
ABSTRACT The growth of databases as a means of storing critical data has made them an inviting target for criminal activity, which in turn has brought about the emerging area of database forensics. However, research in this area is just beginning, and few methods and tools designed for database forensic analysis exist at this time. Following a database security incident, it is essential to learn what data was exposed or damaged so that steps can be taken to mitigate the situation. The data cache, Structured Query Language (SQL) cache, and transaction log may contain important database forensic information. Research into database forensics has resulted in the development of some practical methods, as well as opened up potential areas for future database design. The future of database forensics lies not just in development of methods and tools but also in developing a thorough knowledge of database processes in order to advance the developing area of database forensics.
ABSTRACT ABSTRACT We propose an automatic image and thumbnail carving tool called myKarve, which is useful in digital forensics investigation and presentation of evidential information. It is able to carve contiguous and linearly fragmented images caused by garbage, which is tested against three hypotheses to prove its authenticity. These images fall into three categories: images with one or two thumbnails or none at all; thumbnails with headers that do not follow the standard header patterns; and fragmentations caused by garbage. myKarve is designed on a new framework by extending Scalpel features to deal with thumbnail and fragmentation issues. The Validated Joint Photographic Experts Group (JPEG) Header (VJH) list and Address DataBase (ADB) are used to automatically generate work instructions in a work queue to initiate a fully automated image carving process. A shift-key-matching (SKM) technique is used to detect garbage that causes fragmentation in carved images or thumbnails before it can be cleaned. The tool is tested with Digital Forensics Research Work Shop (DFRWS) 2006 and 2007 data sets and images obtained from the Internet. myKarve is found to be a more efficient automated image and thumbnail carver compared to the original Scalpel with the following advantages: detects more headers using validated headers; carves more images and thumbnails by using the newly introduced image patterns; and is able to discard garbage from linearly fragmented images. The results from myKarve are invaluable in the fieldwork of digital forensic analysis and can produce technical evidence of cybercrime activities. Keywords: file carvingfile fragmentationdigital forensicsdigital forensic analysis tooldigital evidenceimage processing ACKNOWLEDGMENT This work was partly supported by University Tun Hussein Onn, Malaysia.
The growth in the computer forensic field has created a demand for new software (or increased functionality to existing software) and a means to verify that this software is truly forensic (i.e., capable of meeting the requirements of the trier of fact). In this work, we present a function-oriented testing framework for validation and verification of computer forensic tools. This framework consists of three parts: function mapping, requirements specification, and reference set development. Through function mapping, we give a scientific and systemical description of the fundamentals of computer forensic discipline; i.e., what functions are needed in the computer forensic investigation process. We focus this article on the forensic copy function. We specify the requirements and develop and a corresponding reference set to test any tools that possess the forensic copy function.
ABSTRACT This article discusses computer--based information and its uses as evidence in legal proceedings. It explains the rules of evidence and their effect on an organization's management of its databases and describes methods of handling requests for production of computerized data.
In any forensic investigation, planning and analysis activities are required in order to determine what digital media will be seized, what types of information will be sought in the examination, and how the examination will be conducted. Existing literature and suggested practices indicate that such planning should occur, but few tools provide support for such activities. Planning an examination may be an essential activity when investigators and technicians are faced with unfamiliar case types or unusually complex, large-scale cases. This article reports the results of empirical studies that evaluate two planning methods for planning computer forensics examinations: an experimental methodology that includes domain modeling and a typical planning method that does not include domain modeling. These studies were conducted to evaluate two research questions: Will the domain modeling of a computer forensics case during the planning phase result in an increased amount of evidence found in a digital forensics examination? Will an experimental “case domain modeling” methodology require a significant amount of additional effort when compared to a typical approach? Three experiment trials were conducted to evaluate the effectiveness of case domain modeling on simulated case scenarios. Analysis of the experiments indicates that case domain modeling in forensics planning requires an additional time investment and it can result in more evidence found during an examination and more effective keyword searches. Additionally, experimental data indicates that case domain modeling is most useful when the evidence disk has a relatively high occurrence of text-based documents and when vivid case background details are available.
The first edition of Harlan Carvey's text on Windows forensics quickly became a standard as an example of both a quality professional reference and a source of a font of practical information on th...
