0% found this document useful (0 votes)
6 views37 pages

Chapter 1

Computer forensics involves the use of analytical techniques to identify, collect, and preserve digital evidence for legal purposes. It requires knowledge of computer systems, networks, and legal standards, including the Daubert Standard for expert testimony. The field is rapidly evolving, with various stakeholders including military, government, and corporations utilizing forensic methods to investigate digital crimes.

Uploaded by

babycrayons1
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views37 pages

Chapter 1

Computer forensics involves the use of analytical techniques to identify, collect, and preserve digital evidence for legal purposes. It requires knowledge of computer systems, networks, and legal standards, including the Daubert Standard for expert testimony. The field is rapidly evolving, with various stakeholders including military, government, and corporations utilizing forensic methods to investigate digital crimes.

Uploaded by

babycrayons1
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link].

com
PROF. GEORGE LILUASHVILI
FORENSICS
INF-270
DIGITAL
WHAT IS COMPUTER FORENSICS?

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
The use of analytical and investigative techniques to identify, collect, examine, and
preserve evidence/information that is magnetically stored or encoded

Objective is to recover, analyze, and present computer-based material in such a


way that it can be used as evidence in a court of law

Applies to all the domains of a typical IT infrastructure: User Domain, Workstation


Domain, LAN Domain, LAN-to-WAN Domain, WAN Domain, Remote Access
Domain, System/Application Domain
WHAT IS COMPUTER FORENSICS? (CONT.)
The seven domains of a typical IT infrastructure.

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
User domain, Workstation domain, LAN domain, LAN-to-WAN
domain, Remote access domain, WAN domain, and
system/application domain
USING SCIENTIFIC KNOWLEDGE

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• Important to understand and apply scientific methods and processes and have knowledge of
the relevant scientific disciplines, including scientific knowledge of the field
• Requires a thorough understanding of:
• Computer hardware
• Operating system running on that device
• May include smartphones and routers
• At least the basics of computer networks
• Stay up-to-date
• Keep learning what is there, where it is stored, and how that information may be used by computer user
and computer criminal alike
USING SCIENTIFIC KNOWLEDGE (CONT.)

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• How you collect evidence determines if that
Collecting evidence is admissible in a court

• Putting together the data you have and


Analyzing finding out what sort of picture is revealed

• The expert report


Presenting
• Expert testimony
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
[Link]
The steps of a digital investigation
EXPERT REPORT

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Support every
conclusion with at
Formal document least two to three
that lists what reputable Must be very
Includes your
tests you references that thorough,
curriculum vitae
conducted, what either agree with complete, and
(CV)
you found, and that conclusion or error free
your conclusions provide support
for how you came
to that conclusion
EXPERT TESTIMONY

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Deposition—testimony taken from a witness or party to a case
before a trial: Less formal and is typically held in an attorney’s
office

Sworn testimony—lying under oath is perjury, which is a felony

U.S. Federal Rule 702 defines what an expert is and what expert
testimony is
EXPERT TESTIMONY

Other U.S. Federal Rules related to expert witness testimony at

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
trial:

• Rule 703: Bases of an expert – Expert may base opinion on facts


• Rule 704: Opinion on ultimate issue – Expert may offer opinion
• Rule 705: Disclosing the facts or data underlying an expert – Expert
can provide reasons for their opinion
• Rule 706: Court-appointed expert witness – The appointment of
neutral experts
• Rule 401: Test for relevant evidence – Evidence is relevant if 1) it
has any tendency to make fact more or less probable 2) the fact is
consequence in determining the action
UNDERSTANDING THE FIELD OF DIGITAL FORENSICS

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• Field is changing very rapidly: Emerging standards provide clear, codified methods for conducting a forensic examination
• Entities involved in and actively using computer forensics:
• The military
• Government agencies
• Law firms
• Criminal prosecutors
• Academia
• Data recovery firms
• Corporations
• Insurance companies
• Individuals
WHAT IS DIGITAL EVIDENCE?

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• Information that has been processed and assembled so that it is relevant to an
investigation and supports a specific finding or determination
• Raw information is not, in and of itself, evidence
• Data must be relevant to a case in order to be evidence
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• [Link]
MURDER: DIGITAL EVIDENCE
TYPES OF EVIDENCE

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Real – Physical object (USB drive, CD & DVD , Tablet , Laptop)

Documentary – Data stored in written matter, on paper or digital

Testimonial – Forensic specialists' interpretation or documentary

Demonstrative –Type of evidence that help explain other evidence


SCOPE-RELATED CHALLENGES TO SYSTEM
FORENSICS

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Volume of data to be analyzed

Complexity of the computer system

Size and character of the crime scene

Size of the caseload and resource limitations


TYPES OF DIGITAL SYSTEM FORENSICS ANALYSIS

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Physical storage
Email Network Internet
media

