Understanding Computer Forensics Guide
Understanding Computer Forensics Guide
Unit 4
Understanding Computer
Forensics
Teach By
Er. Vivek Srivastava
Mob: 9935195999
MCA, MCSE,MCP
Prompt Engineer
Ethical Hacker & Digital forensic expert
Unit – 4 Understanding Computer Forensics
2. Collection: It includes preserving the digital evidences identified in the first step so that they
doesn’t degrade to vanish with time. Preserving the digital evidences is very important and crucial.
3. Analysis: It includes analyzing the collected digital evidences of the committed computer crime in
order to trace the criminal and possible path used to breach into the system.
4. Documentation: It includes the proper documentation of the whole digital investigation, digital
evidences, loop holes of the attacked system etc. so that the case can be studied and analysed in
future also and can be presented in the court in a proper format.
5. Presentation: It includes the presentation of all the digital evidences and documentation in the
court in order to prove the digital crime committed and identify the criminal.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Digital Forensics Important: Digital forensics is commonly thought to be confined to digital and
computing environments. But in fact, it has a much larger impact on society. Because computers and
computerized devices are now used in every aspect of life, digital evidence has become critical to
solving many types of crimes and legal issues, both in the digital and in the physical world.
All connected devices generate massive amounts of data. Many devices log all actions performed by
their users, as well as autonomous activities performed by the device, such as network connections
and data transfers. This includes cars, mobile phones, routers, personal computers, traffic lights, and
many other devices in the private and public spheres.
Digital evidence can be used as evidence in investigation and legal proceedings for:
• Data theft and network breaches—digital forensics is used to understand how a breach
happened and who were the attackers.
• Violent crimes like burglary, assault, and murder—digital forensics is used to capture digital
evidence from mobile phones, cars, or other devices in the vicinity of the crime.
• White collar crimes—digital forensics is used to collect evidence that can help identify and
prosecute crimes like corporate fraud, embezzlement, and extortion.
Digital forensics can be used to identify and investigate both cybersecurity incidents and physical
security incidents. Most commonly, digital evidence is used as part of the incident response process, to
detect that a breach occurred, identify the root cause and threat actors, eradicate the threat, and
provide evidence for legal teams and law enforcement authorities. To enable digital forensics,
organizations must centrally manage logs and other digital evidence, ensure they retain it for a long
enough period, and protect it from tampering, malicious access, or accidental loss.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Objectives of Digital Forensics: Knowing the primary objectives of using digital forensics is essential
for a complete understanding of what is digital forensics:
• It aids in the recovery, analysis, and preservation of computers and related materials for the
investigating agency to present them as evidence in a court of law
• It aids in determining the motive for the crime and the identity of the primary perpetrator
• Creating procedures at a suspected crime scene to help ensure that the digital evidence obtained is
not tainted
• Data acquisition and duplication: The process of recovering deleted files and partitions from digital
media in order to extract and validate evidence
• Assists you in quickly identifying evidence and estimating the potential impact of malicious activity
on the victim
• Creating a computer forensic report that provides comprehensive information on the investigation
process
• Keeping the evidence safe by adhering to the chain of custody
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
HISTORY OF FORENSIC
• 44 BC: Death of an emperor - Julius Caesar is assassinated. Following this event, a physician
performed an autopsy, and determined that of the 23 wounds found on the body, only one was fatal.
• 400 BC: Who determines cause of death(400s) - Germanic and Slavic societies made law that
medical experts must be the ones to determine cause of death in crimes.
• 600 BC: Use of fingerprints for the first time (600s) - Fingerprints first used to determine identity.
Arabic merchants would take a debtor's fingerprint and attach it to the bill.
• First forensic science book - First forensic science manual published by the Chinese. This was
the first known record of medical knowledge being used to solve criminal cases.
• Investigating poisoning 1806s - German chemist Valentin Ross developed a method of detecting
arsenic in a victim's stomach, thus advancing the investigation of poison deaths.
• More physical evidence discovered to work in forensics 1816 - Clothing and shoes of a farm
laborer were examined and found to match evidence of a nearby murder scene, where a young
woman was found drowned in a shallow pool.
• Chemical testing utilized 1836 - James Marsh, an English chemist, uses chemical processes to
determine arsenic as the cause of death in a murder trial.
• Fingerprints found to be unique 1880 - Henry Faulds and William James Herschel publish a
paper describing the uniqueness of fingerprints. Francis Galton, a scientist, adapted their findings
for the court. Galton's system identified the following patterns: plain arch, tented arch, simple loop,
central pocket loop, double loop, lateral pocket loop, plain whorl, and accidental.
• Sherlock Holmes and the coroner 1887 - Coroner's act established that coroners' were to
determine the causes of sudden, violent, and unnatural deaths. Arthur Conan Doyle also publishes
the first Sherlock Holmes story.
