0% found this document useful (0 votes)
5 views30 pages

DFS Unit2

The document outlines various digital forensic investigation models, including the DFRWS, ADFM, IDIP, EEDIP, and UMDFPM, each providing structured frameworks for handling digital evidence. It discusses the phases involved in these models, emphasizing the importance of legal and ethical considerations in maintaining evidence integrity and admissibility in court. Additionally, it highlights challenges faced in digital forensics, such as encryption, data volume, anti-forensics techniques, and the impact of emerging technologies.

Uploaded by

jhrrrs760
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views30 pages

DFS Unit2

The document outlines various digital forensic investigation models, including the DFRWS, ADFM, IDIP, EEDIP, and UMDFPM, each providing structured frameworks for handling digital evidence. It discusses the phases involved in these models, emphasizing the importance of legal and ethical considerations in maintaining evidence integrity and admissibility in court. Additionally, it highlights challenges faced in digital forensics, such as encryption, data volume, anti-forensics techniques, and the impact of emerging technologies.

Uploaded by

jhrrrs760
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

UNIT – II

DIGITAL FORENSIC
INVESTIGATION MODELS
Introduction to Digital Forensic Investigation
Models
A Digital Forensic Investigation Model is a systematic framework that guides investigators in
identifying, collecting, preserving, analyzing, and presenting digital evidence in a legally
acceptable manner.

► These models ensure that:

► Evidence remains authentic and unaltered

► Investigation follows legal and ethical rules

► Findings are admissible in court

► Investigation is repeatable and verifiable


2.1 Models of Digital Forensic
Investigation
1. DFRWS Investigative Model:

The DFRWS (Digital Forensic Research Workshop) model is one of the first and
most widely accepted digital forensic models. It focuses on proper handling of digital
evidence throughout the investigation.
Phases of DFRWS Model
1. Identification
► Identifying potential sources of digital evidence
► Examples:
► Hard disks
► Mobile phones
► Servers
► Network logs
► Objective: Recognize where evidence exists
2. Preservation
► Protecting evidence from:
A bit-by-bit forensic image is an exact replica of a digital
► Modification storage device where every single bit of data is copied,
► Deletion
► Damage
A blocker allows investigators to read data but not write or
► Actions include:
change anything on the device.
► Creating bit-by-bit forensic images
► Using write blockers
► Maintains chain of custody
3. Collection
► Acquiring evidence in a forensically sound manner
► Uses:
► Forensic tools
► Standard acquisition methods
► Ensures original evidence remains intact
4. Examination
► Extracting relevant information
► Activities:
► File recovery
► Keyword search
► Metadata extraction
► Intent of the suspect
5. Analysis
► Interpreting extracted data
► Establishes:
► Timeline of events
► User activities
[Link]
► Present findings in court-acceptable format
► Clear reports and expert testimony
Advantages
► Simple and structured
► Foundation model for later frameworks
Limitations
► Does not consider legal procedures deeply
► Less focus on decision-making
Abstract Digital forensic model
► Abstract Digital forensic model which is abbreviated as ADFM is a tool for digital forensic investigation. This
model provides a clear and structured and structured way to proceed with particular evidence. It contains 9 phases
which are Identification, Preservation, Collection, Examination, Analysis, Reconstruction, Documentation,
Presentation, and Returning Evidence. Because of these phases, investigators can increase the likelihood of
successfully identifying and prosecuting crimes.
Phases of Abstract Digital Forensic Model
► Identification- In this phase Identification of evidence takes place. Here evidence can be a computer, server,
mobile, cloud service, etc.
► Preservation- Maintenance of integrity and security of evidence is performed in this phase.
► Collection- Recording the evidence and making a duplicate copy of the main evidence.
► Examination- Identification of relevant information and finding more related hints from this information.
► Analysis- Linking of data and recovering and identifying the damaged and deleted files.
► Reconstruction- In this phase, a model of the evidence or a situation when the evidence was found is
constructed.
► Documentation- The result or the information found from the above phases is combined together in a form of
a document which helps in legal proceedings.
► Presentation- The investigator plays the role of a presenter and provides graphs, reports, and visual aids for
the further investigation process.
► Returning evidence- After a complete examination, the evidence which is used for investigation is returned to
the original owner of the evidence.
Integrated Digital Investigation Process (IDIP)
IDIP is a structured model that integrates physical crime scene investigation with digital forensic investigation.
It ensures that both physical and digital evidence are handled together.

