0% found this document useful (0 votes)
3 views17 pages

module 3 (1)

The document provides an in-depth overview of phishing and identity theft, explaining the methods and techniques used by fraudsters to acquire sensitive information. It details various phishing tactics, including email scams, and outlines the consequences of identity theft, along with preventive measures and common myths. Additionally, it highlights the importance of protecting personally identifiable information (PII) and the different methods attackers use to commit identity theft.

Uploaded by

papri_karekal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views17 pages

module 3 (1)

The document provides an in-depth overview of phishing and identity theft, explaining the methods and techniques used by fraudsters to acquire sensitive information. It details various phishing tactics, including email scams, and outlines the consequences of identity theft, along with preventive measures and common myths. Additionally, it highlights the importance of protecting personally identifiable information (PII) and the different methods attackers use to commit identity theft.

Uploaded by

papri_karekal
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module 3

Phishing and Identity Theft


Phishing:
● Defn: It is a criminally fraudulent process of attempting to acquire sensitive information
such as usernames, passwords and credit card details by masquerading as a trustworthy
entity in an electronic communication.
● It is an act of sending an E-mail to a user falsely claiming to be an established, legitimate
enterprise in an attempt to scam the user into surrounding private information that will be
used for ID theft.
● It is a scam to steal valuable information such as credit card and Social Security numbers,
user ID's and passwords.
● It is also known as brand spoofing. An artificial looking e-mail is sent to potential victims
pretending to be from their bank or retail establishment.
● Fishing is a type of deception designed to steal your identity.
● In phishing schemes, the phisher tries to get the user to disclose valuable personal data
such as credit card numbers, passwords, account data. Or other information by
convincing the user to provide it under false pretenses.
● E-mail is a popular medium used in the phishing attacks and such emails are also called
as spams. However, not all emails are spam emails.
● There are two types of emails. a) spam emails and b) hoax emails.
a)Spam emails:
● They're also known as junk emails.
● They involve nearly identical messages sent to numerous recipients.
● Botnets are used to send about 80% of spam.
● Types of spam emails are as follows.
1. Unsolicited bulk e-mail(u BE).
2. Unsolicited commercial e-mail(uCE.)
● Spam emails proved to be a popular medium for fishers to scam users to enter
personal information on fake websites using e-mail forged to look like as if it is
from a bank or other organization.
● Spam emails. Can we reduced by following
1. Sharing personal e-mail address with limited people and on. Public websites.
2. Never reply or open any spam.
3. Use alternate e-mail address to register for any personal or shopping website.
4. Do not forward any emails from unknown recipients.
5. Previewing a e-mail before opening it.

b) Hoax emails:
These are deliberate attempts to deceive or trick a user into believing or accepting that
something is real when the whole actor knows it is false.
● It is difficult to sometimes recognize whether an E-mail is spam or a hoax. The
websites mentioned below can be used to check the validity of such hoax emails.
1. [Link].
2. [Link]

To maximize the chances that a recipient respond, the phisher might employ any or
all of the following tactics:
1. Names of legitimate organizations: Instead of creating a phony company from scratch, the
phisher might use a legitimate company's name and incorporate the look and feel of its website
(i.e., including the color scheme and graphics) into the Spam E-Mail.
2. “From" a real employee: Real name of an official, who actually works for the organization,
will appear in the "from" line or the text of the message (or both). This way, if a user contacts the
organization to confirm whether "Rajeev Arora" truly is "Vice President of Marketing" then the
user gets a positive response and feels assured.
[Link] that "look right”: The E-Mail might contain a URL (.e., weblink) which seems to be
legitimate website wherein user can enter the information the phisher would like to steal.
However, in reality the website will be a quickly cobbled copycat - a "spoofed website that looks
like the real thing, that is, legitimate website. In some cases, the link might lead to selected pages
of a legitimate website - such as the
real company's actual privacy policy or legal disclaimer.
[Link] messages: Creating a fear to trigger a response is very common in Phishing attacks -
the E-Mails warn that failure to respond will result in no longer having access to the account or
E-Mails might claim that organization has detected suspicious activity in the users' account or
that organization is implementing new privacy software for ID theft solutions.