• Fingerprint ID used in crime 1892 - Juan Vucetich, an Argentinean police officer, is the first to use
fingerprints as evidence in a murder investigation. He created a system of fingerprint identification,
which he termed dactyloscopy.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
• Criminal features reduced to numerical measurements 1888 - Anthropometry, a system using
various measurements of physical features and bones, used throughout the US and Europe. Using
the system, a criminal's information could be reduced to a set of numbers.
• Investigations into blood markers 1901 - Human blood grouping, ABO, discovered by Karl
Landsteiner and adapted for use on bloodstains by Dieter Max Richter.
• First fingerprint prisoner ID used 1903 – New York state prison system implemented fingerprint
identification.
• Learning about forensics 1909 - First school of forensic science founded by Rodolphe Archibald
Reiss, in Switzerland.
• Guns are unique 1912 - Victor Balthazard realizes that tools used to make gun barrels never leave
the same markings, and individual gun barrels leave identifying grooves on each bullet fired through
it. He developed several methods of matching bullets to guns via photography.
• Crime labs built 1923 - First police crime lab established in Los Angeles.
• Lie detection 1930 - Prototype polygraph, which was invented by John Larson in 1921, developed
for use in police stations.
• Crime experts build lab 1932 - FBI establishes its own crime laboratory, now one of the foremost
crime labs in the world. This same year, a chair of legal medicine at Harvard was established.
• First national crime system 1967 - FBI established the National Crime Information Center, a
computerized national filing system on wanted people, stolen vehicles, weapons, etc.
• Advanced manual fingerprints 1975 - First fingerprint reader installed at the FBI
• Auto fingerprint system first used 1979 - Royal Canadian Mounted Police implement first
automatic fingerprint identification system.
• Advances in DNA lead to conviction (1983-86) - DNA fingerprinting led to conviction of Colin
Pitchfork in the murder of two teenage girls. This evidence cleared the main suspect in the case,
who likely would have been convicted without it.
• DNA catches the criminal 1987 - Tommy Lee Andrews convicted of a series of sexual assaults,
using DNA profiling.
• DNA evidence certified 1996 - National Academy of Sciences announces DNA evidence is reliable.
• Faster fingerprint IDs 1999 - FBI establishes the integrated automated fingerprint identification
system, cutting down fingerprint inquiry response from two weeks to two hours.
• Faster DNA IDs 2001 - Technology speeds up DNA profiling time, from 6-8 weeks to between 1-2
days.
• Footwear detection system 2007 - Britain's Forensic Science Service develops online footwear
coding and detection system. This helps police to identify footwear marks quickly.
• Detection after cleaning 2008 - A way for scientists to visualize fingerprints even after the print has
been removed is developed, relating to how fingerprints can corrode metal surfaces.
• Facial sketches matched to photos 2011 - Michigan state university develops software that
automatically matches hand-drawn facial sketches to mug shots stored in databases.
• 4 second dental match 2011 - Japanese researchers develop a dental x-ray matching system. This
system can automatically match dental x-rays in a database, and makes a positive match in less
than 4 seconds.
• Law of Individuality
• Principle of Comparison
• Principle of Analysis
i) Law of Individuality –
This law states that, “Every object whether natural or man-made has a distinctive quality or
characteristic in it which is not duplicated in any other object,” in other words, no two things in this
universe are alike. Most common example is the human fingerprints; they are unique, permanent
and prove individuality of a person. Even the twins did not have the same fingerprints. Consider
grains of sand, salt, seeds or man-made objects such as currency notes, laptop, typewriter, etc. they
may look similar but a unique characteristic is always present between them. This principle
considered as the most basic elementary unit of Forensic Science. Fingerprints, footprints, tool
marks, obtained from the crime scene are studied and analyzed on the principle of individuality.
This principle emphasizes that, “Everything changes with the passage of time and nothing remains
constant. “ The changing frequency varies from sample to sample and on different objects. The
crime scene must be secured in time otherwise a change in weather (rain, heat, wind), presence of
animals/humans, etc. affects the crime scene.
For example, a road accident on a busy highway may lose all essential evidence if not properly
secured on time.
When samples are not much durable, several complications occur in an investigation as the process
of identification is affected due to the variations in the main features of identification. Without an
appropriate preservative, tissue samples start degrading immediately and they need immediate
analysis.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
This principle was stated by French scientist -Edmond Locard (a pioneer in criminology and forensic
science). Law of exchange states that, “As soon as two things come in connection with each other,
they mutually interchange the traces between them.” Whenever criminal or his weapon/instrument
made connection with the victim or the things surrounding him he left some traces at crime scene
and also picked up the traces from the area or person he has been in contacted with (mutual
exchange of matter). These traces are very helpful for investigation purposes as these traces are
identified by the expert and linked to its original source resulted in the decisive linkage of the criminal
with the crime scene and the victim. This law forms the basis of scientific crime investigation.
For laboratory Investigation this law is very important. The law state that “Only the likes can be
compared”. It highlights the requirement of providing like samples and specimens for evaluation with
the questioned items’.
