Tutorial 1
CI3002N (Digital Forensics)
Q1 - What is Digital Forensics? Explain its meaning, scope and basic terminology.
Q2 - Describe the core principles of Forensic Science, including chain of custody and
data integrity.
Q3 - Explain in detail the key components/steps of digital forensic approaches and best
practices.
English
Ans 1 -
Digital Forensics is the process of identifying, collecting, preserving, examining, analyzing
and presenting digital evidence from electronic devices in a systematic manner.
Digital evidence can be obtained from computers, mobile phones, hard disks, USB drives,
memory cards, networks, emails and other digital devices.
The main purpose of digital forensics is to find facts and evidence from digital devices that
can help in an investigation.
Scope of Digital Forensics
1. Cybercrime Investigation: Investigating hacking, phishing, online fraud and other
cybercrimes.
2. Computer Investigation: Examining computers and storage devices for evidence.
3. Mobile Forensics: Examining mobile phones, SIM cards, messages and call records.
4. Email Investigation: Examining emails, headers, attachments and sender
information.
5. Malware Investigation: Examining malicious software and the traces left by it.
Basic Terminology
• Digital Evidence: Information stored or transmitted in digital form that is useful in an
investigation.
• Forensic Image: An exact copy of a digital storage device used for examination.
• Evidence Acquisition: The process of obtaining digital evidence from a device.
• Examination: Searching and extracting relevant information from evidence.
• Analysis: Interpreting the extracted information to understand what happened.
• Chain of Custody: A record of who collected, handled, transferred and stored the
evidence.
• Data Integrity: Ensuring that the evidence has not been changed or manipulated.
Ans 2-
Forensic Science is the application of scientific methods and principles to investigate crimes
and examine evidence.
Main Principles
1. Identification:
The investigator should correctly identify the evidence and determine its relevance to the
investigation.
2. Preservation:
Evidence should be protected from alteration, damage, destruction or contamination.
Original evidence should be kept safe.
3. Integrity:
Evidence should remain unchanged from the time it is collected until it is presented.
4. Documentation:
Important activities should be properly recorded, such as what evidence was collected,
when and where it was collected, who collected it and which tools were used.
5. Chain of Custody:
Chain of Custody is the documented history of evidence from collection to final presentation
or storage.
Example:
Evidence Collected → Labelled → Stored → Transferred → Examined → Reported
It helps prove that the evidence was properly handled and not changed or replaced.
6. Data Integrity:
Data Integrity means maintaining the accuracy and original condition of digital evidence.
Hash values can be used to check integrity. If the hash values before and after examination
match, it indicates that the data has not been changed.
7. Proper Examination:
Evidence should be examined using suitable forensic methods and tools.
8. Reporting:
Findings should be clearly documented in a forensic report.
Ans 3-
A Digital Forensic Approach is a systematic process used to handle digital evidence from the
beginning of an investigation until the final presentation of findings.
Main Steps
1. Preparation:
Prepare required forensic tools, equipment, storage media and documentation.
2. Identification:
Identify the incident, devices involved and possible sources of evidence.
3. Preservation:
Protect evidence from alteration, destruction or unauthorized access. The original evidence
should be kept safe.
4. Acquisition / Collection:
Collect digital evidence from the relevant device. This may include creating a forensic image,
collecting logs or extracting mobile data.
5. Examination:
Search and extract relevant information from the acquired evidence. This may include files,
deleted data, metadata, browser history and logs.
6. Analysis:
Study the extracted information to understand what happened, when it happened and
which device or account was involved.
7. Timeline / Interpretation:
Connect different pieces of evidence to understand the sequence of events.
Example:
Email Received → Attachment Downloaded → File Opened → Suspicious Activity
8. Documentation:
Record evidence details, date and time, collection method, tools used, hash values and
findings.
9. Reporting:
Prepare a clear and accurate forensic report containing the important findings.
10. Presentation:
Present the findings to investigators, organizations or a court based on the available
evidence.
Best Practices
1. Protect the original evidence.
2. Maintain Chain of Custody.
3. Maintain Data Integrity.
4. Use appropriate forensic tools.
5. Document every important action.
Hindi
Ans 1-
Digital Forensics वह प्रक्रिया है क्रिसमें electronic devices से digital evidence को identify,
collect, preserve, examine, analyze और present क्रिया िाता है।
Digital evidence computers, mobile phones, hard disks, USB drives, memory cards, networks
और emails से प्राप्त क्रिया िा सिता है।
Digital Forensics िा मुख्य उद्दे श्य investigation में उपयोगी facts और evidence प्राप्त करना है।
Digital Forensics का Scope
1. Cybercrime Investigation: Hacking, phishing और online fraud िी िााँच।
2. Computer Investigation: Computers और storage devices िी िााँच।
3. Mobile Forensics: Mobile phones, SIM cards, messages और call records िी िााँच।
4. Email Investigation: Emails, headers और attachments िी िााँच।
5. Malware Investigation: Malicious software और उसिे traces िी िााँच।
Basic Terminology
• Digital Evidence: Investigation में उपयोगी digital information.
