0% found this document useful (0 votes)
5 views13 pages

Multimedia

Multimedia Forensics is a specialized field focused on the collection, analysis, and authentication of multimedia evidence for legal purposes. The increasing prevalence of multimedia devices, the ease of digital forgery, the rise of deepfakes, and the critical role of multimedia in criminal investigations highlight the growing need for this discipline. Key processes include maintaining a chain of custody, employing various forensic tools, and understanding legal standards for evidence admissibility.

Uploaded by

ndlovunigel771
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
5 views13 pages

Multimedia

Multimedia Forensics is a specialized field focused on the collection, analysis, and authentication of multimedia evidence for legal purposes. The increasing prevalence of multimedia devices, the ease of digital forgery, the rise of deepfakes, and the critical role of multimedia in criminal investigations highlight the growing need for this discipline. Key processes include maintaining a chain of custody, employing various forensic tools, and understanding legal standards for evidence admissibility.

Uploaded by

ndlovunigel771
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
UNIT 1 Multimedia Forensics Multimedia Forensics is a branch of forensics science concerned with the scientific collection, examination, analysis, and authentication of multimedia evidence (images, audio, and video) in a forensically sound manner to be presented in a court of law. 1.1 The "Need" for Multimedia Forensics arises from several modern realities: 1. Ubiquity of Multimedia Devices: Smartphones, CCTV cameras, drones, and body-cams generate vast amounts of potential evidence for both criminal and civil 2. Rise of Digital Forgery: The availability of powerful and user-friendly editing software (¢.g., Adobe Photoshop, Audacity, Adobe Premiere) has made it trivial to manipulate or fabricate multimedia content. This necessitates methods to verify authenticity and integrity 3. Deepfakes and Synthetic Media: Al-driven technologies can create highly realistic but entirely fake videos and audio (deepfakes), which can be used for misinformation, blackmail, fraud, and political destabilization. Forensic analysis is crucial to detect these. 4. Criminal Investigations: Multimedia files are often primary evidence in cases like: 1. Terrorism: Analyzing propaganda videos, communication intercepts. 2. Child Exploitation: Identifying victims, perpetrators, and locations from images and videos. 3. Homicide/Assault: Using CCTV footage to reconstruct crime scenes and identify suspects. 4, Fraud: Authenticating disputed audio recordings of contracts or video evidencs 5. Civil Litigation: Proving or disproving claims in cases related to insurance fraud, copyright infringement, and marital disputes. 6. Copyright and Intellectual Property (IP) Protection: Identifying unauthorized use or distribution of copyrighted material through techniques like digital watermarking and steganography analysis 7. National Security: Verifying the authenticity of intelligence data, analyzing satellite imagery ete. Potential Exam Question: Explain the growing need for multimedia forensics in the modern digital age, citing at least four distinct reasons with examples Answer Guideline: Start with the definition. Then, detail the points above: 1) Proliferation of recording devices (CCTV, smartphones). 2) Ease of forgery with software, 3) Emergence of Al-based fakes (Deepfakes). 4) Its central role in eriminal/civil fic example for each point (c.g., using CCTV in a robbery for point 4). cases. Provide a sp 1.2 Multimedia Tools and Their Applications - Multimedia tools in a forensic context can be broadly categorized. Primarily designed for content creation Adobe Photoshop, Adobe Understanding how a forgery e.g, image ‘and modification. Forensically, they are Premiere Pro, Final Cut Pro, splicing, audio clipping) could be created. studied to understand forgery ‘Audacity Replicatinga suspected manipulation to test a techniques, hypothesis. All-in-one software designed Amped FIVE, IMATest, Ocean The primary tool for an analyst. Used for ‘specifically for the forensic examination Systems dTective, Axon enhancement, authentication, analysis (e.8., ‘of multimedia. They integrate multiple Investigate (formerly PRNU, ELA), and generating a forensically analysis algorithms intoa single Cognitech) sound report. workflow. Tools used to examine the internal _ExifTool, Medialnfo, Extracting camera model, date/time, GPS structure and metadata of a file JPEGsnoop, Hex Editors (e.g., coordinates, software used for last save. without altering it HxD) Crucial for initial assessment and source identification. FILE FORMAT HISTORY. Ginieetrail Software used to recover deleted or PhotoRec, FTK Imager, Recovering deleted images from a camera's SD Tools corrupted multimedia files from digital EnCase Forensic card or video files from a formatted hard drive storage media. using file carving techniques. cores Software focused on the analysis and Prat, iZotope RX, SOUND Forensic voice analysis (speaker identification), Ealimucrey| enhancement