This paper provides a historical overview of the development of cyberforensics as a scientific discipline, along with a description of the current state of training, educational programs, certification and accreditation. The paper traces the origins of cyberforensics, the acceptance of cyberforensics as forensic science and its recognition as a component of information security. It also discusses the development of professional certifications and standardized bodies of knowledge that have had a substantial impact on the discipline. Finally, it discusses the accreditation of cyberforensic educational programs, its linkage with the bodies of knowledge and its effect on cyberforensic educational programs.
This paper provides a historical overview of the development of cyberforensics as a scientific discipline, along with a description of the current state of training, educational programs, certification and accreditation. The paper traces the origins of cyberforensics, the acceptance of cyberforensics as forensic science and its recognition as a component of information security. It also discusses the development of professional certifications and standardized bodies of knowledge that have had a substantial impact on the discipline. Finally, it discusses the accreditation of cyberforensic educational programs, its linkage with the bodies of knowledge and its effect on cyberforensic educational programs.
This paper contrasts the traditional metaphors for digital forensics – computer science, geology and archeology – with the new metaphors of history and historiography. Narratology, the study of how narratives operate, is used to develop a construct for identifying narratives from within digital evidence. Knowledge management is suggested as a core digital forensic process. The paper describes how the investigative paradigm and traditional theories of forensic science can be integrated using two theoretical constructs, the hermeneutic and narrative theories of digital forensics. Also, natural language processing techniques are used to demonstrate how subjects can be identified from the Enron email corpus.
Since the advent of the microprocessor, affordable storage devices, and networks, more of our daily lives are being recorded in the ones and zeros of the digital world. Thus, it is not surprising that when crimes and torts are committed, there is often evidence of probative value stored or transmitted in digital form. This, in fact, is the definition of digital evidence according to the Scientific Working Group on Digital Evidence (SWGDE) (Forensic Science Communications 2(2), 2000). This digital evidence can be probative in virtually any criminal or civil matter. As a result of this, it appears that digital evidence will likely become the predominant form of evidence in the twenty-first century.
Journal of Forensic SciencesVolume 55, Issue 5 p. 1408-1408 Review of: Investigating Digital Crime Mark M. Pollitt M.S., Mark M. Pollitt M.S. Visiting Faculty, National Center for Forensic Science, University of Central Florida, Orlando, FL.Search for more papers by this author Mark M. Pollitt M.S., Mark M. Pollitt M.S. Visiting Faculty, National Center for Forensic Science, University of Central Florida, Orlando, FL.Search for more papers by this author First published: 01 September 2010 https://doi.org/10.1111/j.1556-4029.2010.01486.xRead the full textAboutPDF ToolsRequest permissionExport citationAdd to favoritesTrack citation ShareShare Give accessShare full text accessShare full-text accessPlease review our Terms and Conditions of Use and check box below to share full-text version of article.I have read and accept the Wiley Online Library Terms and Conditions of UseShareable LinkUse the link below to share a full-text version of this article with your friends and colleagues. Learn more.Copy URL Share a linkShare onFacebookTwitterLinked InRedditWechat No abstract is available for this article. Volume55, Issue5September 2010Pages 1408-1408 RelatedInformation
The field of digital forensics is relatively new. While its history may be chronologically short, it is complex. This paper outlines the early history of digital forensics from the perspective of an early participant. The history is divided into four epochs: pre-history, infancy, childhood and adolescence. Each of these epochs is examined from the perspective of the people involved, the criminal targets, the forensic tools utilized, the organizational structures that supported digital forensic practitioners and how the community formed. This history is, by necessity, incomplete and biased. There is a need for rigorous historical research in this area before all traces of the past are forgotten or obliterated.
The field of digital forensics is relatively new. While its history may be chronologically short, it is complex. This paper outlines the early his- tory of digital forensics from the perspective of an early participant. The history is divided into four epochs: pre-history, infancy, childhood and adolescence. Each of these epochs is examined from the perspective of the people involved, the criminal targets, the forensic tools utilized, the organizational structures that supported digital forensic practitioners and how the community formed. This history is, by necessity, incom- plete and biased. There is a need for rigorous historical research in this area before all traces of the past are forgotten or obliterated.
One of the most interesting aspects of Web 2.0 technologies is how they have been adapted by users in ways not anticipated by the creators of the technology. We, as digital forensic practitioners, have to evolve our methods and approaches in response to both the technologies and their use. But that is “old hat” to us. After all, constant change and challenge are what attract most of us to this field.