Phases of IDIP

1. Readiness Phase

► Preparation before any incident occurs

► Ensure trained staff, tools, policies, and legal permissions

► Objective: Be ready for investigation

2. Deployment Phase

► Detection of an incident

► Confirmation that a digital crime has occurred

► Authorization to start investigation


3. Physical Crime Scene Investigation
► Secure physical locations (rooms, offices, devices)
► Identify computers, mobiles, storage devices
► Prevent tampering of evidence
[Link] Crime Scene Investigation
► Identify digital evidence (logs, files, emails, network data)
► Collect and preserve digital evidence
► Maintain chain of custody
5. Review Phase
► Analyze collected evidence
► Re-evaluate investigation steps
► Improve future readiness
End-to-End Digital Investigation Process (EEDIP)
EEDIP focuses on handling a digital crime from beginning to end, ensuring continuity and completeness.
Phases of EEDIP
1. Preparation
► Policies, tools, forensic readiness
► Training of investigators
2. Detection & Identification
► Identify suspicious activities
► Detect cybercrime incidents
3. Acquisition
► Collect digital evidence
► Use forensic tools to create bit-by-bit copies
4. Preservation
► Protect evidence from alteration
► Hashing and secure storage
5. Examination
► Recover deleted files
► Extract hidden or encrypted data
6. Analysis
► Correlate evidence
► Reconstruct timeline of events
7. Presentation
► Prepare forensic report
► Present findings in court
8. Closure
► Case closure
► Lessons learned
Extended Model for Cybercrime
Investigation
This model improves earlier forensic models by adding feedback loops, decision points, and parallel
investigations.
Main Stages
1. Awareness & Readiness
► Organization prepares for cyber threats
► Policies, tools, incident response plans
2. Detection
► Identify cybercrime using IDS, logs, alerts
3. Authorization
► Legal approval to start investigation
4. Collection
► Collect volatile and non-volatile data
► RAM, logs, network traffic, disks
5. Preservation
► Maintain integrity using hashing
► Secure storage
6. Examination
► Extract relevant digital artifacts
7. Analysis
► Link attacker actions to evidence
► Identify motive, method, and attacker
8. Documentation
► Maintain detailed investigation records
► 9. Presentation
► Evidence presentation in legal proceedings
► 10. Review
► Improve security and forensic process
UML Modeling of Digital Forensic Process
Model (UMDFPM)
UMDFPM uses UML diagrams to visually represent the digital forensic investigation process.
► Clear visualization of forensic workflow
UML:Unified Modeling Language
► Improves understanding and communication
► Useful for training and tool development
UML Diagrams Used
► 1. Use Case Diagram
► Shows interaction between:
► Investigator
► System
► Evidence
► Example actions: Collect Evidence, Analyze Data, Generate Report
[Link] Diagram
► Step-by-step forensic workflow
► Shows sequence, decision points, parallel actions
3. Sequence Diagram
► Order of interactions over time
► Shows how tools and investigators communicate
4. Class Diagram
► Represents forensic objects:
► Evidence
► Case
► Investigator
► Tools
Difference Between Models of Digital Forensic Investigation

Paramet DFRWS Extended Cybercrime


ADFM IDIP EEDIP UMDFPM
er Investigative Model Model

Full Digital Forensic Abstract Digital Integrated Digital End-to-End Digital Extended Model for UML Digital Forensic
Form Research Workshop Forensic Model Investigation Process Investigation Process Cybercrime Investigation Process Model

Basic forensic Abstract and


Main Integration of physical Complete lifecycle Handling complex Visual modeling of
investigation generalized forensic
Focus & digital crime scenes investigation cybercrimes forensic process
framework process

Type of UML-based graphical


Linear Abstract & structured Integrated & phased End-to-end lifecycle Flexible & feedback-based
Model model

Physical
Crime Not emphasized Not included Included Not included Included where required Represented visually
Scene
Digital Crime Scene Included Included Included Included Included Included via diagrams

Pre-Incident Readiness No No Yes Yes Yes Depends on design

Feedback / Review Loop No No Yes Limited Strong feedback loop Yes (via diagrams)

Flexibility Low Medium Medium Medium High High

Visualization Support No No No No Limited Strong (UML diagrams)