Cell phone/
Software Live system
mobile
GENERAL GUIDELINES

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Maintain chain of custody

Do not touch suspect drive

Create a document trail

Secure evidence
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
KNOWLEDGE NEEDED FOR COMPUTER FORENSIC

• Addresses
• Hardware

• Networks
• Software
ANALYSIS
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Hard drives/storage devices
Memory
COMPUTER HARDWARE
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
SOFTWARE: OPERATING SYSTEMS

Linux/Android
Windows

Mac OS
FILES AND FILE SYSTEMS
• Files

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• Any document, spreadsheet,
picture, video, or program
• File systems
• Physical journaling
• Logical journaling
NETWORKING: ADDRESSING
• Physical ports

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• MAC address
• IP address
• IPv4 example: [Link]
• Logical port numbers
• Uniform resource locator (URL)
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
NETWORK UTILITIES: IPCONFIG

• ipconfig
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
NETWORK UTILITIES: PING

• ping
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
NETWORK UTILITIES: TRACERT

• tracert
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
OBSCURED INFORMATION AND ANTI-FORENSICS
THE DAUBERT STANDARD

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• Legal precedent set in the 1993 Supreme Court case of Daubert v. Merrill Dow
Pharmaceuticals [509 U.S. 579 (1993)]
• Regards the admissibility of expert witnesses’ testimony during legal
proceedings
• Any scientific evidence presented in a trial must have been reviewed and
tested by the relevant scientific community
THE DAUBERT STANDARD (CONT.)

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Empirical testing

Peer review

Error rate and standards

Generally accepted theory/technique


U.S. LAWS AFFECTING DIGITAL FORENSICS
• The Federal Privacy Act of 1974

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• The Privacy Protection Act of 1980 (PPA)
• The Communications Assistance to Law Enforcement
Act of 1994
• Unlawful Access to Stored Communications: 18
U.S.C. § 2701
• The Electronic Communications Privacy Act of 1986
• The Computer Security Act of 1987
• The Foreign Intelligence Surveillance Act of 1978
U.S. LAWS AFFECTING DIGITAL FORENSICS (CONT.)
• The Child Protection and Sexual Predator

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Punishment Act of 1998
• The Children’s Online Privacy Protection Act of
1998
• The Communications Decency Act of 1996
• The Telecommunications Act of 1996
• The Wireless Communications and Public Safety
Act of 1999
• The USA PATRIOT Act
• The Sarbanes-Oxley Act of 2002
U.S. LAWS AFFECTING DIGITAL FORENSICS (CONT.)
• 18 USC 1030 Fraud and Related Activity in

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Connection with Computers
• 18 USC 1020 Fraud and Related Activity in
Connection with Access Devices
• The Digital Millennium Copyright Act (DMCA)
• 18 USC § 1028A Identity Theft and Aggravated
Identity Theft
• 18 USC § 2251 Sexual Exploitation of Children
• Warrants
CALEA AND FISA

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
The Communications Assistance for Law The Foreign Intelligence Surveillance Act of
Enforcement Act of 1994 1978
• A federal wiretap law for traditional wired • A law that allows for the collection of
telephony “foreign intelligence information” between
foreign powers and agents of foreign
• Was expanded to include wireless, Voice
powers using physical and electronic
over Internet Protocol (VoIP), and other
surveillance
forms of electronic communications
• Including signaling traffic and metadata • Foreign Intelligence Surveillance Act (FISA)
court issues a warrant for actions under FISA
CHILD PROTECTION AND WIRELESS ACTS

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
The Child Protection and Sexual The Wireless Communications and
Predator Punishment Act of 1998 Public Safety Act of 1999
• Requires service providers that • Allows for the collection and use of
become aware of the storage or “empty” communications
transmission of child pornography to • Nonverbal and nontext
report it to law enforcement communications, such as GPS
information
THE USA PATRIOT ACT OF 2001

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• The primary law under which a wide variety of internet and communications
information content and metadata is currently collected
• Provisions exist within the PATRIOT Act to protect identity and privacy of U.S.
citizens
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Fourth Amendment
and reasonable
expectation of
Warrants

privacy
Search and seizure
WARRANTS
FEDERAL GUIDELINES

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
• FBI computer forensics guidelines
• Secret Service guidelines
• Regional Computer Forensics Laboratory (RCFL) Program
MURDER: DIGITAL EVIDENCE

Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
Gruesome Murder Case Solved by REVOLUTIONARY
Forensic Tool | Witness to Murder: Digital Evidence
Copyright © 2022 by Jones & Bartlett Learning, LLC an Ascend Learning Company. [Link]
SUPPLEMENTARY READING

[Link]

You might also like