Much has been made of the capabilities to commit a crime that has a digital component, whether it is hacking, fraud, embezzlement, identity theft, organized crime, child pornography, or other criminal act. While the capabilities of the perpetrators and IT professionals' response are often discussed, what is often overlooked is the ability of law enforcement to investigate and prosecute digital crime. An information security plan that is not developed with prosecution as a possible outcome is short sighted. This article is a research report on Michigan's law enforcement capabilities, including training, staffing levels, and trends, and it provides information that will help IT professionals understand the challenges they may encounter when soliciting help from law enforcement agencies.
This essay discusses the nature of transnational organized crime (TOC) and its activities affecting today's electronic landscape. It is assumed that the reader is familiar with IT-related information security in general, and therefore the technicalities around networks and information systems will be avoided as many papers and books cover these subjects extensively. Most security practitioners are familiar with the technical aspects of IT-related attacks (referred to here as cyber attacks or crimes) but not so with the organization and structure of the groups behind these attacks. We will further explore the origins and evolution of TOC, and how it influences and is influenced by today's omnipresent 'speed of thought' digital society.
ABSTRACT Adversary threats to critical infrastructures have always existed during times of conflict, but threat scenarios now include peacetime attacks from anonymous computer hackers. Current events, including examples from Israel and Estonia, prove that a certain level of real-world disorder can be achieved from hostile data packets alone. The astonishing achievements of cyber crime and cyber espionage – to which law enforcement and counterintelligence have found little answer – hint that more serious cyber attacks on critical infrastructures are only a matter of time. Still, national security planners should address all threats with method and objectivity. As dependence on IT and the Internet grow, governments should make proportional investments in network security, incident response, technical training, and international collaboration.
Digital signal processing of sound is a domain with numerous applications in the telecommunications and informatics. These well-developed algorithms of the analysis of sound can be also applied in the field of security systems, where traditional monitoring is still based mainly on video cameras. The commonly used monitoring cameras can be equipped with additional microphones and the audio content can be analyzed by a monitoring program running on a dedicated hardware. This application can automatically detect in the audio stream events like a broken window, gunshot, explosion, or scream. One of the main parts of this system is a parameterization block. In this article two parameterization methods are proposed for this purpose. The first is based on the frequency analysis of the examples of the sound events. The second is based on using a standardized set of audio MPEG-7 and cepstral descriptors. The feature vectors calculated by these two methods have been used for the training of two intelligent classifiers: a support vector machines classifier (SVM) and a neural networks perceptron (NNP). The classifiers have been verified using of the cross-validation method. The results have been compared and conclusions derived. The application of the results in a system working in real conditions is presented and discussed at the end of the article. The work has been done in the frame of the international project “INDECT” (Intelligent Information System Supporting Observation, Searching and Detection for Security of Citizens in Urban Environment).
Although still a relatively new undergraduate course of study at most colleges and universities, specialized degree programs in computer forensics and digital investigations are now becoming available at the graduate level. There appear to be two divergent educational paths for graduate-level education in this field, namely, technology and management. This paper describes Champlain College's online Master's degree program in Digital Investigation Management. The proposed curriculum is described, along with the learning theories and pedagogies that provide the guiding principles for course design. Issues related to the online learning environment and adult learners are also presented.
The adoption of computers into every aspect of modern society has been accompanied by the rise of E-crime. The processes and techniques employed by the field of computer forensics offer huge potential for the extraction and presentation of electronic evidence in a court of law. This article analyzes the legal issues that currently or could potentially impact the computer forensics field from the perspective of experts in Australia.
One of the most interesting aspects of Web 2.0 technologies is how they have been adapted by users in ways not anticipated by the creators of the technology. We, as digital forensic practitioners, have to evolve our methods and approaches in response to both the technologies and their use. But that is “old hat” to us. After all, constant change and challenge are what attract most of us to this field.
A detailed examination of Vista® recycling is given including the effect of recycling on dates and times of files. Forensic implications of Vista recyling are discussed.
