
Storage as a Service (SaS) platforms provide users with a convenient and cost effective way to store and share data. The scale and distribution of data in SaS is such that existing signature detection techniques are not suited to the task of analysing data in these platforms. To maintain a practical and effective digital forensic capability, a new approach to the detection of target data in such platforms is required. This paper analyses the potential impact of the widespread use of SaS in particular object storage platforms, has on digital forensic investigations and identifies the key challenges to be overcome. The focus of the paper is the development of a model to distribute the signature detection process in a way that minimises the quantity of resources required to carry out signature detection while at the same time maintaining the accuracy of current techniques and achieving signature detection within appropriate temporal boundaries.
The importance of digital forensics is on a steady rise. One of the biggest challenges posed to digital forensics is the identity challenge. The authors define the identity challenge as the difficulty to prove beyond reasonable doubt in a court of law that a specific person was using a specific identity of a digital subject at a certain time. In order to meet or at least decrease this challenge, organised action within the digital forensics field is needed. The authors propose a set of requirements to be introduced within digital forensics in order to help solve this issue. These requirements include the following: defining the principles of digital identity within digital forensics; introducing strong authentication methods for all information systems and electronic devices; introducing digital signatures for all transactions within information systems and electronic devices; constant interaction with other relevant fields and last but not least, putting an end to internet anonymity. The authors believe that, if implemented, the proposed requirements would not only bring about the higher admissibility of digital evidence related to digital identity in a court of law, but also increase the efficiency of digital forensic investigations.
In this paper we argue that optimization in terms of forensic readiness should be performed in a controlled and structured manner, taking under consideration the current situation an organization is in. We reflect upon well known practices relating to process maturity and investigate the feasibility and appropriateness of adopting such approaches in order to express forensic readiness. Levels of forensic readiness are defined by using a 0 to 5 scale. By using a fictitious example of an organization’s website, which suffers a security breach, we examine how forensically ready the organization is. From this exercise we conjecture that an organization cannot develop or adopt solely generic forensic readiness assessment practices, but there is a need for tailoring.
Graphic design applications are often used for the editing and design of digital art. The same applications can be used for creating counterfeit documents like identity documents (IDs), driver’s licenses or passports among others. However the use of any graphic design application leaves behind traces of digital information which can be used during a digital forensic investigation. Current digital forensic tools examine a system to find digital evidence but they do not examine a system specifically for the creating of counterfeit documents. This paper reviews the digital forensics analysis process involved in the creation of counterfeit documents by determining and corroborating the events that previously occurred. The analysis is achieved by associating the digital forensic information gathered to the possible actions taken, precisely, the scanning, editing, saving and printing of counterfeit documents. The digital forensic information is gathered by analyzing the files generated by the particular graphic design application used for document creating. Another analysis is conducted on user generated files, the actual files that can be used as potential evidence to establish file structural contents and the relationship with the associated actions. This involves analyzing the user generated files associated with these applications and determining their signatures and related metadata. Contextually, the authors illustrate an evaluation disclosing the digital forensic evidence gathered from graphic design applications.
Forensics profiling refers to the study and exploitation of traces in order to draw a profile relevant to the investigation about criminal or litigious activities. While traces may not be strictly dedicated to a court use, they may increase knowledge of the subject under investigation. In this context we will study the evidence found in a modern ebook reader, and we will explain how it could be used during an investigation to help understand the profile and the habits of its owner by building a reliable timeline of all the interactions between the user and the device. We use as an example a modern ebook reader, the Sony Touch PRS-650, of which we present a complete profiling made with custom software.
Although very little amount of research has been done on database forensics, current research has tacitly focused on digital examination and reconstruction of databases from a number of dimensions. The general assumption is that only one of these dimensions needs to be handled during database forensics investigations. This paper analyses the dimensions in which research in database forensics has been focused on and uses these to reveal the different aspects of database forensics which are yet to be explored. The paper also elaborates on the tools and techniques currently being used in database forensics analysis process and highlights some of the challenges being faced in database forensics research and practice as they relate to the dimensions implied by current research in database forensics.
A Database Management System (DBMS) consists of metadata and data. The metadata influences the way the data is presented to the user and this presents various forensic complications. The data model can be viewed as the highest level of metadata which governs the way other metadata and data in the DBMS are presented to the user. The data model can be modified to hide or tamper with forensic evidence. In this study the focus is on the data model of the DBMS and arguments are provided to indicate why the data model is an important consideration when conducting a forensic investigation on a DBMS. Various methods are presented to transform the data model into a desired state for a forensic investigation and these methods are measured against set out criteria. No one method is adequate for every forensic investigation. A forensic investigator should understand the various methods and select the correct data model state and method to convert the data model into that required state.
