out.
The compressed size of this data set was
1.28 terabytes. A data set this large
would normally be divided into batches,
with each batch being processed
separately on stand-alone machines.
This could take a month to process,
using traditional tools, depending on the
hardware used. However with AccessData’s
distributed processing technology, it only
took 6 days, 5 hours.
The AccessData® Lab family of solutions enables labs of all sizes, facing an array of challenges, to work more effectively. Single person labs can radically speed up the processing of cases with the 4-worker distributed processing available with FTK. However, labs handling a greater number of cases with larger data sets will benefit significantly from the unlimited distributed processing capabilities, centralized database and processing infrastructure, collaborative analysis and web-enabled case management found in Lab Lite. Finally large labs that either utilize a distributed workforce or would like to collaborate with lawyers, HR personnel or any other non-forensic personnel can step up to AD Lab, which adds powerful and intuitive web-based review functionality. Regardless of the size, scope or mission of your lab, AccessData has a solution that will meet your needs.
Which solution is right for you?
FUNCTIONALITY
FTK
AD LAB LITE
AD LAB
Distributed Processing
4 WORKERS
UNLIMITED
UNLIMITED
Share a Central Database Infrastructure
NO
YES
YES
Investigator Collaboration
NO
UNLIMITED
UNLIMITED
Case and Task Management
NO
YES
YES
Role-based Permissions to
Control Access & Activity
NO
YES AT THE CASE LEVEL
YES
AT THE DATA LEVEL
Web Review & Analysis
NO
NO
UNLIMITED
ACCESSDATA LAB Product Features
A Secure Solution
Data can be fully secured at the case or file level.
Granular role-based administration allows administrators to assign users to a given case or set of data within a case.
Users can be restricted by feature, so only qualified users can access more advanced functions.
Centralized processing, indexing and data storage.
Examiners can leverage a distributed processing farm and share a database.
Create a case and associate a given set of processed data to it, including non-forensic evidence (images, log files, recordings).
Assign multiple analysts to a case, assign tasks with deadlines and monitor progress.
Notify analysts when new tasks have been assigned to them.
Create custom tasks and case types.
Search by case type, case notes or tasks.
Administrators can assign specific data sets to each analyst. (e.g. analyst can only look at email from drive one in case abc123)
Ease of Use and Efficiency
Leverage a shared distributed processing farm to processing massive data sets in a fraction of the time it would take using traditional tools.
Distributed Processing obviously requires powerful hardware and networking technology. Processing evidence is very disk IO intensive and requires fast drives. In addition, the machine that runs the Processing Manager must be the fastest computer (CPU) speed in the processing group. Finally, you will need the fastest networking technology available to you. For details on configuring distributed processing, please see the following documents. However, Lab customers will receive configuration assistance from our engineering team to ensure optimized functionality.
Easily overcome the bandwidth constraints of distributed labs with centralized or distributed databases and web-based analysis enabling efficient sharing of workload.
Investigators can share a centralized distributed processing worker farm.
Native document review allows analysts to view and tag data as if the documents were in their native application.
Oracle database enables simultaneous collaboration and review.
Integrates with both FTK® and AD Enterprise to streamline investigations for law enforcement, government and corporate labs.
Fully leverage the cutting-edge analysis capabilities of Forensic Toolkit® technology