Cyber Forensics Overview and Methodology

0% found this document useful (0 votes)
82 views6 pages
The document discusses computer forensics, which involves examining digital devices for evidence in criminal or civil cases. It covers the differences between computer forensics and cybersec…

Uploaded by

Seenu Shukla

1.

Understanding Computer Forensics: Introduction


BCC 301 Cyber Security Notes (Unit 4)
Computer forensics, also referred to as computer forensic analysis, electronic
discovery, electronic evidence discovery, digital discovery, data recovery, data discovery,
Table of Contents
1. Understanding Computer Forensics: Introduction ..................................................... 2 computer analysis, and computer examination, is the process of methodically examining
computer media (hard disks, diskettes, tapes, etc.) for evidence. A thorough analysis by a
1.1 Computer Forensics vs. Cyber Security............................................................... 3
skilled examiner can result in the reconstruction of the activities of a computer user. [1]
1.2 Methodology Used in Cyber Forensics [2] .......................................................... 4
In other words, computer forensics is the collection, preservation, analysis, and
1.3 Computer/Cyber Forensics Experts ..................................................................... 4
presentation of computer-related evidence. Computer evidence can be useful in criminal cases,
1.4 Steps for cyber forensic specialists ...................................................................... 5 civil disputes, and human resources/employment proceedings.
1.5 Types of Computer/Cyber forensics .................................................................... 5 Computer forensics can be an essential facet of modern investigations. When a crime
1.6 Computer/Cyber forensic methods and technologies .......................................... 6 is committed and an investigation is started, one of the more common places to look for clues

1.7 Computer Forensics Services ............................................................................... 6 is the computer or cell phone of a suspect. This is where a computer forensics professional
enters the picture.
2. Digital Forensics Science........................................................................................... 8
When a suspect has been identified and their personal computer or cell phone taken into
3. The Need for Computer Forensics ........................................................................... 10
evidence, a computer forensics professional goes searching for data that is relevant to the
4. Cyber forensics and Digital Evidence...................................................................... 10 investigation. When searching for information, they need to be careful to follow detailed
5. Forensics Analysis of E-Mail................................................................................... 11 procedures that allow their findings to be used as evidence. The information they uncover,

6. Digital Forensics Life Cycle .................................................................................... 11 whether it be documents, browsing information or even metadata, may then be used by
prosecution to create a compelling case against the suspect.
7. Chain of Custody Concept ....................................................................................... 11
Cyber forensics is the process of obtaining data as evidence for a crime (using electronic
8. Network Forensics ................................................................................................... 11
equipment) while adhering to correct investigative procedures to apprehend the offender by
9. Approaching a Computer ......................................................................................... 11
presenting the evidence to the court. Computer forensics is another name for cyber forensics.
10. Forensics Investigation. ......................................................................................... 11 Maintaining the chain of evidence and documentation to identify the digital criminal is the
11. Forensics and Social Networking Sites: The Security/Privacy Threats................. 11 primary goal of cyber forensics.

12. Challenges in Computer Forensics. ....................................................................... 11 It is crucial to make a digital copy of the system's unique storage cell during the
examination. To identify who is responsible for a security breach, a thorough cyber forensics
13. References .............................................................. Error! Bookmark not defined.
investigation is conducted. While assuring that the system is not impacted, a full investigation
is conducted on the software copy.

1 2
1.1 Computer Forensics vs. Cyber Security 1.2 Methodology Used in Cyber Forensics [3]

Cyber security is focused on prevention while computer forensics is about recovery and Acquiring a digital replica of the system that is being or must
reaction. Cyber security helps to prevent cybercrimes from happening, while computer be examined.

forensics helps recover data when an attack does occur and also helps identify the culprit behind
Confirming and authenticating the copy.
the crime.

Cyber security professionals use many different kinds of tools to protect networks and Getting back erased files (using Autopsy Tool).
the information. [2]

Web application firewalls (WAF): These firewalls help protect web applications from To discover the information you need, use keywords.
breaches and keep data secure.

Vulnerability scanners: These tools help scan through networks and programs to The creation of a technical report

identify vulnerabilities that can be potentially exploited by cybercriminals.

