JIS  Vol.6 No.2 , April 2015
A Comparative Study of Email Forensic Tools
Abstract: Over the last decades, email has been the major carrier for transporting spam and malicious contents over the network. Email is also the primary source of numerous criminal activities on the Internet. Computer Forensics is a systematic process to retain and analyze saved emails for the purpose of legal proceedings and other civil matters. Email analysis is challenging due to not only various fields that can be forged by hackers or malicious users, but also the flexibility of composing, editing, deleting of emails using offline (e.g., MS Outlook) or online (e.g., Web mail) email applications. Towards this direction, a number of open source forensics tools have been widely used by the practitioners. However, these tools have been developed in an isolated manner rather than a collaborative approach. Given that email forensic tool users need to understand to what extent a tool would be useful for his/her circumstances and conducting forensic analysis accordingly. In this paper, we examine a set of common features to compare and contrast five popular open source email forensic tools. The study finds that all email forensic tools are not similar, offer diverse types of facility. By combining analysis tools, it may be possible to gain detailed information in the area of email forensic.
Cite this paper: Devendran, V. , Shahriar, H. and Clincy, V. (2015) A Comparative Study of Email Forensic Tools. Journal of Information Security, 6, 111-117. doi: 10.4236/jis.2015.62012.

[1]   Conan Albrecht, Email Analysis.

[2]   McAfee SaaS Email Protection.

[3]   Banday, M. (2011) Analyzing Email Headers for Forensic Investigation. Journal of Digital Forensics, Security, and Law, 6, 50-64.

[4]   Meghanathan, N., Allam, S.R. and Moore, L.A. (2009) Tools and Techniques for Network Forensics. International Journal of Network Security and its Applications, 1, 14-25.

[5]   Garfinkel, S.L. (2010) Digital Forensics Research: The Next 10 Years. Digital Investigation, 7, S64-S73.

[6]   MailXaminer.

[7]   Aid4Mail Forensic.

[8]   Digital Forensics Framework.

[9]   EMailTrackerPro.

[10]   Paraben (Network) E-mail Examiner.

[11]   Garfinkel, S. (2006) Forensic Feature Extraction and Cross-Drive Analysis. Digital Investigation, 3, 71-81.

[12]   Marwan A.Z. (2004) Tracing E-mail Headers. Proceedings of Australian Computer, Network & Information Forensics Conference, November 2004, School of Computer and Information Science, Edith Cowan University Western Australia, 16-30.

[13]   Free Computer Forensic Tool.

[14]   Digital Intelligence Forensic Software.