Digital Forensic Evidence

No description

Gavin McKay

on 14 December 2012

Transcript of Digital Forensic Evidence

5) Disconnect all cords 6) Check for HPA and hard drives then package everything with antistatic evidence bags. Digital Forensic Evidence How do you preserve it and make it admissible in court? What are the tools of digital evidence and how are they used? What are the problems with digital evidence and how can they be solved? How does law enforcement obtain digital evidence? Procedures to handle digital evidence must be up to date so it remains admissible in court. Also, always make sure to store evidence on separate tapes so as to keep the evidence separate from other cases. The steps to handling digital evidence Identification Preservation Collection Examination Analysis Presentation Things that could possibly be evidence must be identified. This can be tricky because frequently not everything at a crime scene is evidence. Ex: Log files, external logs, primary memory, and volatile memory Transient: evidence that may not be there that long. Semi-permanent: evidence that will remain longer. Digital evidence is extremely volatile and can easily be lost or modified. This can be prevented or minimized by taking steps such as having multiple backup copies, data on readable discs only which cannot be rewritten, observing the chain of custody, and when it is absolutely necessary to access the data, note what was done and when. When evidence is being collected off of a stand alone home computer, the best way to do so while keeping it all in tact is to follow the following procedure. 1) Leave the computer off if it is off and photograph the scene and computer. If the screen is on photograph the screen as well. 2) Collect live data like RAM and network connections. 3) If the hard disk is encrypted collect a logical image, a clone. 4)Unplug the computer by removing the plug from the tower or removing the battery, label all cords, and document the device model numbers and serial numbers. 7) Take all storage media, keep everything away from magnets, and collect all instruction manuals and notes from the area. 8) Finally, show all the steps used when collecting the evidence. Examination of digital evidence should be done by professionals trained in digital forensics so as not to ruin anything. A useful piece of information is known as metadata. Metadata is basically data on data. It summarizes what the actual data has to say and it can be utilized to tell a lot about the actual data. Examples of this are the name and address of the user who created the data, the location of a file on a computer, or even the date and time stamp of the data. Many court rooms have their own digital evidence presentation rules which one must be abide by. It also should be remembered that the evidence must be admitted before being brought up while discussion is occurring. Court rooms that are set up for digital evidence usually include some sort of big flat screen and some individual monitors for the judge and others to look at the presentation. If the court room is not set up for digital evidence presentation, or even if it is, sometimes it can be good to hire a professional company to use the tools for the digital presentation so you do not have to worry about them. Resources: Works Cited
-Key component of police investigations and a potential source of evidence that could prove critical in supporting the prosecution of different types of crimes. Law enforcement agencies and departments are training more investigators to specialize in recognizing, handling, and deciphering the information on computers and digital devices. -Involves crimes such as terrorism, child pornography, violent crimes, theft or destruction of intellectual property, corporate crimes, Internet crimes, and financial fraud and embezzlement The most important step for a first-responder investigator is to determine how best to preserve that device and its data. -Recording and documenting the scene, including photographs of the mobile device in an undisturbed state should be included. Types of Digital Evidence Image acquired from google images -Computer Hard Drive
-Personal Digital Assistant
-Flash Card in Camera
-Mobile Phone
-Compact Disk
-GPS Device Image taken from google images -Evidence from mobile phones is becoming more and more important

-Usually related to drug investigations or child pornography

-Cell Phone Towers- help with tracking a person

-Terrorists used cell phones to detonate the bombs in the Madrid bombing that killed 190 in 2004 - For law enforcement officers to obtain evidence legally they must have probable cause and a warrant that allows for search and seizure. -Exporting information from several digital devices and importing it into the software-investigators can see a timeline of events

-Makes it easier for investigators to understand what happened

-Also, makes it easier for the jury to understand the criminal activity and any connections among offenders -Vital in computer and
internet crimes

Also includes:
-Facial Recognition
-Crime Scene Photos
-Surveillance Tapes FISWG- develop consensus standards, guidelines and best practices for the discipline of image-based comparisons of human features, primarily face Past Method-
-Confiscate computer, then create an exact duplicate- called an image
-Some data can not be recovered once the computer is shut down

Current Method-
-Collect as much data as possible at the scene, while the device is still on
-Evidence should not be changed in any way while it is being collected
-Only those with the specific training should examine the evidence
-Everything must be documented BTK Killer

-“Bind, Torture, Kill”
-Sent a message to police on a floppy disk
-Found a link to his first name “Dennis” and to the Lutheran Church he attended
-Police came across Dennis Rader
-DNA evidence was a close match to Rader’s daughter, so they knew the killer was related to her
-This was enough to make an arrest
-He plead guilty- sentenced to 10 consecutive life sentences. Eligible for parole in 2180. -Software and operating systems are rapidly changing and being updated
-Law enforcement has to constantly update their tools and training
-One example is the Cloud- Apple product
Create, share and store files on remote computers- this disguises the identity of the person
-There are many training courses that help to train investigators Training Data Mining Cell Phones -Evidence can change from moment to moment within a computer.
-Transmission lines can easily be altered
-Changes can be made during collection. -Many people can not read computer evidence because of the complexity of the systems
-Investigators usally need software to help mine the vast amounts of data that is stored on computers and other devices Problems One of the most problematic part of the whole process is linking specific individual to documents and logs found. Linking the Data Conclusion Practical investigations tend to rely on multiple streams of evidence which corroborate each other
- each stream may have its weaknesses, but taken together may point to a single conclusion THE END
Full transcript