For example, if the murder is done by a firearm weapon then it is useless to send a knife for
comparison. So, the important condition of this principle is to supply specimen/samples of like nature
for proper assessment with the questioned sample discovered from the crime scene.
5) Principle of Analysis -
This principle states that, “The quality of any analysis would be better by collection of correct sample
and its correct preservation in the prescribed manner”. This leads to better result and avoid
tampering, contamination and destruction of a sample. If you collect a hard disk in a paper bag, it
can be damaged when it falls within the range of a strong electromagnetic field resulted in poor
results. Hence, always appropriate and effective collection and packaging techniques must be used.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
6) Law of Probability -
This law states that, “All identifications (definite or indefinite), made consciously or unconsciously on
the basis of probability.” The perpetrator blood group is also the blood group of various people is
high, but the probability of the same occurring in the case is low. A woman with a tattoo bear on its
right hand and an old injury mark on head is reported missing, an unknown woman is found
murdered with these characteristics then the probability for cops that the unknown corpse is of that
missing woman is high. The probability that the dead body is of another woman will be 1 in millions.
According to this law, “Facts cannot be wrong, they cannot lie not wholly absent but men can and
do.” This law emphasizes the significance of circumstantial facts and supports that a statement given
by a human may or may not be accurate. In an investigation identified and discovered facts are more
accurate and reliable than any eyewitness.
•Identification: Identifying what evidence is present, where it is stored, and how it is stored (in which
format). Electronic devices can be personal computers, Mobile phones, PDAs, etc.
•Preservation: Data is isolated, secured, and preserved. It includes prohibiting unauthorized personnel
from using the digital device so that digital evidence, mistakenly or purposely, is not tampered with and
making a copy of the original evidence.
•Analysis: Forensic lab personnel reconstruct fragments of data and draw conclusions based on
evidence.
•Documentation: A record of all the visible data is created. It helps in recreating and reviewing the
crime scene. All the findings from the investigations are documented.
•Presentation: All the documented findings are produced in a court of law for further investigations.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Advantages of Computer Forensics :
•To produce evidence in the court, which can lead to the punishment of the culprit.
•It helps the companies gather important information on their computer systems or networks potentially
being compromised.
•Allows to extract, process, and interpret the factual evidence, so it proves the cybercriminal action’s in
the court.
•Before the digital evidence is accepted into court it must be proved that it is not tampered with.
•If the tool used for digital forensics is not according to specified standards, then in a court of law, the
evidence can be disapproved by justice.
•A lack of technical knowledge by the investigating officer might not offer the desired result.
What is the Purpose of Digital Forensics? The most common use of digital forensics is to support
or refute a hypothesis in a criminal or civil court:
Criminal cases: Involve the alleged breaking of laws and law enforcement agencies and their
digital forensic examiners.
Civil cases: Involve the protection of rights and property of individuals or contractual disputes
between commercial entities where a form of digital forensics called electronic discovery
(eDiscovery) may be involved. Digital forensics experts are also hired by the private sector as part of
cybersecurity and information security teams to identify the cause of data breaches, data leaks,
cyber attacks and other cyber threats. Digital forensic analysis may also be part of incident response
to help recover or identify any sensitive data or personally identifiable information (PII) that was lost
or stolen in a cybercrime.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Cyber Forensics: Cyber forensics is a process of extracting data as proof for a crime (that involves electronic
devices) while following proper investigation rules to nab the culprit by presenting the evidence to the court.
Cyber forensics is also known as computer forensics. The main aim of cyber forensics is to maintain the thread
of evidence and documentation to find out who did the crime digitally. Cyber forensics can do the following:
•It can determine which user used which system and for how much time.
• Cyber forensics helps in collecting important digital evidence to trace the criminal.
• Electronic equipment stores massive amounts of data that a normal person fails to see. For example: in a
smart house, for every word we speak, actions performed by smart devices, collect huge data which is crucial
in cyber forensics.
• It is also helpful for innocent people to prove their innocence via the evidence collected online.
• It is not only used to solve digital crimes but also used to solve real-world crimes like theft cases, murder, etc.
• Businesses are equally benefitted from cyber forensics in tracking system breaches and finding the attackers.
• Identification: The first step of cyber forensics experts are to identify what evidence is present, where it is
stored, and in which format it is stored.
• Preservation: After identifying the data the next step is to safely preserve the data and not allow other
people to use that device so that no one can tamper data.
• Analysis: After getting the data, the next step is to analyze the data or system. Here the expert recovers the
deleted files and verifies the recovered data and finds the evidence that the criminal tried to erase by deleting
secret files. This process might take several iterations to reach the final conclusion.
• Documentation: Now after analyzing data a record is created. This record contains all the recovered and
available(not deleted) data which helps in recreating the crime scene and reviewing it.
• Presentation: This is the final step in which the analyzed data is presented in front of the court to solve
cases.
[Link]: Digital evidence cannot be seen physically like paper evidence; it exists in electronic form.