Digital forensics is traditionally approached either as a computer science problem or as an investigative problem. In both cases, the goal is usually the same: attempt to locate discrete pieces of information that are probative. In the computer science approach, characteristics of the data are utilized to include or exclude objects, data or metadata. The investigative approach reviews the content of the evidence to interpret the data in the light of known facts and elements of the crime in order to determine probative information or information of lead value. This paper explores two literary theories, narrative theory and surrealism, for potential application to the digital forensic process. Narrative theory focuses on the "story" that is represented by text. At some level, a storage device may be viewed as a series of interweaving, possibly multi-dimensional, narratives. Furthermore, the narratives themselves, coupled with the metadata from the file system and applications, may form a meta-narrative. The literary theory of surrealism, the notion of disjointed elements, can be utilized to derive meaning from forensic evidence. This paper uses a technique known as surrealist games to illustrate the point.
Early digital forensic examinations were conducted in toto — every file on the storage media was examined along with the entire file system structure. However, this is no longer practical as operating systems have become extremely complex and storage capacities are growing geometrically. Examiners now perform targeted examinations using forensic tools and databases of known files, selecting specific files and data types for review while ignoring files of irrelevant type and content. Despite the application of sophisticated tools, the forensic process still relies on the examiner's knowledge of the technical aspects of the specimen and understanding of the case and the law. Indeed, the success of a forensic examination is strongly dependent on how it is designed. This paper discusses the application of traditional forensic taxonomy to digital forensics. The forensic processes of identification, classification/individualization, association and reconstruction are used to develop "forensic questions," which are applied to objectively design digital forensic examinations.
ABSTRACT The International Federation on Information Processing Working Group on Digital Forensics (IFIP WG 11.9) is an international body comprised of primarily researchers and educators in the field of digital forensics. It is my privilege to be the chair of this group and we recently held our fifth annual meeting in Orlando, Florida, that was attended by a broad representation from at least eight countries. The program committee did a great job at recruiting good papers and presentations, one of which I would like to share with our readers. In a field that evolves as quickly as this one, it is important from time to time to stop and look at how we are doing. To that end, Dr. Nicole Beebe from the University of Texas at San Antonio was asked to put together a presentation that would examine what we are doing well in the field, what needs work, and what is lacking in attention. Though Dr. Beebe is an expert in her own right—a college professor, an investigator and forensic examiner in both the public and private sector—she did what the best academics do and she sought the opinions of as many experts as she had time to contact. And what a list it was. It included over two dozen names that are acknowledged “players” in this field. She interviewed each one and synthesized their collective wisdom in a thirty-minute presentation. What follows is a summary of her presentation.
This paper discusses the concept of a. virtual digital forensic laboratory, which incorporates networked examination and storage machines, secure communications, multi-factor authentication, role-based access control, and case management and digital asset management systems. Laboratory activities such as the examination, storage and presentation of digital evidence can be geographically distributed and accessed over a network by users with the appropriate credentials. The advantages of such a facility include reduced costs through shared resources and the availability of advanced expertise for specialized cases.
The application of virtualization software and techniques in information technology research and education has provided a foundational environment to advance the state-of-the-art in research and education in many related areas. Commercial and open source virtualization products are being used by researchers and educators to create a wide variety of virtual environments. These virtual environments facilitate systems design and development and product development as well as the testing and modeling of production and preproduction systems. As the capabilities, functionality, and stability of these products have evolved, the use of virtualization has expanded, necessitating the identification of new research areas to investigate the impacts of virtualization on digital forensics. In February 2007, a group of digital forensics researchers, educators, and practitioners gathered at the National Center for Forensic Science at the University of Central Florida for the 2007 Workshop on Virtualization in Digital Forensics to discuss these issues and develop a research and education agenda for virtualization and digital forensics. This article outlines some of the ideas generated and new research categories and areas identified at this meeting.
As a law enforcement officer and forensic professional, I watched in horror as the O.J. Simpson trial unfolded. Sloppy crime scene work, poor chains of custody, incompetent and lying witnesses were...
Law enforcement agents at the local, state, and Federal levels have informed us of backlogs of computer-related crime cases ranging from 18 months to three years. The primary cause of these backlogs is the lack of educated and trained personnel to serve as digital forensics examiners. In response to this need, the University of Central Florida has created a Masters in Digital Forensics. This 30-hour degree is an interdisciplinary mix of technical, legal, ethical, and courtroom testimony-based courses. Students must complete a capstone course as well as a graduate internship to demonstrate proficiency in the knowledge and skills acquired from the courses.
This panel will review issues associated with the development of an interdisciplinary educational program on digital forensics practice, computer science and judicial process.