The increasing use of social media, whereby users interact online, ensures that it will provide a useful source of evidence for the forensics examiner. Due to the dynamic nature of this environment, current approaches for its analysis are not without their limitations. This paper posits a novel inter-disciplinary methodology for the forensic analysis of user interaction with social media. In particular, it presents an approach for the quantitative analysis of user engagement to identify relational and temporal dimensions of evidence that will be relevant to an investigation. In this way, it may be used to support the identification of individuals who might be ‘instigators’ in a criminal event orchestrated via social media, or a means of potentially identifying those who might be involved in the ‘peaks’ of activity. In order to demonstrate the applicability of this methodology, this paper applies it to a case study of users posting to a social media Web site.
Microsoft Word and Skype are widespread applications in our daily IT life. Up to now, if a computer forensic examination is required, the majority of forensic investigators tends to use commercial software to analyse this application-specific data. However, commercial software is rather expensive and typically closed-source. This paper aims at exploring if an applicationspecific forensic investigation is feasible by using free available software and whether its findings then still meet the investigators' demands. We contribute to this question by developing a guideline for the forensic investigation of Microsoft Word binary files (aka .doc files) and Skype chat log files. Solely free of charge available tools are proposed for use. In addition, we develop a Python-based, platform independent tool to enable a more in-depthanalysis of .doc-metadata. This tool does not rely on any third-party application libraries (e.g. Microsoft APIs (Application Programming Interfaces)). Furthermore we optimise an existing tool for analysing Skype's .dat files by reverse-engineering the file's structure. Finally, we present a questionnaire completed by 4 experienced practitioners. In spite of the small number of participants their answers underline that our approach meets their needs.
Due to its convenience and low cost, short message service (SMS) has been a very popular medium of communication for quite some time. Unfortunately, however, SMS messages are sometimes used for reprehensible purposes, e.g. communication between drug dealers and buyers, or in illicit acts such as extortion, fraud, scams, hoaxes, and false reports of terrorist threats. In this study, we perform a likelihood-ratio-based forensic text comparison of SMS messages focusing on lexical features. The likelihood ratios (LRs) are calculated in Aitken and Lucy’s (2004) multivariate kernel density procedure, and are calibrated. The validity of the system is assessed based on the magnitude of the LRs using the log-likelihood-ratio cost (Cllr). The strength of the derived LRs is graphically presented in Tippett plots. The results of the current study are compared with those of previous studies.
The need for an automated approach to forensic digital investigation has been recognized for some years, and several authors have developed frameworks in this direction. The aim of this paper is to assist the forensic investigator with the generation and testing of hypotheses in the analysis phase. In doing so, the authors present a new architecture which facilitates the move to automation of the investigative process; this new architecture draws together several important components of the literature on question and answer methodologies including the concept of 'pivot' word and sentence ranking. Their architecture is supported by a detailed case study demonstrating its practicality.
With the advent of Information and Communication Technologies, the means of committing a crime and the crime itself are constantly evolved. In addition, the boundaries between traditional crime and cybercrime are vague: a crime may not have a defined traditional or digital form since digital and physical evidence may coexist in a crime scene. Furthermore, various items found in a crime scene may worth be examined as both physical and digital evidence, which the authors consider as hybrid evidence. In this paper, a model for investigating such crime scenes with hybrid evidence is proposed. Their model unifies the procedures related to digital and physical evidence collection and examination, taking into consideration the unique characteristics of each form of evidence. The authors' model can also be implemented in cases where only digital or physical evidence exist in a crime scene.
With the increasing scale of digital forensic investigations, there is a need for approaches that are capable of reducing the quantities of data forensic examiners are required to search. As this trend continues, traditional quiescent digital forensic analysis is in some cases becoming impractical; examiners must often rely on an in-situ investigation of the live computing environment. Numerous approaches to live digital forensic evidence acquisition have been proposed in the literature, but relatively little attention has been paid to the problem of identifying how the effects of these approaches, and their improvements over other techniques, can be evaluated and quantified. In this paper, we present Pypette, a novel framework enabling the automated, repeatable analysis of live digital forensic acquisition techniques.
Advancement in disk technology led to the development of hard disks of terra byte sizes. Users have the option to divide the storage into a number of partitions based on the nature of uses. In case of Master Boot Record partitioning scheme, whenever a partition is created, the complete track containing MBR/EMBR of the storage media is reserved to store boot information and partition table information. But this information requires only the first sector of the track. The remaining sectors in that track cannot be used for any other purpose, as the file system cannot access these free sectors and hence, the chances of overwriting these sectors are very low. So, this area can be used to hide any critical information. The user will get a large amount of storage space for hiding data depending on the number of partitions. This area becomes an important area in Forensics Analysis. In this paper, first we describe the details of data hiding in unused areas, which cannot be easily overwritten by the Operating Systems and how it can be analysed using standard cyber forensics software. Analysing such areas using cyber forensics tools may give lot of valuable information and also will lead to reduce the criminals in hiding information.