[Link]: It can be easily altered, modified, or deleted if proper measures are not taken during collection.
[Link] Replicable: Digital evidence can be copied multiple times without affecting the original.
[Link] Interpretation: Raw digital data needs tools and techniques to make it human-readable.
1. Files and data stored on platforms like Google Drive, iCloud, or AWS.
• Multimedia Evidence:
Example: A photo from a smartphone showing its GPS coordinates linked to a crime location.
The negative side of emails is that criminals may leak important information about their company. Hence, the
role of emails in digital forensics has been increased in recent years. In digital forensics, emails are considered as
crucial evidences and Email Header Analysis has become important to collect evidence during forensic process.
The body of email contains actual message. Headers can be easily spoofed by spammers. Header protocol
analysis is important for investigating evidence. After getting the source IP address we find the ISP’s details. By
contacting ISP, we can get further information like:
•Name
•Address
•Contact number
•Internet facility
•Type of IP address
•Any other relevant information
What can email forensics be used for? Email forensics can be used to investigate a wide range of
crimes, including:
•Fraud: Email can be used to send phishing scams, impersonate legitimate businesses, or commit
other types of financial fraud.
•Cybercrime: Email can be used to spread malware, launch denial-of-service attacks, or steal
sensitive data.
•Employee misconduct: Email can be used to document employee misconduct, such as harassment,
discrimination, or theft.
•Legal disputes: Email can be used as evidence in civil and criminal cases.
Digital Forensics Life Cycle: The digital forensics process is shown in the following figure. Forensic life
cycle phases are:
In order to be processed and analysed, evidence must first be identified. It might be possible that the
evidence may be overlooked and not identified at all. A sequence of events in a computer might include
interactions between:
•Different files
•Log files
In case of a network, the interactions can be between devices in the organization or across the globe
(Internet). If the evidence is never identified as relevant, it may never be collected and processed.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Digital evidence can be collected from many sources. The obvious sources can be:
Proper care should be taken while handling digital evidence as it can be changed easily. Once
changed, the evidence cannot be analysed further. A cryptographic hash can be calculated for the
evidence file and later checked if there were any changes made to the file or not. Sometimes important
evidence might reside in the volatile memory. Gathering volatile data requires special technical skills.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
3. Storing and Transporting Digital Evidence: Some guidelines for handling of digital evidence:
•Image computer-media using a write-blocking tool to ensure that no data is added to the suspect device
•Only use tools and methods that have been tested and evaluated to validate their accuracy and reliability
•Fires
•Floods
Sometimes evidence must be transported from place to place either physically or through a network. Care should
be taken that the evidence is not changed while in transit. Analysis is generally done on the copy of real evidence.
If there is any dispute over the copy, the real can be produced in court.
Many current attacks leave no trace on the computer’s hard drive. The attacker only exploits the information in
the computer’s main memory. Performing forensic investigation on main memory is called live analysis.
Sometimes the decryption key might be available only in RAM. Turning off the system will erase the decryption
key. The process of creating and exact duplicate of the original evidence is called imaging. Some tools which can
create entire hard drive images are:
DCFLdd Iximager Guymager
The original drive is moved to secure storage to prevent tampering. The imaging process is verified by using the
SHA-1 or any other hashing algorithms.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
5. Analysis, Interpretation and Attribution: In digital forensics, only a few sequences of events might
produce evidence. But the possible number of sequences is very huge. The digital evidence must be analyzed to
determine the type of information stored on it. Examples of forensics tools:
•Media analysis
•Application analysis
•Network analysis
•Image analysis
•Video analysis
6. Reporting: After the analysis is done, a report is generated. The report may be in oral form or in written
form or both. The report contains all the details about the evidence in analysis, interpretation, and attribution
steps. As a result of the findings in this phase, it should be possible to confirm or discard the allegations. Some
of the general elements in the report are:
Descriptive list of items submitted for examination Identity and signature of the examiner
Experts with inadequate knowledge are sometimes chastised by the court. Precautions to be
taken when collecting digital evidence are:
•No action taken by law enforcement agencies or their agents should change the evidence
•When a person to access the original data held on a computer, the person must be competent to do so
•An audit trial or other record of all processes applied to digital evidence should be created and
preserved
•The person in-charge of the investigation has overall responsibility for ensuring that the law and these
are adhered to
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Chain of Custody: A chain of custody is the process of validating how evidences have been gathered, tracked,
and protected on the way to the court of law. Forensic professionals know that if you do not have a chain of
custody, the evidence is worthless.
The chain of custody is a sequential written record of those individuals who have had custody of the evidence
from its initial acquisition to its final disposition. A chain of custody begins when an evidence is collected and
the chain is maintained until it is disposed off. The chain of custody assumes continuous accountability.
The Chain of custody standards is usually set by following the National Institute of Standards and Technology
(NIST) or Cybersecurity Framework (CSF) guidelines in an organization to address risk and improve the
security of the infrastructure.