Methods of phishing:
1. Dragnet:
● This method involves use of spammed emails bearing falsified corporate identification
which are addressed to a large group of people to websites or popup windows with
similarly falsified identification.
● Dragnet fishers do not identify specific prospective victims in advance.
● When the victim clicks on the links in the body of the e-mail. They are taken to the
websites or pop up windows where they are requested to enter bank or credit card
account date or other personal data.
2. Rod and reel:
● In this method, features identify specific prospective victims in advance and convey false
information to them to prompt their disclosure of personal financial data.
3. Lobster pot :
● This method focuses upon use of spoofed websites.
● It consists of creating bogus or phony websites similar to legitimate corporate ones,
targeting a narrowly defined class of victims.
● These attacks are also called content injection phishing.
● Phisher places a web link into an e-mail message to make it look more legitimate and
which takes the victim to a phony scam site which looks exactly like the official site.
● These fake sites are called spoof websites which can steal personal data.
4. Gillnet:
● In this technique. The phishers introduce malicious codes into emails and websites.
● Thick and misuse browser functionality by injecting hostile content into another site's
popup window.
● By opening such emails, the victims will be having Trojen horse introduced into their
systems.
● The malicious code will change the settings in the user system so that users who want to
visit legitimate banking websites will be redirected to look a like phishing sites.
● In other cases, the malicious code will record users keystrokes and passwords when they
visit legitimate banking sites and then transmit those data to freshers for later illegal
access to the user's financial accounts.

Phishing techniques:

[Link] web link manipulation:


In phishing attacks, the URLs are usually supplied as misspelled. For example, instead of
[Link], the URL is provided as [Link]. Lobsterpot method of phishing
is used by phishers to make the difference of one or two letters in the URLs which is ignored by
the netizens.
2. Filter evasion:
This technique you use graphics instead of text to obviate from, netting such emails by anti
phishing filters. Normally these filters are inbuilt with web browsers.
3. Website forgery:
In this technique, the phisher directs netizens to the website design and developed by
him, to login into the website by altering the browser address bar through JavaScript commands.
4. Flash phishing:
Anti phishing toolbars are installed or enabled to help check the web page content for
signs of phishing, but have limitations that they do not analyze flash objects at all. Phishers use it
to emulate legitimate websites. netizens believe that the website is clean and is a real website
because the anti phishing toolbar is unable to detect it.
5. Social phishing:
Phishers entice the netizens to reveal sensitive data by other means and it works in a
systematic manner. Phisher speaks with the victim in a similar fashion as a bank employee,
asking to verify the victim that he is a customer of the bank. phisher
gets the required details swimmingly.
6. Phone phishing:
Phishers can use a fake caller ID data to make it appear that the call is received from a
trusted organization to entice users to reveal their personal information such as account numbers
and passwords.
=================
Phishing toolkits and spy phishing:

● A phishing toolkit is a set of scripts or programs that allows a phisher to automatically set
up phishing websites that spoof the legitimate websites of different brands, including the
graphics displayed on these websites.
● Phishing toolkits are developed by groups or individuals and are sold to the underground
economy.
● These sophisticated kits are typically difficult to obtain or quite expensive and are more
likely to be purchased and used by well organized groups of phishers rather than average
users.
● Fishers use hypertext preprocessor PHP to develop fishing kits.
● Most of the fishing kits are advertised and distributed at no charge and they are also
called DIY fishing kits.
● These kits hide the back doors through which the phished information is sent to recipients
other than the intended users.