• Forensic Image: Storage device िी exact copy.
• Evidence Acquisition: Device से evidence प्राप्त िरना।
• Examination: Evidence में useful information खोिना।
• Analysis: प्राप्त information िो समझना।
• Chain of Custody: Evidence िो क्रिसने collect, handle, transfer और store क्रिया उसिा
record.
• Data Integrity: यह सुक्रनक्रित िरना क्रि evidence में िोई बदलाव न हुआ हो।
Ans 2-
Forensic Science scientific methods और principles िा उपयोग िरिे crimes िी investigation
और evidence िी examination िरने िी प्रक्रिया है।
मुख्य Principles
1. Identification – पहचान:
Evidence िी सही पहचान िरना और यह दे खना क्रि वह investigation से संबंक्रित है या नहीं।
2. Preservation – संरक्षण:
Evidence िो alteration, damage, destruction और contamination से सुरक्रित रखना।
3. Integrity – अखंडता:
Collection से लेिर presentation ति evidence में िोई बदलाव नहीं होना चाक्रहए।
4. Documentation – दस्तावेजीकरण:
Evidence िब, िहााँ और क्रिसने collect क्रिया तथा िौन-से tools इस्तेमाल हुए, इन सभी बातों िो
record िरना।
5. Chain of Custody:
Evidence िो collect िरने से लेिर final presentation ति उसिी पूरी handling िा documented
record.
उदाहरण:
Evidence Collect → Label → Store → Transfer → Examine → Report
इससे यह साक्रबत िरने में मदद क्रमलती है क्रि evidence िो सही तरीिे से handle क्रिया गया और
उसमें िोई बदलाव नहीं क्रिया गया।
6. Data Integrity – Data की अखंडता:
Digital evidence िो accurate और original condition में रखना।
Integrity check िरने िे क्रलए Hash Value िा उपयोग क्रिया िा सिता है। यक्रद दोनों hash values
match िरती हैं , तो data में बदलाव न होने िा संिेत क्रमलता है।
7. Proper Examination:
Suitable forensic methods और tools िा उपयोग िरिे evidence िी िााँच िरना।
8. Reporting:
Investigation िी findings िो clearly forensic report में क्रलखना।
Ans 3-
Digital Forensic Approach एि systematic process है क्रिसमें investigation िी शुरुआत से लेिर
final findings िी presentation ति digital evidence िो properly handle क्रिया िाता है।
मुख्य Steps
1. Preparation – तैयारी:
Required forensic tools, equipment, storage और documentation तैयार िरना।
2. Identification – पहचान:
Incident, involved devices और possible evidence sources िी पहचान िरना।
3. Preservation – संरक्षण:
Evidence िो alteration, destruction और unauthorized access से सुरक्रित रखना।
4. Acquisition / Collection – संग्रह:
Relevant device से digital evidence collect िरना। िैसे forensic image बनाना, logs collect िरना
या mobile data क्रनिालना।
5. Examination – जााँच:
Evidence में useful information खोिना और extract िरना। इसमें files, deleted data, metadata,
browser history और logs शाक्रमल हो सिते हैं।
6. Analysis – ववश्लेषण:
Extracted information िा अध्ययन िरिे पता लगाना क्रि क्या हुआ, कब हुआ और कौन-सा
device या account involved था।
7. Timeline / Interpretation:
अलग-अलग evidence िो िोड़िर events िा sequence समझना।
उदाहरण:
Email Received → Attachment Download → File Open → Suspicious Activity
8. Documentation – दस्तावेजीकरण:
Evidence details, date/time, collection method, tools, hash values और findings िो record
िरना।
9. Reporting – ररपोवटिं ग:
Important findings वाली clear और accurate forensic report तैयार िरना।
10. Presentation – प्रस्तुतीकरण:
Findings िो investigators, organization या court िे सामने evidence िे आिार पर प्रस्तुत िरना।
Best Practices
1. Original evidence िो सुरक्रित रखें।
2. Chain of Custody maintain िरें ।
3. Data Integrity maintain िरें ।
4. Appropriate forensic tools िा उपयोग िरें ।
5. हर important action िो document िरें ।