Preserving the asset or evidence of an organization requires the chain of custody to start from the collection of
that evidence, its analysis, reporting, and till it’s presented in court. Evidence is usually altered (such as the
timestamps or metadata associated) as it is transferred to different people or different organizations, so
documenting its state right from the point of the collection becomes necessary.
After an incident, the chain of custody starts from the collection of evidence and its state. Each acquired piece
of evidence is to be labeled with its source, the time of its collection, where it is stored, and who has access to
it. All of this is documented to preserve the integrity of the evidence.
Step 3. Analysis: The collected evidence is then transferred for analysis, and again, each step of the analysis is
recorded. Analysts use digital forensics tools to reconstruct the background of the evidence and draw unbiased
conclusions, which are documented.
Step 4. Reporting: The final stage is to report the findings to the court in a professional digital forensics
report, following standards set by organizations such as the National Institute of Standards and Technology
(NIST). The report covers key aspects of the chain of custody, which include: the tools used to collect and
process the evidence, the chain of custody statement, a list of the data sources, identified issues and
vulnerabilities, and the next possible steps to take. All of this adds to the authenticity and viability of the
evidence and makes it presentable to the court.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
The basic things to be present in the chain of custody form:
By analyzing records of network events provided by network forensics, law enforcement agencies and
cybercrime investigators can piece together communications and timelines to better understand what happened
during a crime or other mysterious event. Analysts check for evidence of human communication, file
tampering, and keyword usage, among other indicators.
Identification: First, decide what you need to look at. This helps you know what information to collect and
what tools to use. This step is very important for the whole process.
Preservation: Next, keep the evidence safe. Make copies of important data and store them securely. Collect
data in a way that keeps it unchanged. Use tools like Autopsy or Encase to keep the evidence safe.
Collection: Now, gather the data. You can do this by hand or with special tools. It’s often best to use both
ways. By hand, you look at each file. With tools, you use software to check network traffic and get data.
Examination: Look closely at the collected data. Check for unusual things that might show a security problem.
Look at the data and its details. Check for signs that something bad happened, like strange IP addresses or file
names.
Analysis: Use the information from network traffic to figure out what happened. Use special software to watch
network activity. These tools also look at records to spot problems.
Presentation: Share what you found. Write a report or give a talk. Include all important information, like proof
of someone breaking in or doing bad things. Suggest ways to make things safer. Be ready to answer questions.
Incident Response: Use what you learned to deal with the problem. Try to limit damage, find the main cause,
and fix it. Take steps to stop it from happening again. The plan should try to keep the system running, save
data, and protect the organization.
1. Packet capture tools: These catch and save network data to look at later. They show what’s moving on the
network. Examples are Wireshark, TCPDump, and Arkime. These tools let you see the content of network
messages.
2. Full-packet capture tools: These save all the data that goes through a network. They don’t miss anything.
NetWitness Investigator and RSA NetWitness Platform are examples. They’re good for deep checking of
network traffic.
3. Log analysis tools: These help look at records from network devices. Splunk, ELK Stack, and Graylog are
examples. They can find patterns in lots of records quickly.
5. SIEM tools: These show all the records from different network devices in one place. Splunk Enterprise
Security and IBM QRadar are examples. They help spot problems across the whole network.
6. Digital forensics platforms: These do everything from getting data to making reports. RSA NetWitness
Platform and Splunk Enterprise Security are examples. They’re all-in-one tools for network checking.
7. Intrusion detection system tools: These watch for bad things on the network and warn about them. Snort
and Suricata are examples. They help stop attacks before they cause problems.
A computer forensics investigation procedure starts with identifying the resources and
devices that hold data that will be the subject of the inquiry. Investigational data may be
found on personal devices like tablets and mobile phones, or any equipment i.e. used by
users, such as PCs or laptops. After that, these devices or gadgets are seized and sealed
off to prevent any potential for manipulation of data. If the data is stored on a server,
network, or cloud, the organization or investigator must guarantee that access to it is
restricted to the investigating team only.
After identifying and isolating the devices in inquiry, as well as copying and securely storing the data, digital
forensic investigators employ a range of methodologies to retrieve relevant data and scrutinize it, seeking out
clues or proof that suggests misconduct. This frequently entails seeking to recover and inspect erased, corrupted,
or encrypted files through the use of techniques like:
•Reverse Steganography: It is a technique that is mainly used for extracting hidden info by looking at the hash
or character string behind an image or other piece of data.
•Data Carving or Deleted File Recovery: It is a process of identifying and retrieving erased or deleted files by
looking for any fragments that the deleted files could have left behind.
After the analysis phase is completed, the investigation's results are accurately
documented in a manner that facilitates visualizing the complete inquiry process and
its conclusions. A chronology of the actions that caused misconduct, such as data
breaches, data leaks, financial crime, cyber espionage, or network breaches, may
be created with the use of proper documentation.
Once all the above phases are complete, the results or findings are submitted to the
committee or court that will decide how to proceed with a lawsuit or internal
complaint. Investigators using computer forensics can serve as expert witnesses,
providing a summary and presentation of the evidence that they gathered and sharing
their conclusions.