In this paper we examine the feasibility of developing a forensic acquisition tool in a distributed file system. Using GFS as a vehicle and through representative scenarios we develop forensic acquisition processes and examine both the requirements of the tool and the distributed file system must meet in order to facilitate the acquisition. We conclude that cloud storage has features that could be leveraged to perform acquisition (such as redundancy and replication triggers) but also maintains a complexity, which is higher than traditional storage systems leading to a need for forensic-readiness-by-design.
The field of wireless sensor networking is a new and upcoming one and unfortunately still lacking as far as digital forensics is concerned. All communications between different nodes (also known as motes) are sent out in a broadcast fashion. These broadcasts make it quite difficult to capture data packets forensically whilst retaining their integrity and authenticity. This paper examines the differences between IEEE 802.15.4 wireless sensor networks and IEEE 802.11x wireless networks when it comes to implementing digital forensic readiness within the network environment. It focuses on the differences in the communication protocol, proof of authenticity and integrity, time stamping, modification of the network after deployment and other differences between IEEE 802.15.4 wireless sensor networks and IEEE 802.11x wireless networks. Each of these elements is discussed, after which a table is provided that shows the specific requirements to be taken into account when proposing digital forensic readiness in a wireless sensor network environment.
'Logging User Actions in Relational Mode' (LUARM) is an open source audit engine for Linux. It provides a near real-time snapshot of a number of user action data such as file access, program execution and network endpoint user activities, all organized in easily searchable relational tables. LUARM attempts to solve two fundamental problems of the insider IT misuse domain. The first concerns the lack of insider misuse case data repositories that could be used by post-case forensic examiners to aid an incident investigation. The second problem relates to how information security researchers can enhance their ability to specify accurately insider threats at system level. This paper presents LUARM's design perspectives and a 'post mortem' case study of an insider IT misuse incident. The results show that the prototype audit engine has a good potential to provide a valuable insight into the way insider IT misuse incidents manifest on IT systems and can be a valuable complement to forensic investigators of IT misuse incidents.
Navman devices can provide a wealth of information to forensic investigators and could prove to be vital to an investigation. In this paper we focus on one Navman device, including what information is left behind on the device and how that information can be interpreted into meaningful data that can be used by a forensic investigator.
This paper presents a novel method of JPEG image steganalysis. Our approach is driven by the need for a quick and accurate identification of stego-carriers from a collection of files of different formats, where there is no knowledge of the steganography algorithm used, nor previous database of suspect carrier files created. The suspicious image is analysed in order to identify the encoding algorithm while various meta-data is retrieved. An image file is then reconstructed in order to be used as a measure of comparison. A generalisation of the basic principles of Benford’s Law distribution is applied on both the suspicious and the reconstructed image file in order to decide whether the target is a stego-carrier. We demonstrate the effectiveness of our technique with a steganalytic tool that can blindly detect the use of JPHide/JPseek/JPHSWin, Camouflage and Invisible Secrets. Experimental results show that our steganalysis scheme is able to efficiently detect the use of different steganography algorithms without the use of a time consuming training step, even if the embedding data rate is very low. The accuracy of our detector is independent of the payload. The method described can be generalised in order to be used for the detection of different type images which act as stego-carriers.
Cloud computing is an emerging model of computing that offers elastic scalable computing resources to many concurrent users worldwide. It provides resources that are paid for as they are consumed, dynamically scaled to suit the demands of the user, which makes it attractive to organisations that wish to consolidate resources by creating their own elastic resource platforms or outsource to obtain more flexible cost effective computing resources. The scale and dynamic nature of cloud computing creates significant challenges for their management, including investigating malicious activity and/or policy failure. Digital forensics is the practice of analysing computers for evidence of crime or breach of policy. Among the various techniques employed to forensically analyse computer systems, file signatures are commonly used. This paper identifies the barriers to applying existing signature detection techniques to the large scale distributed storage platforms provided by cloud computing. The focus of this paper is the development of a model to determine a suitable signature length for use in the forensic analysis of a large distributed set of files. By reducing the signature length we show that we can reduce the amount of data required to carry out signature detection as this is one of the constraints preventing exiting techniques from being applied to cloud platforms. Through experimentation we validate our model and show that it is possible to use shorter length signatures to accurately carry out forensic analysis if factors such as the scale of the data undergoing analysis and the scale of the signature set used for the analysis are taken into account.