Penetration testing tools: Penetration testing tools are used by cyber security
1.3 Computer/Cyber Forensics Experts
professionals to carry out sanctioned hacks on their own systems in order to uncover
weaknesses. During an investigation, computer forensic professionals gather and analyze potential
evidence, including deleted, encrypted, or corrupted data. To avoid the evidence from being
Malware detectors: Malware detectors review sites and programs to see whether they
changed, tainted, or destroyed, all actions conducted during this procedure are documented and
have been infected with malware and pose a threat.
adhered to protocols.
Password security tools: Password security tools help identify weak passwords,
A cyber forensic specialist investigates each event using cutting-edge methods. Their
autofill saved passwords or generate passwords to help keep devices secure.
thorough inquiry focuses on building a solid chain of evidence. They can settle legal disputes
Table 1.1 Cyber security and computer forensics both have a few specializations
and convict cybercriminals thanks to the admissible proof they create.
Cyber security Computer forensics
Cyber forensics can accomplish:
Systems architecture Criminal investigations

Software security Data recovery


It can retrieve deleted data,
Which user executed which
Access management chat histories, emails, and
application can be determined?
more.
Ethical hacking and vulnerability assessment

Phone calls can be recorded Calls and SMS can also be


and played back afterward. erased.

3 4
1.4 Steps for cyber forensic specialists  Database forensics: This area of forensics looks at and evaluates database data as

Identification: Cyber forensics professionals identify the evidence that is present, well as any associated information.

where it is stored, and in what format it is stored as their first step.  Disk forensics: This area of forensics searches updated, active, or deleted files to
retrieve data from storage media.
Preservation: The next step after locating the data is to carefully preserve it and prevent
anyone from using the device so that the data cannot be altered. 1.6 Computer/Cyber forensic methods and technologies

Analysis: The next step after obtaining the data is to examine the data or system. Here, Reverse steganography: Steganography is a technique for concealing crucial data

the expert identifies the evidence that the criminal attempted to erase by erasing hidden files, within a digital file, picture, etc. Therefore, reverse steganography is used by cyber forensic

recovers the erased files, checks the recovered data, and restores the data. The ultimate result specialists to examine the data and discover a connection to the case.

may need numerous cycles of this method. Stochastic forensics: Without employing digital artifacts, stochastic forensics

Documentation: After data analysis, a record is now produced. This file contains all of professionals examine and recreate digital activities. In this context, artifacts refer to

the retrieved and readily accessible (not deleted) data that is useful for evaluating and unintentional data changes that result from digital operations.

reconstructing the crime scene. Cross-drive analysis: In this procedure, data from several computer discs are

Presentation: The studied data is finally provided to the court at this phase to help correlated and cross-referenced to preserve and evaluate data that is pertinent to the inquiry.

resolve cases. Live analysis: In this method, the operating system of the culprits' computer is

1.5 Types of Computer/Cyber forensics examined from within. To obtain certain important data, it targets the volatile RAM data.

Depending on the industry that requires digital inquiry, there are many forms of Deleted file recovery: This involves looking through memory for remnants of a file

computer forensics. Here are the fields: that was partially destroyed to recover it for use as evidence. [3]

 Network forensics: This entails keeping an eye on and examining network traffic 1.7 Computer Forensics Services
going to and coming from the criminal's network. Network intrusion detection
A computer forensics professional does more than turn on a computer, make a directory
systems and other automated techniques are the technologies in use here.
listing, and search through files. Your forensics professionals should be able to successfully
 Email forensics: In this kind of forensics, the specialists examine the criminal's perform complex evidence recovery procedures with the skill and expertise.
email and recover deleted email threads to extract important case-relevant data.
 Malware forensics: This area of forensics focuses on crimes connected to hacking.
To determine who is responsible for this breach, the forensics specialist looks at the
malware and Trojans in this case.
 Memory forensics: This area of forensics works with extracting information from
raw memory data (such as cache, RAM, etc.) after it has been collected.
 Mobile Phone forensics: Generally speaking, this area of forensics focuses on cell
phones. They look over and evaluate the cell phone's data.