Due to the rapid spread of internet use all over the world, email has become a primary communication
medium for many official activities. Not only companies, but also members of the public tend to use emails in
their critical business activities such as banking, sharing official messages, and sharing confidential files.
However, this communication medium has also become vulnerable to attacks. This article focuses on email
architecture and existing investigation techniques used by forensic investigators.
Email Architecture
When a user sends an email to a recipient, this email does not travel directly into the recipient’s mail server.
Instead it passes through several servers. The MUA is the email program that is used to compose and read the
email messages at the client end. There are multiple MUAs available such as Outlook express, Gmail, and
Lotus Notes. MTA is the server that receives the message sent from the MUA. Once the MTA receives a
message it decodes the header information to determine where the message is going, and delivers the message
to the corresponding MTA on the receiving machine. Every time when the MTA receives the message, it
modifies the header by adding data. When the last MTA receives the message, it decodes it and sends to the
receiver’s MUA, so the message can then be seen by the recipient. Therefore an email header has multiple
pieces of server information, including IP addresses.
Email architecture comprises three basic components: a sender, intermediate servers, and a recipient. There are
applications and servers in place that help with the communication between these components. They are:
•MUA User agents: The mail user agent or the email client is an application that facilitates the drafting,
sending, and receiving of emails. Popular email clients include Google, Yahoo, and Outlook. Once an email is
sent, it will be transferred to the MUA's server.
•MSA Mail submission agents: The mail submission agent is the email client's server, which receives the
message and transmits it to the next step. If the authentication mechanisms are in place, an email's contents
will be scrutinized while the email is with the MSA.
•MTA Mail transfer agents (MTAs): The mail transfer agent then proceeds to relay the message to the
recipient mail server. If the recipient client is the same as the sender, the mail will automatically be relayed to
the recipient's delivery server. However, if the recipient is hosted on a different server, then the MTA will relay
the message to the corresponding MTA, which will then transfer the message to the recipient.
•MDA Mail delivery agents (MDAs): Once the email ends up in the necessary MTA, it will be handed over to
the mail delivery agent, where it will be converted to user-readable format. The email will then be transferred
to the recipient's MUA, and from there it will be fetched by the recipient.
•Delivery protocol: Rules dictating which emails will be sent between the sender and recipient.
•Access protocol: Rules that aid with email retrieval from either the sending server or the receiving server.
Mail delivery protocol: The standard used to transmit messages between servers is called the Simple Mail
Transfer Protocol (SMTP). SMTP helps transmit messages from the sending server to the recipient. At its most
basic level, the SMTP protocol is used during the interaction between the following components:
•The user
•The SMTP server
•The receiver
The communication between components occurs using a set of SMTP commands (e.g., EHLO, MAILFROM,
etc.). A back-and-forth interaction occurs using these commands until the email is transferred to the [Link]
the email reaches the recipient server, the recipient will be ready to collect it.
Email forensics refers to analyzing the source and content of emails as evidence. Investigation of email related
crimes and incidents involves various approaches.
Header Analysis: Email header analysis is the primary analytical technique. This involves analyzing metadata in
the email header. It is evident that analyzing headers helps to identify the majority of email-related crimes. Email
spoofing, phishing, spam, scams and even internal data leakages can be identified by analyzing the header.
Server Investigation: This involves investigating copies of delivered emails and server logs. In some
organizations they do provide separate email boxes for their employees by having internal mail servers. In this
case, investigation involves the extraction of the entire email box related to the case and the server logs.
Network Device Investigation: In some investigations, the investigator requires the logs maintained by the
network devices such as routers, firewalls and switches to investigate the source of an email message. This is
often a complex situation where the primary evidence is not percent (when the ISP or proxy does not maintain
logs or lacks operation by ISP ).
Software Embedded Analysis: Some information about the sender of the email, attached files or documents
may be included with the message by the email software used by the sender for composing the email. This
information may be included in the form of custom headers or in the form of MIME content as a Transport
Neutral Encapsulation Format (TNEF).
Sender Mail Fingerprints: The “Received” field includes tracking information generated by mail servers that
have previously handled a message, in reverse order. The “X-Mailer” or “User-Agent” field helps to identify
email software. Analyzing these fields helps to understand the software, and the version used by the sender.