Complex Cybercrime
Limited Limited Moderate Moderate Excellent Good
Support

Legal Suitability Good Good Very strong Strong Very strong Strong

Common Diagrams Flow-based Conceptual Process flow Process flow Flow + decision points Use case, Activity, Sequence

Academic
Best Used For Basic forensic cases Real-world investigations Full investigation lifecycle Advanced cybercrime cases Training & system design
understanding
❖ Challenges in Digital Forensics
Digital forensics faces many challenges due to rapid technological
advancements and increasing cybercrimes. The major challenges are
explained below:
1. Encryption
► Encryption converts data into unreadable format to protect confidentiality.
► Used in disk encryption, file encryption, messaging apps, and cloud storage.
► Challenges
► Investigators cannot access encrypted data without keys.
► Strong encryption algorithms are difficult to break.
► Password-protected devices delay investigations.
► 2. Volume of Data
► Large amount of data stored in computers, mobiles, servers, and cloud.
► Includes emails, logs, videos, images, social media data.
► Challenges
► Analysis becomes slow and complex.
► Requires high storage capacity and powerful tools.
► Difficulty in identifying relevant evidence from massive data.
3. Anti-Forensics Techniques
Techniques used by criminals to hide, destroy, or manipulate digital evidence.
Examples
► Data wiping and secure deletion
► File encryption and steganography
► Log tampering
► Use of VPN, proxy, and TOR network
Challenges
► Evidence may be altered or destroyed.
► Makes reconstruction of events difficult.
4. Legal and Ethical Issues
Digital evidence must follow legal procedures and privacy laws.
► Challenges
► Jurisdiction issues in cloud and cross-border crimes.
► Privacy concerns while accessing personal data.
► Need for proper warrants and authorization.
► Admissibility of evidence in court.
► Impact
► Improper handling can make evidence invalid.
► Ethical violations may lead to legal consequences.
5. Emerging Technologies
Description
► New technologies like IoT, Cloud Computing, AI, Blockchain, and Metaverse.
► Challenges
► Lack of standardized forensic tools.
► Difficulty in evidence collection from distributed systems.
► Rapid evolution of technology outpaces forensic methods.
► Impact
► Investigators require continuous training.
► Existing forensic models may become outdated.
2.3 Legal and Ethical Considerations in Digital Forensics
Digital forensic investigations must follow legal rules and ethical standards to ensure
that evidence is valid, reliable, and admissible in court.

1. Integrity
► Investigators must be honest and truthful.
► No alteration, fabrication, or suppression of evidence.
2. Confidentiality
► Protect sensitive and private information.
► Share evidence only with authorized persons.
3. Objectivity and Impartiality
► Avoid bias or personal opinions.
► Base conclusions only on factual evidence.
4. Competence
► Use updated forensic tools and techniques.
► Maintain proper training and professional skills.
5. Proper Authorization
► Conduct investigations only with legal permission (warrant, court order).
► Respect jurisdictional laws.
6. Chain of Custody
► Maintain detailed records of evidence handling.
► Ensure evidence integrity from collection to presentation.
7. Respect for Privacy
► Examine only relevant data.
► Avoid unnecessary intrusion into personal information.
8. Documentation
► Keep accurate logs, notes, and reports.
► Ensure transparency and accountability.
B. Unethical Norms in Digital Forensic Investigation
Unethical norms are improper practices that violate legal and professional standards.

► 1. Evidence Tampering
► Altering, deleting, or planting digital evidence.
► 2. Unauthorized Access
► Accessing systems or data without legal approval.
► 3. Violation of Privacy
► Examining irrelevant personal files or data.
► 4. Bias and Misrepresentation
► Manipulating findings to favor one party.
► Giving false or misleading reports.
5. Poor Chain of Custody
► Incomplete documentation.
► Mishandling evidence.
6. Incompetent Investigation
► Using unverified tools.
► Lack of proper skills or training.
7. Conflict of Interest
► Investigating cases where personal interest exists.
Difference Between Ethical and Unethical Norms

Ethical Norms Unethical Norms

Follow laws and procedures Violate legal requirements

Maintain confidentiality Leak sensitive information

Preserve evidence integrity Tamper with evidence

Remain unbiased Show favoritism or bias

Respect privacy Invade privacy unnecessarily

You might also like