5 6
Evidence Service Options: Standard service, On-site service, Emergency service and
Data
Data recovery duplication and Data seizure Priority service.
preservation
Miscellaneous Services:

Expert witness Media Document  Analysis of computers and data in criminal investigations
services conversion searches
 On-site seizure of computer data in criminal investigations
 Analysis of computers and data in civil litigation.
Evidence miscellaneous
service options services  On-site seizure of computer data in civil litigation
 Analysis of company computers to determine employee activity
 Assistance in preparing electronic discovery requests
 Reporting in a comprehensive and readily understandable manner
Data Recovery: Computer forensics experts should be able to safely recover and
analyze otherwise inaccessible evidence. The ability to recover lost evidence is made possible  Court-recognized expert witness testimony

by the expert’s advanced understanding of storage technologies.  Fast turnaround time

Data Duplication and Preservation: the data must not be altered in any way, and the 1.8 Types of Computer Forensics Systems

seizure must not put an undue burden on the responding party. Computer forensics experts  Internet security systems
should acknowledge both of these concerns by making an exact duplicate of the needed data.  Intrusion detection systems
Data Seizure: forensics experts inspect and copy designated documents or data  Firewall security systems
compilations that may contain evidence.  Storage area network security systems

Expert Witness Services: forensics experts should be able to explain complex  Network disaster recovery systems

technical processes in an easy-to-understand fashion. This should help judges and juries  Public key infrastructure security systems

comprehend how computer evidence is found, what it consists of, and how it is relevant to a  Wireless network security systems

specific situation.  Satellite encryption security systems


 Instant messaging (IM) security systems
Media Conversion: forensics experts should extract the relevant data from old and
 Net privacy systems
unreadable devices, convert it into readable formats, and place it onto new storage media for
 Identity management security systems
analysis.
 Identity theft prevention systems
Document Searches: forensics experts should also be able to search over large number
of electronic documents in minimum time. Speed and efficiency of these searches make the 2. Digital Forensics Science
discovery process less complicated and less intrusive to all parties involved.
Digital forensics is a branch of forensic science that focuses on identifying, acquiring,
processing, analysing, and reporting on data stored electronically. Electronic evidence is a

7 8
component of almost all criminal activities and digital forensics support is crucial for law Software forensics: It is the branch of digital forensics which includes identification,
enforcement investigations. Electronic evidence can be collected from a wide array of sources, collection, analysis and presentation of digital evidences during the investigation of a crime
such as computers, smartphones, remote storage, unmanned aerial systems, shipborne related to software’s only. [5] [6]
equipment, and more. The main goal of digital forensics is to extract data from the electronic
evidence, process it into actionable intelligence and present the findings for prosecution. All
3. The Need for Computer Forensics
processes utilize sound forensic techniques to ensure the findings are admissible in court. [4] Cybercrime causes billions of dollars of economic damage. Because of this, forensic

The first computer crimes were recognized in the 1978 Florida computers act and after science has to evolve to deal with cybercriminals. Computer forensic techniques allow

this, the field of digital forensics grew pretty fast in the late 1980-90’s. It includes the area of investigators to gather evidence against cybercriminals that will stand up in a court of law. [7]

analysis like storage media, hardware, operating system, network and applications. It consists According to a McAfee report from 2014, the economic damage done by cybercrimes
of 5 steps at high level: globally was about $445 billion. The most common type of cybercrime is financial fraud, where
an individual accesses the private data of another and uses it to misrepresent themselves to
Identification of evidence
financial institutions. For example, credit card fraud. [7]
Collection
Because of the rise of cybercrimes, a new branch of investigation has been developed
Analysis to help law enforcement trace and find proof of illegal activity using computers. This is
computer forensics and much of their techniques involved some form of data recovery, it is
Documentation
also known as digital forensics. Computer forensic experts can go through a suspected
Presentation cybercriminal’s hard drive – be it on a computer or a mobile device – and find deleted and
hidden files that serve as evidence of illegal activity. Much of what computer forensics does is
Figure 2.1 Digital Forensic Process
related to data recovery.
2.1 Branches of Digital Forensics