When people talk about a computer network they generally are referring to a group of computer systems linked
together. Within the network each computer system or device is called a node. The idea behind a social
network is similar, only the nodes are generally individuals, groups or organizations. Social networking services,
also called social networking sites (SNS), are designed to build upon interactions to create communities of
people online, and provide the required software to do this. Web-based social networking spaces offer a way
for individuals or groups to create profiles and share images, videos, thoughts, and other types of posts with
other members of the social networking space. The specific site also provides a variety of ways for users to
communicate with others within that network, such as instant messaging and chat rooms, e-mail or site mail
(used only use through the service), notes and blogs, file sharing, forums or other types of discussion groups,
videos, and so on.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
• Some security aspects related to Social Networking Sites are: The following are some common risks and
threats associated with social media security:
• Unauthorized access: the unauthorized infiltration of personal or corporate social media accounts by hackers
or other bad actors, which could result in data breaches or the improper utilization of information
• Phishing attacks: the act of deceitfully trying to acquire sensitive information, such as passwords or personal
details, through impersonation of genuine entities or creation of fake profiles
• Malware and viruses: malicious links or infected files can spread malware and viruses through social media
platforms, compromising the security of devices and networks
• Privacy breaches: inadequate privacy settings or unintentional sharing of personal information can expose
individuals to privacy violations, identity theft or online stalking
• Social engineering: manipulation techniques employed by cybercriminals to deceive users into revealing
confidential information or performing actions that compromise security
• Account hijacking: the unauthorized takeover of social media accounts, often for malicious purposes,
leading to identity theft, dissemination of harmful content, or fraudulent activities
• Data mining and tracking: social media platforms collect and analyze user data for targeted advertising or
third-party purposes, potentially compromising privacy and personal information
• Fake accounts and scams: creation of fake profiles or fraudulent schemes on social media, aiming to deceive
users into providing personal information, financial details or engaging in fraudulent activities.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Types of Social Networking Platforms : Social media consists of many types of networks for people who engage
in a variety of different interests. Marketing and advertising on social media are economical and effective, helping
you to connect with a wider audience. Learning about the popular types of social media can help you create more
specific, meaningfully targeted marketing campaigns.
1. Facebook: called nicknames andLaunched in February 2004, Facebook is the leading social networking site
with over 2.9 billion monthly active users (MAU) as of July 2022. Users can add friends, send messages,
share videos and pictures and update personal profiles and these are what makes this site very popular.
2. YouTube: This is a video sharing site launched in February 2005. Users can upload, share, view and using
third party applications download videos which are in flash format. Most contents on this site are uploaded by
individuals and this is the reason behind its success in the last 5 years.
3. MySpace: MySpace is a social networking site and it is owned by News Corporation. MySpace allows its
members to stay anonymous using screen names also just like Facebook, users can have profiles, upload
pictures, share notes and chat online.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
4. Twitter: Founded in 2006, Twitter is a social networking and microblogging service website that enables its
users to send and read messages from other users they are following, also called tweets. The popularity of twitter
arose due to its simplicity and compatibility with sms.
5. Flickr : Flicker is a video and image hosting site, online community and web services suite launched in
February 2004. It is widely used by users to share images and videos and for bloggers to host images that are
embedded in social media and blogs.
6. Photobucket: This is a slideshow creation, video hosting, photo sharing and image hosting website founded in
2003. It is more popular for use in remote storage of avatars displayed on internet forums, personal photographic
albums and storing videos. Users can keep their albums private, password protected access or open to the public.
7. LinkedIn: This is a business oriented social networking site. It was founded in 2002 and launched in May 2003
and mostly used for professional networking. It has over 75 million registered users from over 200 countries and
territories all over the world. It is available in German, English, Portuguese, French, Spanish and Italian.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
8. Digg: Digg is a social news website where users are allowed to vote for stories (digg) to promote them. It
started out as an experiment in November 2004 and has become very popular for the reason that it now features
friend’s’ lists, the ability to digg any story and great interface.
9. Ning: Ning is an online platform where users can create their own social networks. It started out in October
2004 but was launched publicly in October 2005. Users can use the service for free or upgrade to paid accounts.
10. Yelp: Yelp (a contraction of Yellow pages) features social networking, local search and user review
services. As of early 2010, it had over 31 million monthly unique users and is commonly used by people as a local
research website. It was founded in October 2004.
11. Tagged: This is a social networking website that allows users to play games, share virtual gifts and tags and to
suggest and meet new people with similar interests. It has been around since 2004 and has over 26 million monthly
users all over the world.
21. Friendster: Friendster was founded in 2002 and it Is a social networking site that enables users to contact other
users, maintain contacts and share online content and media with them. It is also a dating website and used to
discover new events, hobbies and bands.
22. Flixster: This is a social movie site where users share movie ratings, meet new people with similar movie tastes
and discover new movies. It was founded in 2005 and has been the parent of website Rotten Tomatoes from
January 2010.
23. Xanga: Xanga is a site that hosts photoblogs, weblogs and social networking profiles of its members. It was
started in 2009 as a site to share music and book reviews but now has over40 million all over the world.
1. Facebook
2. Instagram
3. Twitter
4. LinkedIn
1. Online Threats, Stalking, Cyber bullying: The most commonly reported and seen crimes that occur on
social media involve people making threats, bullying, harassing, and stalking others online. While much of this
type of activity goes unpunished, or isn`t taken seriously, victims of these types of crimes frequently don`t know
when to call the police. If you feel threatened by a statement made online about you, or believe that the threat is
credible, it`s probably a good idea to consider calling the police.