The following are a few examples of such toolkits:


[Link]: It is a phishing toolkit popular in the hacking community since 2005. It allows non
techies to launch phishing attacks. The kit allows a single website with multiple DNS names to
host a variety of fished web pages covering numerous organizations and institutes.
2. Xrenoder Trojan Spyware: It resets the home page and/or the the search settings to point to
other websites, usually for commercial purposes.
3. Cpanel Google: It is a Trojan spyware that modifies DNS entry in the hosts file. To its own
website. If Google gets redirected to this website and it may end up having a version of the
website prepared by phisher.
=================
Identity Theft (ID Theft):

● It is used to refer to fraud that involves someone pretending to be someone else to steal
money or get other benefits.
● The person whose identity is used can suffer various consequences when he or she is held
responsible for the perpetrators actions.
● The ID theft is a punishable offense under the Indian IT Act, section 66C and section
66D.
● Federal Trade Commission, (FTC) has provided the statistics about each one of the
identity fraud mentioning prime frauds presented below.
● Card fraud. 26%.
● Bank fraud 17%.
● Employment fraud 12%.
● Government fraud 9%.
● Loan fraud 5%.

Myths and facts about Identity theft:

[Link] Myth Fact

1 There is no way to protect yourself The risk of identity theft can be minimized by taking preventive
from identity theft. measures such as keeping financial records duly protected and
private.

2 Identity theft is only a financial Financial identity theft is theft of information for financial gain,
crime. which is most prevalent. However, other types of identity theft
are also equally dangerous.

3 It is my bank's fault if I become a Majority of the identity theft begins when personal information
victim of identity theft. may be stolen with low technology tools such as lost or stolen
wallet, checkbook, or a debit card or credit card. Oregon. More
highly technological methods such as skimming, phishing and
hacking.

4 It is safe to give your personal It is never safe to give personal information to unsolicited callers,
information over the phone if your no matter who they say they are.
caller ID confirms that it is your
bank.
[Link] Myth Fact

1 There is no way to protect yourself The risk of identity theft can be minimized by taking preventive
from identity theft. measures such as keeping financial records duly protected and
private.

5 Checking your credit card If anyone wants to be vigilant about identity theft, one should
periodically or using a credit check their credit card regularly and one should also review their
monitoring service is all you need bank and credit card statements regularly.
to do to protect yourself from
identity theft.

6 My personal contact information is That could be used by a thief to impersonate you should be
not valuable to an identity thief. protected.

7 Shredding my mail and other Shredding documents that contain personal information before
personal documents will keep me you throw them away is a great way to protect yourself from
safe. dumpster diving, which occurs when attackers search the trash
for personal information.

8 I don't use the Internet, so my Your personal information appears in more places. Like medical
personal information is not records, job applications, or school emergency contact forms.
exposed online.

9 Networking is safe. Social networking sites such as Facebook, Myspace, Twitter can
be fun to use. However, they are very dangerous when it comes
to your identity.

10 It is not safe to shop or bank Less social networking, shopping and banking online are safe as
online. long as you use common sense and make good choices about
where and how you do it.

Personally identifiable information, PII:


● The fraudster always has an eye on the information which can be used to uniquely
identify, contact or locate a single person, or can be used with other sources to uniquely
identify a single individual.
● The fraudster attempts to steal the elements mentioned below, which can express the
purpose of distinguishing individual identity.
■ Full name
■ national identification number.
■ Telephone number, mobile number.
■ Drivers license number.
■ Credit card number.
■ Digital Identity.
■ Birthplace / birth date
■ Face and fingerprints.
● The fraudster message for following about an individual which is less often used to
distinguish individual identity like
■ First or last name.
■ Age
■ country, state or city of residence
■ Gender, name of the school or college or?
■ Job position, Grades or salaries
■ Criminal record.

● The information can be further classified as non classified and classified.


1. Non classified information.
Public information. Information that is a matter of public record or knowledge.
Personal information: Information belongs to a private individual, but the
individual commonly may share his information with others for personal or business
reasons.:
Business information: That do not require any special protection and may be
routinely shared with anyone inside or outside of the business.
private information: Information that can be private if associated with an
individual and individual can object in case of disclosure.
Business information: Information which, if disclosed, may harm the business.