Media forensics: It is the branch of digital forensics which includes identification, 4. Cyber forensics and Digital Evidence
collection, analysis and presentation of audio, video and image evidences during the Digital evidence is information stored or transmitted in binary form that may be relied
investigation process. on in court. It can be found on a computer hard drive, a mobile phone, among other places.
Cyber forensics: It is the branch of digital forensics which includes identification, Digital evidence is commonly associated with electronic crime, or e-crime, such as child
collection, analysis and presentation of digital evidences during the investigation of a cyber pornography or credit card fraud. However, digital evidence is now used to prosecute all types
crime. of crimes, not just e-crime. For example, suspects' e-mail or mobile phone files might contain
critical evidence regarding their intent, their whereabouts at the time of a crime and their
Mobile forensics: It is the branch of digital forensics which includes identification,
relationship with other suspects. In 2005, for example, a floppy disk led investigators to the
collection, analysis and presentation of digital evidences during the investigation of a crime
BTK serial killer who had eluded police capture since 1974 and claimed the lives of at least 10
committed through a mobile device like mobile phones, GPS device, tablet, and laptop.
victims. [8]

Digital forensics essentially involves a three-step, sequential process: [9] [10]


9 10
[3] V. Narayan, “A Brief Introduction to Cyber Forensics,” [Online]. Available:
[Link]
 Seizing the media.
[4] CCF, “Digital forensic,” [Online]. Available: [Link]
 Acquiring the media; that is, creating a forensic image of the media for
work/Innovation/Digital-forensics.
examination.
 Analyzing the forensic image of the original media. This ensures that the [5] GeeksforGeeks, “Digital Forensics in Information Security,” [Online]. Available:
[Link]
original media are not modified during analysis and helps preserve the probative
value of the evidence. [6] EC-Council, “Digital Forensic,” [Online]. Available:
[Link]

5. Forensics Analysis of E-Mail [7] DataNumen, “Computer Forensics,” DataNumen Inc, 9 Oct 2021. [Online]. Available:
[Link]
6. Digital Forensics Life Cycle
[8] NIJ, “Digital Evidence and Forensics,” National Insitute of Justics, [Online]. Available:
[Link]
7. Chain of Custody Concept
[9] N. I. o. Justice, “New Approaches to Digital Evidence Processing and Storage,”. Patent
8. Network Forensics [Link] announcement number NIJ-2014-3727, 6 Feb 2014.

[10] J. G. a. D. G. Martin Novak, “Approaches to Digital Evidence,” National Institute of


9. Approaching a Computer
Justice, 7 Oct 2018. [Online]. Available: [Link]
evidence-acquisition-and-analysis#note1.
10. Forensics Investigation.

11. Forensics and Social Networking Sites: The Security/Privacy Threats

12. Challenges in Computer Forensics.

13. Bibliography

[1] A. University, “CYBER FORENSICS,” [Online]. Available:


[Link]

[2] D. University, “Cyber Security vs. Computer Forensics,” [Online]. Available:


[Link]
[Link]#difference.

11 12

Common questions

Powered by AI

Computer forensics investigations face several challenges, especially with digital evidence management. One primary challenge is maintaining the integrity of evidence; this involves ensuring that digital evidence is not altered or corrupted during the investigation process, which includes proper documentation and chain of custody . Another challenge is the complexity and volume of digital data, which requires efficient tools and methodologies to process large datasets and analyze them within a reasonable timeframe . Additionally, evolving technology and encryption methods can make retrieving and understanding evidence more difficult, requiring continuous updates and training in forensic tools and practices . These challenges necessitate a skillful approach to ensure that evidence remains reliable and admissible.

The digital forensics life cycle manages the preservation and analysis of digital evidence through a structured sequence of steps: identification, collection, analysis, documentation, and presentation. Initially, potential digital evidence is identified and collected in a manner that preserves its original state . The analysis phase involves examining this data to draw meaningful conclusions or insights, often involving the recovery of deleted or hidden information . Documentation ensures all findings are recorded systematically, aiding in the reconstruction of the event timeline. Finally, the presentation stage prepares this comprehensive data for legal proceedings, ensuring its validity and reliability in court . This life cycle is designed to maintain the evidence's integrity and facilitate its admissibility.

Different types of computer forensics contribute uniquely to building a comprehensive legal case by addressing specific areas of potential evidence. For instance, disk forensics focuses on recovering data from storage media, which may include active and deleted files . Network forensics examines network traffic to trace unauthorized access and data exfiltration, crucial for identifying breach paths and culprits . Email forensics retrieves deleted emails to uncover communication patterns and potential incriminations, while malware forensics investigates malicious software to understand the methods used in the attack . Each type of forensics provides distinct evidence that collectively helps construct a robust and detailed legal narrative necessary for cybercrime investigation and prosecution.