Like so many things in our just-in-time world, this book was sent to me just as one of my colleagues was looking for a text for a course he was developing in computer forensics laboratory operations and management. The two lead authors—and contributing author P. Swinburne—bring decades of experience in military and law enforcement environments in Australia and the UK to these topics. The book provides valuable insights that are applicable to digital forensics lab managers in both the public and private sector. Like many aspects of digital forensics, there are several public sector guidelines from around the world for building computer forensics labs. That said, the largest growth in digital forensics staffing and activity is in the private sector, as information security incident response teams, representatives for the defense in criminal investigations, and e-discovery specialists in civil litigation employ a larger number of computer forensics specialists. This book is composed of 24 chapters divided into four sections covering a broad spectrum of topics. Section I is titled, " Creating a Digital Forensics Laboratory " and comprises the first 9 chapters of the book. These chapters cover a range of topics that set down the framework for determining why one is building such a capability in the first place; knowing why you need to build a lab will help immensely in how you design the facility, assemble the resources, and recruit the personnel. The first chapter offers a broad overview of the history and processes of digital forensics, setting the stage at 50,000 ft (or, in deference to the authors, 15,240 m) of what computer forensics is all about. The second chapter delves into the types of digital forensics investigations , including aspects of criminal and civil litigation , e-discovery, and data recovery. These two chapters are essential because they provide the base-line for everything else that follows. The next two chapters offer a checklist of issues to consider when establishing a lab and scoping out the requirements. These chapters discuss topics from the role of the lab within the organization/agency, staffing , and quality assurance to managing evidence, purchasing equipment, and prioritizing the cases. These chapters provide the framework for the rest of the book. The remaining chapters in this section drill deeper into some of the specific topics introduced earlier. Three chapters briefly describe the creation of a business plan for the lab, determining the location for the …
ABSTRACT This paper examines cyberterrorism and its potential to create a postmodern state of chaos. In general, chaos refers to a state of extreme confusion and disorder. This analysis breaks new ground in that it describes chaos theory as a foundation for better understanding cyberterrorism and explains how chaos theory and game theory are tightly coupled. The author also contrasts modern, conventional terrorism with postmodern, innovative cyberterrorism. The main idea is that the postmodern state of chaos caused by cyberterrorist attacks differs dramatically from the destruction caused by conventional terrorist acts. This comparison serves as the basis for making the point that cyberterrorism is not three-dimensional, it is not analog (but it is digital), and it exposes actors of cyberspace to new concepts of time and space. Another important argument is that the postmodern state of chaos implies the danger of cascading failures brought forth by cyberterrorists. A cascading failure is a succession of failures (i.e., cascade) caused by the elimination of a crucial node (i.e., a point or location in an infrastructural system) from a network. This paper is groundbreaking in that it adds fresh, new insights on scholarly perceptions of cyberterrorism. While most of the literature on the subject is technical and political, this paper brings a philosophical outlook to the association between postmodernism and the evolving face of terrorism. This paper begins with a thorough description of cyberterrorism, which refers to attacks conducted against computers, networks, and systems. Of equal relevance is the distinction between cyberterrorism and simple hacking. This paper then proceeds to explain postmodernism, asserting that cyberspace needs to be framed in the context of hyperreal (the blurring of distinctions between the real in the unreal). What comes next is the heart of the paper: the postmodern state of chaos. This paper ends with a discussion that also includes suggestions for future research.
ABSTRACT This article examines cyberterrorism, the use of computers or the Internet against infrastructures whose systems or networks rely on computers or the Internet, and the effects it has on oil and gas utilities, water facilities, and hospitals. The main premise of this analysis is that cyberterrorism is a real threat and represents a continuous struggle. Because such critical health-related infrastructures have become increasingly dependent on computer-based technologies and the Internet, cyberterrorists are potentially a few mouse clicks away from breaching dams, damaging the control systems of hazmat companies, or compromising important hospitals databases.
ABSTRACT Software piracy is widespread because it is simple and inexpensive to copy software programs. The arbitration of software piracy and the interpretation of copyright laws are often grey areas. When called upon to arbitrate in matters of piracy, the judicial system solicits the support of technical experts, who then are typically required to substantiate issues arising from patent and copyright infringements, trade secret misappropriation, and software piracy. Such experts have so far been largely relying on their own experiential and intuitive expertise. This article is an attempt to show how a dedicated expert can supplement such intuitive expertise with objective empirical evidence based on various elements that can be found in the “original” and the “pirated” source codes of the software, to a judicially convincing level. A few formats for presenting the source code comparison results are proposed here, which are convenient to technical experts as well as judicial officers. These formats would help the technical experts to avoid overlooking certain tangible elements of software commonalities that may well be dismissed as insignificant or predictable in the context of management information systems. These formats have been successfully used in the court of law in India by the author for collecting evidence by comparing the original and the pirated software using nonautomated tools. The evidence collected in these formats have been used in the court by the author to supplement the evidence put forward by the automated tools and other physical evidence in order to establish piracy.