2. Classified information.:
Confidential.: Information that requires protection and an unauthorized
disclosure could damage national security.
Secret: That requires substantial protection, and unauthorized disclosure could
seriously damage national security.
Top secret: Information that requires the highest degree of production and
unauthorized disclosure could severely damage national security.
==============
Techniques of ID theft:
Identity theft can affect all aspects of a victim's daily life and often occurs far from its
victims. The attackers use both traditional that is human-based methods as well as computer
based techniques.
1. Human based methods: Others are techniques used by an attacker without and/or or minimal
use of technology.
● Direct access to information: Have earned a certain degree of trust. Can obtain
legitimate access to a business or to a residence to steal the required personal
information.
● Dumpster diving: Retrieving documents from trash bins is very common.
● Theft of a purse or a wallet: While it often contains bank credit cards, debit cards,
driving license, medical insurance, identity card and many important documents. Pick
Pocketers, steal the wallets and in turn sell the personal information.
● Mail theft and rerouting: It is easy to steal the postal mails from mailboxes which has
pure security mechanism and all the documents available for the fraudster are free of
charge. Example bank mail. Administrative forms or partially completed credit offers.
The fraudster can use your name and other information that may prove to be harmful for
an individual in the near future.
● Shoulder surfing: Two lighter around the public facilities such as cyber cafes, near
ATMs and telephone booths can keep an eye to grab the personal information.
● False or disguised ATMs, (skimming): Just as it is possible to imitate a bank ATM, it is
also possible to install miniature equipment on valid ATM. This equipment captures the
card information using which duplicate card can be made and personal identification
number (PIN )can be obtained by stealing the camera films.
● Used or mistreated employees: An employee or partner with access to the personal file,
salary information, insurance files, or bank information can gather all sorts of
confidential information and can use it to provide sufficient damage.
● Telemarketing and fake telephone calls: This is an effective method for collecting
information from unsuspecting people. The caller who makes a cold call asks the victim
to verify account number immediately on the phone, often without much explanation and
verification. This attack is known as vishing.

[Link] based techniques: These techniques are attempts made by the attacker to exploit
the vulnerabilities within existing processes or systems.
● Backup theft: This is the most common method. In addition to stealing equipment from
private buildings, attackers also strike public facilities such as transport areas, hotels and
recreation centers. They get fully analyzed on equipment or backups, or recover the data.
● Hacking, unauthorized access to systems, and database theft: Besides stealing the
equipment or hardware, criminals attempt to compromise information systems with
various tools, techniques, and methods to gain unauthorized access to download the
required information.
● Phishing: Steals sensitive information through email.
● Farming: The attacker setup typo or matching domain names of the target and install
websites with similar look and feel. Hence, even if a user types incorrect URL, the user
gets the website with. The same look and feel.
● Redirectors: These are the malicious programs that redirect users' network traffic to
locations they did not intend to visit.
● Hardware: The attacker uses the hardware equipment that will be inserted into the
systems that can steal the identity of the users.

==============
Types of identity theft
Identity is stolen in order for someone to commit the crime. ID theft is related to many
areas.
1. Financial identity theft.
2. Criminal identity theft.
3. Identity cloning.
4. Business identity theft.
5. Medical energy theft.
6. Synthetic identity theft.
7. Child identity theft.

1. Financial identity theft.:


● Financial ID theft includes bank fraud, credit card fraud, tax refund fraud, mail
fraud, and several more.
● Financial identity occurs when a fraudster makes use of someone else's
identifying details such as name, SSN and bank account details to commit fraud
that is detrimental to victims finances.
● The fraudster will completely take over a victim's identity, which enables the
fraudster to easily open bank accounts, multiple credit cards, purchase vehicle,
receive a home, or even find employment in the victim’s name.
● The process of recovering from the crime is often expensive, time consuming.
Painful.

[Link] identity theft:


It involves making over someone else's identity to commit a crime, such as enter into a country,
gets special permits, hide one's own identity or commit acts of terrorism. These criminal
activities can include
■ computer and cyber crimes.
■ Organized crime
■ Drug trafficking.
■ smuggling
■ Money laundering etc.
● Individuals who commit ID theft are not always out to steal the victim's money or
ruin victims credit. This type of fraud or theft occurs when a fraudster uses the
victims name upon an arrest or during criminal investigation.