2. Hacking and Fraud: Although logging into a friend`s social media account to post an embarrassing status
message may be acceptable between friends, but technically, can be a serious crime. Additionally, creating fake
accounts, or impersonation accounts, to trick people (as opposed to just remaining anonymous), can also be
punished as fraud depending on the actions the fake/impersonation account holder takes.
3. Buying Illegal Things: Connecting over social media to make business connections, or to buy legal goods
or services may be perfectly legitimate. However, connecting over social media to buy drugs, or other
regulated, controlled or banned products is probably illegal.
4. Vacation Robberies: Sadly, one common practice among burglars is to use social media to discover when a
potential victim is on vacation. If your vacation status updates are publicly viewable, rather than restricted to
friend groups, then potential burglars can easily see when you are going to be away for an extended period of
time.
Importance
• Criminal Investigations: Helps in tracking activities, establishing alibis, and identifying suspects.
• Cybersecurity: Provides insights into phishing, data breaches, and other cyberattacks initiated through
social media.
• Corporate and Civil Cases: Aids in resolving intellectual property disputes, defamation cases, and HR
issues like harassment or misconduct.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Challenges
• Privacy Laws: Navigating laws like GDPR and other regional regulations.
• Platform Restrictions: Dealing with limited access to APIs or restricted data policies.
[Link] Tampering and Manipulation: Refers to the unauthorized alteration of digital data, often to mislead
investigators or modify outcomes. Examples include editing timestamps, changing file metadata, or injecting
false information into records.
[Link] Theft and Unauthorized Access: The act of stealing sensitive or confidential information without
permission. Unauthorized access often leads to data breaches, identity theft, or misuse of intellectual
property.
3. Insider Threats: Risks posed by individuals within an organization who misuse their access to data or
systems. This may be intentional (e.g., sabotage) or unintentional (e.g., negligence).
4. Malware and Exploits: Malicious software or code that exploits vulnerabilities in systems. Examples
include ransomware, spyware, and zero-day exploits that can compromise evidence or disrupt forensic
processes.
5. Chain of Custody Violations: Occur when the proper documentation and secure handling of evidence
are not maintained, jeopardizing its integrity and admissibility in court.
6. Network Sniffing and Interception: Unauthorized monitoring or capturing of data transmitted over a
network. Without encryption, this data can be intercepted, altered, or stolen.
8. Data Remnants and Incomplete Deletion: Residual data left on storage devices after deletion. This can
lead to inadvertent exposure of sensitive information or recovery of evidence during investigations.
9. Social Engineering and Phishing: Techniques used to deceive individuals into revealing sensitive
information, such as passwords or access credentials. These attacks exploit human psychology rather than
technical vulnerabilities.
[Link]-border Jurisdiction and Legal Challenges: Challenges arise when investigations involve data
stored in different countries, as laws governing access and privacy vary significantly between
jurisdictions.
Er. Vivek Srivastava
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
[Link] Authentication and Access Controls: Weak or poorly implemented security measures that
fail to prevent unauthorized users from accessing sensitive systems or data.
[Link] and Authenticity of Evidence: Ensuring that evidence remains unaltered and authentic
throughout its lifecycle, from collection to presentation in court, is critical for its credibility.
[Link] Privacy Violations: Breaches of regulations or ethical standards concerning the collection, storage,
or use of personal data. Examples include unauthorized access to private communications or sharing
sensitive user information without consent.
•Real-time data requires ability to capture and analyze data on the fly
•A protocol might also involve multiple layers of signal (VoIP, HTTP tunneling)
Er. Vivek Srivastava
•Current forensic tools will not be able to handle real-time data and huge amount of data
Mob: 9935195999
Unit – 4 Understanding Computer Forensics
Challenges Facing in Computer Forensics
• One of the key challenges is the increasing complexity of cloud and edge computing environments. These
environments offer benefits such as data computation and storage, faster understanding and actions, and
continuous operation. However, they also present technical challenges for computer forensics due to their
complexity and key features. The heterogeneity of ICT technologies and the volume of information in these
environments further compound the challenges.
• Another challenge in computer forensics is the proliferation of Internet of Things (IoT) devices. Smartphones,
in particular, have become prevalent in legal and corporate investigations. However, forensic analysis of
smartphones is challenging due to their limited interfaces for retrieving information of forensic value.
Electromagnetic side-channel analysis has been proposed as an alternative method for acquiring forensic
insights from smartphones and other IoT devices.
• Anti-Forensic Techniques: Cybercriminals will select the anti-forensic tools and technique to cover their
traces, making investigation much more difficult
• Jurisdictional Issues: Cybercrimes will be difficult to solve because they can happen in different countries,
and that can make it much more difficult to figure out who should be in charge of the investigation.
• Data Volume: There are more and more digital data getting day by day and it is getting harder to work with
data and understand all the data
• Privacy Concerns: Finding the correct balance between collecting digital proof and respecting people’
privacy will be tricky matter