of audio recordings. FORGE Audio Studio, Audacity enhancement of noisy recordings, detecting, edits in an audio. > A digital forgery or tampering is the intentional alteration of a multimedia file's content to mislead an observer. > The goal ofa forensic analyst is to detect thes ‘Types of Forgeries: A. Image Forgeries (Digital Image Tampering 1 : Combining parts of two or more different images to create a composite image, 1, Example: Adding a person who was not present into a group photograph 2. Detection Techniques: Inconsistencies in lighting (shadows, reflections), perspective mismatch, variations in noise patterns, shatp or unnatural edges, and specialized algorithms like DCT coefficient analysis, 2. Copy-Move (Cloning): Copying a part of an image and pasting it onto another area within the same image, often to conceal an object or duplicate an element. 1, Example: Hiding a weapon in a photo by copying a patch of the background wall and pasting it over the weapon 2. Detection Techniques: Algorithms that search for duplicated regions in the image, such as Block-based methods and Keypoint-based methods. 3. Retouching / Inpainting: Enhancing or diminishing certain features of an image. This isa less drastic form of manipulation. Example: Removing wrinkles from a face, airbrushing skin, or removing a small, unwanted object from the background, Detection Techniques: Can be very difficult to detect. Analysis of local noise patterns, blur inconsistencies, and looking for tell- tale signs of brushing or smudging tools B. Audio Forgeries 1. Splicing/Deletion: Inserting or removing segments of an audio recording. 1, Example: Deleting a “not” from the sentence "I will not pay you" to reverse its meaning. 2. Detection Techniques: Abrupt changes in background noise, discontinuities in the fundamental frequency (pitch), or unnatural silence, Examining the waveform and spectrogram can reveal these breaks, alterations, C. Video Forgeries 1. Inter-frame Tampering: Manipulating the relationship between frames. 1, Examples: Deleting frames to remove an event, inserting frames from another source, or duplicating frames to lengthen a pause. 2. Detection Techniques: Analysis of motion vectors between frames, temporal inconsistencies, and duplicated frame detection 2. Intra-frame Tampering: Manipulating the content within individual frames. This is essentially applying image forgery techniques (splicing, copy-move) to one or more frames of a video. 1, Example: Digitally removing a license plate number from every frame of a video showing a getaway car 2. Detection Techniques: Same as image forgery detection, but applied on a frame-by-frame basis, looking for consistency across the video sequence. 3. Deepfakes (Al-Synthesized Video): Using deep learning models (like Generative Adversarial Networks - GANS) to swap a person's face with another's or to generate realistic speech from text. 1. Example: Creating a fake video of a politician giving an ineriminating speech. 2. Detection Techniques: Looking for artifacts common in early deepfakes like unnatural blinking, lack of fine facial details (pores, hairs), inconsistent head-body physics, and artifacts in video compression. Modern detection relies on sophisticated AI ‘models trained to spot synthetic media, 1.4 Handling and Preservation of Multimedia Files (Chain of Custody) + The Chain of Custody is the chronological documentation or paper trail, showing the seizure, custody, control, transfer analysis, and disposition of evidence. + broken chain of custody can render evidence inadmissible in court. Forensically Sound Procedure: 1. Identification: Locate and identify all potential sources of multimedia evidence (e.g, DVR, smartphone, laptop, SD card), 2. Collection & Acqr 1, Principle: The primary rule is to never work on the original evidence, Always create a bit-for-bit copy (forensic image). 2, Hashing: A hash function (¢.g., SHA-256, MDS) generates a unique alphanumeric string (the "hash value" or "digital fingerprint") fora file. 1. Process: 1. Calculate the hash of the original evidence media/file. 2. Create a forensic image (e.g., using FTK Imager). 3. Calculate the hash of the newly created image. 4, Verify that the hash values of the original and the copy are identical. This mathematically proves the copy is aan exact duplicate, 3. Write-Blockers: Use a hardware or software write-blocker during acquisition to prevent any modification to the original evidence device. /[Link]/sha256-online-generator 3. Preservation: 1. Store the original evidence in a secure, anti-static bag in a locked evidence locker. 2. Store the forensic image(s) in ure digital location. Multiple copies are recommended. 3. All actions (acquisition, anal is) should be performed on the forensic image, not the original. 4. Analysis: Conduct the forensic examination on the verified forensic copy. 5, Documentation & Reporting: Meticulously document every step taken: who handled the evidence, when, what was done, and what the results were. This documenta jon forms the core of the chain of custody. Potential Exam Question: What is the "Chain of Custody" in the context of digital evidence? Describe the key steps involved in handling a CCTV DVR from a crime scene to ensure the evidence is admissible. Answer Guideline: Define Chain of Custody. Then list the steps: 1) Secure the scene and document the DVR in situ. 2) Power down correctly. 