3. Identity cloning :
● Identity cloning may be the scariest variation of all ID theft.
● Instead of stealing the personal information for financial gain or committing
crimes in the victim's name, identity clones compromise the victim’s life by
actually living and working as the victim.
● Identity cloning is the act of a fraudster living a natural and unusual life similar to
victim’s life may be a different location.
● An Identity Clone will obtain as much information about the victim as possible.
● Identity Clone want as much personal information about the victim as they can
attain.

4. Business identity theft:


● “ Bust-out” is one of the schemes fraudsters use to steal business identity.
● Identity theft in the business context occurs most often when someone knocks off
the victims product and masquerades their shobby goods as victim’s. It is a kind
of intellectual property theft.
● The consequences of business ID theft may call for a disaster to the business, such
as call out from the market and damage the reputation and hence it is extremely
important to employ countermeasures for such type of attacks. Some of such
measures are.
■ Premise with locks and alarms.
■ Put your business records under lock and key.
■ Be cautious on the phone.
■ Limit access to your IT systems.
■ Protect the IT systems from hackers.
■ Avoid broadcasting information.
■ Create and enforce an organization wide information security
policy.
■ Disconnect the axis of ex employees immediately.

5. Medical energy theft.
● Medical facility providers are moving from cumbersome paper records to faster
and easier file and trace electronic records. However, the concern over medical ID
theft is growing.
● The stolen information can be used by a fraudster or sold in the black market to
people who need it.
● Medical theft can be dangerous, not only from a financial perspective. But also
from a medical perspective.
● If the fraudster has successfully stolen the victim’s identity and received the
treatment the record can become part of the victims permanent medical record.
● The World Privacy Forum estimates that there are more than 250,000 cases of
medical ID theft each year and acknowledges that medical ID theft is a crime that
can cause great harm to the victims.

6. Synthetic identity theft.:


● This is an advanced form of ID theft in the ID theft world.
● The fraudster will take parts of personal information from many victims and
combine them.
● The new identity is not any specific person, but all the victims can be affected
when it is used.

7. Child identity theft.:


Parents might sometimes steal their child's identity to open credit card accounts, utility
accounts, bank accounts, and even to take out loans. Or secure leases because they won't credit
histories insufficient or too damaged to open such accounts.
===============
Cyber forensics:

● The application of a computer for investigating computer based crime has little
development of a new field called computer forensics. Sometimes computer forensics is
also referred to as digital forensics.
● The computer forensics experts need digital evidence in cases involving data acquisition,
preservation, recovery, analysis and reporting, intellectual property theft, Computer
Misuse, Corporate policy violation, mobile device data acquisition and analysis,
malicious software application into your system, encrypted, deleted and hidden Files
recovery, confidential information leakage etc.
● Forensic science is the application of science to law, and it is ultimately defined by use in
court.

Digital forensic science.:


● Digital forensics is the application of analysis techniques to the reliable and unbiased
collection, analysis, interpretation, and presentation of digital evidence.
● The objective of cyber forensics is to provide digital evidence of a specific or general
activity.

Definition of computer forensics.: It is a lawful and ethical seizure, acquisition, analysis,


reporting, and safeguarding of data and metadata derived from digital devices which may contain
information. That is notable.
Definition of digital forensics.: It is the use of scientifically derived, unproven methods towards
the preservation, collection, validation, identification, analysis, interpretation, documentation and
presentation of digital evidence derived from digital sources for the purpose of facilitation.

The role of digital forensics is to -

● Uncover and document evidence and leads.


