Understanding
Computer Forensics
Chapter 5
Agenda
❑ Introduction
❑ Digital forensics science
❑ Role of digital forensics
❑ Methods for computer forensics
❑ Cyberforensics and digital evidence
Introduction
▪ The application of computer for investigating computer-
based crime has led to development of new field called
computer forensics. Sometimes, computer forensics is also
referred to as “digital forensics”.
▪ Cyber forensics plays a key role in investigation of
cybercrime.
Introduction
▪ Evidence in the case of “Cyber offence” is extremely
important from a legal perspective.
▪ Often, computer forensics is used to uncover evidence
that could be used in a court of law.
Introduction
▪ Computer forensics is a field of technology that
uses investigative techniques to identify and store
of a digital evidence from a computer device.
Historical Background
of Cyberforensics
Historical Background…
▪ Computer is either the subject or the object of
cybercrimes or is used as a tool to commit a cybercrime.
▪ The earliest recorded computer crimes occurred in 1969
and 1970 when students protesters burned computers
at various universities.
Historical Background…
▪ Around at the same time, people were discovering
methods for gaining unauthorized accesses to the
computer systems.
▪ Computer intrusion and fraud committed with the help
of computers were the first crimes to be widely
recognized a new type of a crime.
Historical Background…
▪ Computer forensics is primarily concerned with the
systematic “identification,” “acquisition,” “preservation,” and
“analysis” of digital evidence, typically after unauthorized
access to computer or unauthorized use of computer has
taken place; while the main focus of “computer security” is
the prevention of unauthorized access to computer systems
as well as maintaining “ confidentiality,” “integrity,” and
“availability” of computer system.
Historical Background…
▪ There are two categories of computer crime: one is
the criminal activity that involves using a computer to commit
a crime , and the other is a criminal activity that has a
computer as a target.
▪ Forensics means a “characteristic of evidence” that satisfies
its suitability for admission as fact and its ability to persuade
based upon proof(or high statistical confidence level).
Digital Forensics Science
Digital Forensics Science
▪ Digital forensics is the application of analyses techniques to
the reliable and unbiased collection, analysis, interpretation,
and presentation of digital evidence.
▪ The objective of “Cyberforensics” is to provide digital
evidence of specific or general activity.
Role of digital forensics
Role of digital forensics
1. Uncover and document evidence and leads.
2. Corroborate evidence discovered in other ways.
3. Assist in showing a pattern of events.
4. Connect attack and victim computers.
5. Reveal an end-to-end path of events leading to compromise
attempt, successful or not.
6. Extract data that may be hidden, deleted or otherwise to directly
available.
Computer Forensic
Methodologies
Computer Forensic Methodologies
Computer forensic methodologies consist of the following basic
activities:
Preservation Identification Extraction Interpretation Documentation
Computer Forensic Methodologies
Preservation: The forensic investigator must preserve the integrity of the
original evidence. The original evidence should not be modified or damaged.
• The forensic examiner must make an image or a copy of the original
evidence and then perform the analysis on that image or copy.
Computer Forensic Methodologies
▪ Identification: Before starting the investigation, the forensic
examiner must identify the evidence and its location.
▪ Extraction: After identifying the evidence, the examiner must
extract data from it. The extracted data must be compared
with the original evidence and analyzed.
Computer Forensic Methodologies
Interpretation: The most important role a forensic examiner plays during
investigations is to interpret what he or she has actually found.
• The analysis and inspection of the evidence must be interpreted in a lucid
manner.
Computer Forensic Methodologies
Documentation: From the beginning of the investigation until the end (when
the evidence is presented before a court of law), forensic examiners must
maintain documentation relating to the evidence.
▪ The documentation comprises the chain of custody form and documents
relating to the evidence analysis.
The need for computer
forensics
Typical scenarios involved
1. Employee internet abuse.
2. Data leak/data break. (accidental or intentional)
3. Industrial espionage. (corporate “spying” activities)
4. Damage assessment. (following an incident)
5. Criminal fraud and deception cases.
6. Criminal cases.
7. Copyright violation
Cyber-forensics Domains
Cyber-forensics Domains
Cyber forensics can be divided into two domains:
1. Computer forensics
2. Network forensics.
Cyber-forensics Domains
▪ Many security threats are possible through computer
networks. Therefore, “Network forensics” assumes
importance in the context of cybercrime.
▪ Network forensics is the study of network traffic to
search for truth in civil, criminal and administrative matters to
protect users and resources from exploitation, invasion of
privacy and any other crime fostered by the continual
expansion of network connectivity.
Cont.
As compared to the “physical” evidence, “digital evidence” is
different in nature because it has some unique characteristics.
▪ First of all, digital evidence is much easier to
change/manipulate!
▪ Second, “perfect” digital copies can be made without harming
original.
Chain of custody
Chain of Custody
• The chain of custody is a written description created by
individuals who are responsible for the evidence from the
beginning until the end of the case.
• The chain of custody form is easy to use.
Chain of Custody
▪ Chain of custody means the chronological documentation trail,
etc. That indicates the seizure, custody, control, transfer,
analysis and disposition of evidence, physical or electronic.
▪ The basic idea behind ensuring “chain of custody” is to ensure
that the “evidence” is NOT tampered with.
Chain of Custody Documentation
A chain of custody document contains the followings:
❑ Case number
❑ Name, title, address, and telephone number of the person from
whom the evidence was received
❑ Location where obtained
❑ Reason for evidence being obtained
❑ Date/time evidence was obtained
❑ Name of the evidence, etc.
Challenges in Computer Forensics
Challenges …
▪ Technical Challenges: Understanding the Raw Data and its
Structure
▪ The Legal Challenges in Computer Forensics and Data
Privacy Issues
Challenges …
▪ There are two aspects of the technical challenges faced in
digital forensics investigation one is the "complexity"
problem and the other is the "quantity" problem involved
in a digital forensics investigation
Challenges …| The Legal Challenges…
▪ There are many types of personnel involved in digital
forensics/computer forensics:
a. Technicians,
b. Policy makers and
c. professionals
END