The digital forensics process involves several crucial steps: seizing the media, acquiring a forensic image of the media, and analyzing the forensic image. The first step ensures that the original media is preserved without tampering. Creating a forensic image in the acquisition phase allows for an exact copy to be analyzed while leaving the original media intact . Analyzing the forensic image then allows investigators to extract actionable intelligence without modifying the original data, maintaining the admissibility of evidence in court . These steps are essential for ensuring the integrity and probative value of the evidence throughout the investigative and legal process.

Computer forensics and cyber security complement each other by addressing distinct phases of managing cyber incidents. Cyber security focuses on preventing cybercrimes by securing networks and information. This involves using tools like firewalls, vulnerability scanners, and penetration testing to protect systems before breaches occur . On the other hand, computer forensics comes into play after a cyber incident has occurred. Its purpose is to recover data and investigate the breach by identifying, preserving, and analyzing digital evidence to determine the perpetrator and the nature of the attack . Together, they provide a comprehensive approach to both protecting against and responding to cyber threats.

Reverse steganography is a technique used in cyber forensic investigations to uncover hidden data within digital files, images, or recordings. This method involves analyzing the digital media to detect and extract obfuscated information that might be concealed to avoid detection . Cyber forensic specialists employ reverse steganography to reveal critical data related to a case, which might include hidden messages, codes, or files that are embedded within seemingly innocuous digital content. This practice aids in gathering comprehensive evidence and enhancing the understanding of how digital media was used in criminal activities.

Live analysis in cyber forensic investigations is significant because it allows for the examination of a computer's system while it is still running, providing access to volatile data such as RAM that might not be available once the system is powered down . This method can yield immediate insights into ongoing processes and active connections, crucial for understanding the attack vector and perpetrator actions. However, because live analysis interacts directly with the operating system, there are challenges regarding data integrity; any actions taken on the live system might alter existing evidence inadvertently. Hence, cyber forensic specialists must exercise extreme caution to prevent contamination, ensuring their findings remain admissible and reliable in court proceedings.

Expert witness service in computer forensics plays a crucial role by translating complex technical processes into understandable information for judges and juries. Forensics experts are expected to explain how evidence was gathered, the meaning of the digital evidence, and how it is relevant to the legal case in a manner that is comprehensible to individuals without technical expertise . This ensures that the court can make informed decisions based on the technical evidence presented, adding credibility to the forensic findings and supporting the legal arguments effectively.

A chain of custody is essential in digital forensics because it ensures that digital evidence is collected, preserved, and documented in a manner that maintains its integrity and authenticity throughout the investigative process. By meticulously tracking who handled the evidence and at what time, any allegations of evidence tampering or contamination can be countered, preserving its credibility . This procedure is critical in legal proceedings as it establishes the admissibility of the evidence in court by providing a transparent history of the evidence's handling. Without a well-documented chain of custody, there is a significant risk that evidence could be deemed inadmissible, thereby weakening the prosecution's case.

Cyber forensics employs various methodologies to conduct comprehensive investigations, helping to identify cybercriminals and linking them to the crime. These methodologies include reverse steganography for uncovering hidden data, stochastic forensics for examining digital activities without relying on artifacts, and cross-drive analysis to compare data across multiple storage devices . These techniques are crucial in reconstructing digital events and identifying perpetrator actions. Furthermore, live analysis is used to access volatile information in real-time, while deleted file recovery retrieves partially destroyed files to piece together credible evidence. These comprehensive methodologies help in creating a detailed chain of evidence that can be used to reliably identify and prosecute cybercriminals.

1 
 
BCC 301 Cyber Security Notes (Unit 4) 
Table of Contents 
1. Understanding Computer Forensics: Introduction ..........
3 
 
1.1 Computer Forensics vs. Cyber Security 
Cyber security is focused on prevention while computer forensics is about r
5 
 
1.4 Steps for cyber forensic specialists 
Identification: Cyber forensics professionals identify the evidence that is
7 
 
 
 
Data Recovery: Computer forensics experts should be able to safely recover and 
analyze otherwise inaccessible evi
9 
 
component of almost all criminal activities and digital forensics support is crucial for law 
enforcement investigatio
11 
 
 
 Seizing the media. 
 Acquiring the media; that is, creating a forensic image of the media for 
examination. 
 A

You might also like