● Corroborate evidence discovered in other ways.
● Assist in showing a pattern of events. Are connect attack and victim computers.
● Reveal an end to end path of events leading to a compromise attempt, successful or not.
● Extract data that may be hidden, deleted, and otherwise not directly available.
================

Need of computer forensics:


● The media on which clues related to cybercrime reside would vary from case to case.
● There are many challenges for forensic investigators because storage devices are getting
miniature due to advances in electronic technology. For example, external storage
devices such as mini hard disks are available in amazing shapes.
● Looking for digital forensic evidence is like looking for a needle in the haystack.
● With the help of forensic tools or software, the relevant data can be sieved from irrelevant
mass.
======================
Chain of custody:

● The basic idea behind ensuring 'chain of custody' is to ensure that the evidence is not
tampered with.
● In a broader perspective, evidence includes everything that is used to determine or
demonstrate the truth of an assertion.
● Evidence can be used in court to convict people who are believed to have committed
crimes.
● Therefore, evidence must be handled in a careful manner to avoid later allegations of
tampering or misconduct that can compromise the case.
● The purpose behind recording the chain of custody is to establish the integrity of the
evidence.
● The police officer or detective will take charge of a piece of evidence, documents, its
collection and hand it over to an evident clerk for storage in a secure place.
● All such transactions, as well as easy succeeding transactions between evidence
collection and its appearance in court need to be completely documented to withstand
legal challenges to the authenticity of the evidence.
● The documentation must include conditions under which the evidence is collected, the
identity of all those who handled the evidence, duration of the evidence, custody security
conditions while handling or storing the evidence, and the manner in which evidence is
transferred to subsequent constraints each time such a transfer occurs.

========================
CYBER FORENSICS AND DIGITAL EVIDENCE:

Cyber forensics can be divided into


i) computer forensics
ii)network forensics - deals with the threats that are possible through computer networks.

There are number of contexts involved in actually identifying a piece of digital evidence:
[Link] context: It must be definable in its physical form. That is, it should reside on a
specific piece of media.
2. Logical context: It must be identifiable as to its logical position, that is, where does it reside
relative to the file system.
3. Legal context: We must place the evidence in the correct context to read it its meaning. It
may require looking at the evidence as machine language, for example ASCII code.

The path taken by digital evidence can be conceptually depicted as shown below.

Fig: path of digital evidence


==============================
Digital forensics life cycle:

The digital forensics process starts from preparation of the evidence to testifying it.

The following figure shows the process model for understanding seizure and handling of
forensics evidence legal framework.
Tools that are used to generate reports for code should be validated. There are many tools to be
used in the process. One should determine the proper tool . To be used based on the case.
Broadly speaking, a four and six life cycle involves the following phases.
1. Preparation and identification.
2. The collection and recording.
3. Storing and transporting.
4. Examination or investigation.
5 Analysis, Interpretation, and attribution.
6 Reporting.
7 Testifying.