3) Use a write-blocker to connect the DVR's hard drive to a forensic workstation. 4) Calculate the SHA-256 hash of the original drive. 5) Create a bit-stream image (e.g., E01 format). 6) Calculate the hash of the image and verify it ‘matches the original. 7) Store the original drive securely. 8) Conduct all analysis on the verified copy. 9) Document every step in a case file 1.5 Legal Aspects of Digital Multimes lence 1. Admissibility: For evidence to be used in court, it must be admissible. Key criteria include: Relevance: The evidence must prove or disprove a fact in question, 2. Authen ‘The prosecution must prove the image/video is a true and accurate representation, 3. Not Unfairly Prejudi prejudice the jury. ts value in proving a fact must not be outweighed by its potential to inflame or 2. Authentication: This is the process of proving authenticity. It can be done through: 1. Witness Testimony: Someone who saw the event testifies that the video accurately depicts it. 2. Technical Authentication: A forensic expert testifies about the analysis performed to verify the file's integrity (eg., metadata analysis, hash value verification, forgery detection analysis) 3. Expert Witness: A multimedia forensic analyst may be called as an expert witness. Their role is to explain complex technical findings to the court in an understandable way. Their testimony is subject to standards like: 1. Daubert Standard: The exper’s methodology must be scientifically valid (testable, peer-reviewed, known error rate, and generally accepted in the scientific community). 2. Frye Standard: The methodology must be "generally accepted” by the relevant scientific community. 1.6 Recovery of Audio and Video Files File recovery in forensics involves retrieving files that have been deleted, are in unallocated space on a drive, or are part of 1a damaged file system. Technique: File Carving ‘Concept: File carving is the process of recovering files from a storage medium based on their file structure and content (headers, footers, and intemal data structures), without relying on the file system metadata. This is essential for recovering deleted files or data from formatted drives 2. How it works: 1. Most file types have a unique starting sequence of bytes (header or "magic number") and often an ending sequence (footer). 2. For example, a JPEG file always starts with FF D8 FF E0 or FF D8 FF El. A WAV audio file starts with the ASCII characters RIFF. 3. File carving tools scan the raw data of a drive (the unallocated space) looking for these known headers. 4, Once a header is found, the tool copies data from that point until a known footer is found or until a predefined file size is reached. 5. The copied data is saved as a new file, which can then be examined. 4, Tools: 1. PhotoRee: A powerful, open-source file carving tool. 2, Foremost: A command-line carving tool for Linux. 3. Bulk Extractor: Scans for features like email addresses and URLs but also has carving capabilities. 4, Integrated in forensic suites like EmCase and FTK. 5. Challenges: 1, Fragmentation: If a file is stored in non-contiguous blocks on the drive, simple header/footer carving will fail, recovering only the first fragment, Advanced carving techniques are needed to reassemble the fragments, 2. Unknown File Formats: Carving relies on a known library of headers/footers, It cannot recover proprietary or unknown file types. 1.7 Cop: it Infringement, Plagiarism and Related Laws 1. Copyright: A legal right granted to the creator of an original work giving them exclusive control over its use and distribution, 1. Infringement: Using a copyrighted work without the owner's permission Multimedia forensics helps prove infringement by: 1g Souree: Analyzing file metadata or unique camera artifacts (PRNU) to trace a pirated photo/video back to a ic device. 2. Detecting Hidden Information: Using steganography analysis to find hidden copyright notices or watermarks embedded ina file 3. Verifying Authenticity: Proving that a file is an exact copy of the copyrighted original arism: The act of taking someone else's work or ideas and passing them off as one's own. It is an ethical offense, but can also be a copyright infringement if the copied material is protected. 1. Forensie Role: While more common in text analysis, forensic tools can be used to compare multimedia files to find instances of direct copying (e.g., lifting a video segment without attribution). 3. Related Laws: 1 I Millennium Copyright Act (DMCA) (US): Criminalizes the production and dissemination of technology that circumvents copyright protection measures. 2. Copyright Act (Varies by Country, e.g., The Copyright Act, 1957 in India): The primary legislation governing copyright tion. legal doctrine that permits limited use of copyrighted material without permission for purposes. such as criticism, news reporting, teaching, and research, Determining fair use is complex and context-dependent.

You might also like