0% found this document useful (0 votes)
6 views35 pages

Chapter 5

Chapter 5 of the document discusses the field of computer forensics, which involves the investigation of computer-based crimes and the collection of digital evidence. It outlines the methodologies used in computer forensics, including preservation, identification, extraction, interpretation, and documentation, as well as the importance of maintaining a chain of custody. The chapter also highlights the challenges faced in digital forensics, including technical and legal issues.

Uploaded by

Abdirizak Abokar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views35 pages

Chapter 5

Chapter 5 of the document discusses the field of computer forensics, which involves the investigation of computer-based crimes and the collection of digital evidence. It outlines the methodologies used in computer forensics, including preservation, identification, extraction, interpretation, and documentation, as well as the importance of maintaining a chain of custody. The chapter also highlights the challenges faced in digital forensics, including technical and legal issues.

Uploaded by

Abdirizak Abokar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Understanding

Computer Forensics
Chapter 5
Agenda
❑ Introduction
❑ Digital forensics science
❑ Role of digital forensics
❑ Methods for computer forensics
❑ Cyberforensics and digital evidence
Introduction
▪ The application of computer for investigating computer-
based crime has led to development of new field called
computer forensics. Sometimes, computer forensics is also
referred to as “digital forensics”.
▪ Cyber forensics plays a key role in investigation of
cybercrime.
Introduction
▪ Evidence in the case of “Cyber offence” is extremely
important from a legal perspective.
▪ Often, computer forensics is used to uncover evidence
that could be used in a court of law.
Introduction

▪ Computer forensics is a field of technology that


uses investigative techniques to identify and store
of a digital evidence from a computer device.
Historical Background
of Cyberforensics
Historical Background…

▪ Computer is either the subject or the object of


cybercrimes or is used as a tool to commit a cybercrime.
▪ The earliest recorded computer crimes occurred in 1969
and 1970 when students protesters burned computers
at various universities.
Historical Background…

▪ Around at the same time, people were discovering


methods for gaining unauthorized accesses to the
computer systems.
▪ Computer intrusion and fraud committed with the help
of computers were the first crimes to be widely
recognized a new type of a crime.
Historical Background…
▪ Computer forensics is primarily concerned with the
systematic “identification,” “acquisition,” “preservation,” and
“analysis” of digital evidence, typically after unauthorized
access to computer or unauthorized use of computer has
taken place; while the main focus of “computer security” is
the prevention of unauthorized access to computer systems
as well as maintaining “ confidentiality,” “integrity,” and
“availability” of computer system.
Historical Background…
▪ There are two categories of computer crime: one is
the criminal activity that involves using a computer to commit
a crime , and the other is a criminal activity that has a
computer as a target.
▪ Forensics means a “characteristic of evidence” that satisfies
its suitability for admission as fact and its ability to persuade
based upon proof(or high statistical confidence level).
Digital Forensics Science
Digital Forensics Science
▪ Digital forensics is the application of analyses techniques to
the reliable and unbiased collection, analysis, interpretation,
and presentation of digital evidence.

▪ The objective of “Cyberforensics” is to provide digital


evidence of specific or general activity.
Role of digital forensics
Role of digital forensics
1. Uncover and document evidence and leads.
2. Corroborate evidence discovered in other ways.
3. Assist in showing a pattern of events.
4. Connect attack and victim computers.
5. Reveal an end-to-end path of events leading to compromise
attempt, successful or not.
6. Extract data that may be hidden, deleted or otherwise to directly
available.
Computer Forensic
Methodologies
Computer Forensic Methodologies

Computer forensic methodologies consist of the following basic


activities:

Preservation Identification Extraction Interpretation Documentation


Computer Forensic Methodologies

Preservation: The forensic investigator must preserve the integrity of the


original evidence. The original evidence should not be modified or damaged.

• The forensic examiner must make an image or a copy of the original


evidence and then perform the analysis on that image or copy.
Computer Forensic Methodologies

▪ Identification: Before starting the investigation, the forensic


examiner must identify the evidence and its location.
▪ Extraction: After identifying the evidence, the examiner must
extract data from it. The extracted data must be compared
with the original evidence and analyzed.
Computer Forensic Methodologies

Interpretation: The most important role a forensic examiner plays during


investigations is to interpret what he or she has actually found.

• The analysis and inspection of the evidence must be interpreted in a lucid


manner.
Computer Forensic Methodologies

Documentation: From the beginning of the investigation until the end (when
the evidence is presented before a court of law), forensic examiners must
maintain documentation relating to the evidence.

▪ The documentation comprises the chain of custody form and documents


relating to the evidence analysis.
The need for computer
forensics
Typical scenarios involved
1. Employee internet abuse.
2. Data leak/data break. (accidental or intentional)
3. Industrial espionage. (corporate “spying” activities)
4. Damage assessment. (following an incident)
5. Criminal fraud and deception cases.
6. Criminal cases.
7. Copyright violation
Cyber-forensics Domains
Cyber-forensics Domains

Cyber forensics can be divided into two domains:

1. Computer forensics
2. Network forensics.
Cyber-forensics Domains
▪ Many security threats are possible through computer
networks. Therefore, “Network forensics” assumes
importance in the context of cybercrime.
▪ Network forensics is the study of network traffic to
search for truth in civil, criminal and administrative matters to
protect users and resources from exploitation, invasion of
privacy and any other crime fostered by the continual
expansion of network connectivity.
Cont.
As compared to the “physical” evidence, “digital evidence” is
different in nature because it has some unique characteristics.

▪ First of all, digital evidence is much easier to


change/manipulate!
▪ Second, “perfect” digital copies can be made without harming
original.
Chain of custody
Chain of Custody
• The chain of custody is a written description created by
individuals who are responsible for the evidence from the
beginning until the end of the case.

• The chain of custody form is easy to use.


Chain of Custody
▪ Chain of custody means the chronological documentation trail,
etc. That indicates the seizure, custody, control, transfer,
analysis and disposition of evidence, physical or electronic.

▪ The basic idea behind ensuring “chain of custody” is to ensure


that the “evidence” is NOT tampered with.
Chain of Custody Documentation
A chain of custody document contains the followings:
❑ Case number
❑ Name, title, address, and telephone number of the person from
whom the evidence was received
❑ Location where obtained
❑ Reason for evidence being obtained
❑ Date/time evidence was obtained
❑ Name of the evidence, etc.
Challenges in Computer Forensics
Challenges …

▪ Technical Challenges: Understanding the Raw Data and its


Structure
▪ The Legal Challenges in Computer Forensics and Data
Privacy Issues
Challenges …

▪ There are two aspects of the technical challenges faced in


digital forensics investigation one is the "complexity"
problem and the other is the "quantity" problem involved
in a digital forensics investigation
Challenges …| The Legal Challenges…

▪ There are many types of personnel involved in digital


forensics/computer forensics:
a. Technicians,
b. Policy makers and
c. professionals
END

You might also like