1. Preparation and identification:


In order to be processed and analyzed, evidence must first be identified. It might be possible that
the evidence may be overlooked and not identified at all. A sequence of events in a computer
might include interactions between:
● Different files
● Files and file systems
● Processes and files
● Log files
In case of a network, the interactions can be between devices in the organization or across the
globe (Internet). If the evidence is never identified as relevant, it may never be collected and
processed.
2. The collection and recording:
● Digital evidence can be collected from many sources. The obvious sources can be:
■ Mobile phone
■ Digital cameras
■ Hard drives
■ CDs
■ USB memory devices
○ Non-obvious sources can be:
■ Digital thermometer settings
■ Black boxes inside automobiles
■ RFID tags
● Proper care should be taken while handling digital evidence as it can be changed easily.
Once changed, the evidence cannot be analysed further.
● A cryptographic hash can be calculated for the evidence file and later checked if there
were any changes made to the file or not.
● Sometimes important evidence might reside in the volatile memory. Gathering volatile
data requires special technical skills.
3. Storing and transporting:
● Some guidelines for handling of digital evidence:
■ Image computer-media using a write-blocking tool to ensure that no data
is added to the suspect device
■ Establish and maintain the chain of custody
■ Document everything that has been done
■ Only use tools and methods that have been tested and evaluated to validate
their accuracy and reliability.
● Care should be taken that evidence does not go anywhere without properly being traced.
Things that can go wrong in storage include:
■ Decay over time (natural or unnatural)
■ Environmental changes (direct or indirect)
■ Fires
■ Floods
■ Loss of power to batteries and other media preserving mechanisms
● Sometimes evidence must be transported from place to place either physically or through
a network.
● Care should be taken that the evidence is not changed while in transit. Analysis is
generally done on the copy of real evidence. If there is any dispute over the copy, the real
can be produced in court.
4. Examination or investigation of digital evidence:
● Forensics specialists should ensure that he/she has proper legal authority to seize, copy
and examine the data. As a general rule, one should not examine digital information
unless one has the legal authority to do so. Forensic investigation performed on data at
rest (hard disk) is called dead analysis.
● Many current attacks leave no trace on the computer’s hard drive. The attacker only
exploits the information in the computer’s main memory. Performing forensic
investigation on main memory is called live analysis. Sometimes the decryption key
might be available only in RAM. Turning off the system will erase the decryption key.
The process of creating and exact duplicate of the original evidence is called imaging.
Some tools which can create entire hard drive images are:
■ DCFLdd
■ Iximager
■ Guymager
● The original drive is moved to secure storage to prevent tampering. The imaging process
is verified by using the SHA-1 or any other hashing algorithms.
5 Analysis, Interpretation, and attribution:
● In digital forensics, only a few sequences of events might produce evidence. But the
possible number of sequences is very huge. The digital evidence must be analyzed to
determine the type of information stored on it. Examples of forensics tools:
■ Forensics Tool Kit (FTK)
■ EnCase
■ Scalpel (file carving tool)
■ The Sleuth Kit (TSK)
■ Autopsy
● Forensic analysis includes the following activities:
■ Manual review of data on the media
■ Windows registry inspection
■ Discovering and cracking passwords
■ Performing keyword searches related to crime
■ Extracting emails and images
● Types of digital analysis:
○ Media analysis : Analysis of data from a storage device. This does not consider
any partitions or other operating system specific data structures.
○ Media management analysis: It is analysis of management systems and used to
organize media. This typically involves partitions and may include volume
management or redundant array of independent systems that merge data from
multiple storage devices into a single virtual storage device.
○ File system analysis : It is analysis of file system data inside a partition or disk.
This typically involves processing the data of, extract the content of file or to
recover contents of a deleted file.
○ Application analysis : It is an analysis of data inside a file. Files are created by
users and applications. The format of the contents is application specific.
○ Network analysis : It is the analysis of data on a communication network.
Network packets can be examined using OSI model to interpret the raw data into
an application level stream.
○ Image analysis : It was mentioned that the image is single searchable file. Digital
images are the target of many digital investigations because some are contraband.
This type of analysis looks for the information about where the picture was taken
and who or what is in the picture. Image analysis also include examining images
for evidence of steganography.
○ Video analysis: Digital video is used to security cameras and in personal video
cameras and webcams. This type of analysis examines the video for the
identification of objects in the video and the location where it was shot.
6 Reporting:
After the analysis is done, a report is generated. The report may be in oral form or in written
form or both. The report contains all the details about the evidence in analysis, interpretation, and
attribution steps. As a result of the findings in this phase, it should be possible to confirm or
discard the allegations. Some of the general elements in the report are:
● Identity of the report agency
● Case identifier or submission number
● Case investigator
● Identity of the submitter
● Date of receipt
● Date of report
● Descriptive list of items submitted for examination
● Identity and signature of the examiner
● Brief description of steps taken during examination
● Results / conclusions
7 Testifying:
This phase involves presentation and cross-examination of expert witnesses. An expert witness
can testify in the form of:
● Testimony is based on sufficient facts or data
● Testimony is the product of reliable principles and methods
● Witness has applied principles and methods reliably to the facts of the case
Experts with inadequate knowledge are sometimes chastised by the court. Precautions to be
taken when collecting digital evidence are:
● No action taken by law enforcement agencies or their agents should change the evidence
● When a person to access the original data held on a computer, the person must be
competent to do so
● An audit trial or other record of all processes applied to digital evidence should be
created and preserved
● The person in-charge of the investigation has overall responsibility for ensuring that the
law and these are adhered to

You might also like