To contribute to the understanding of the operationalisation of digital forensic science and the associated chal lenges, this study observes daily practices and interactions of a digital forensic unit. The observation was focused on four main questions: (1) What are the primary missions of a DFU? (2) What workflow procedures do DFUs use in performing their duties? (3) How useful are DFUs and digital traces at various stages of an investigation? (4) What obstacles do DFUs face in fulfilling their missions? This study draws on 160 hours of field observations conducted between January and March 2020 in a Swiss police force, the analysis of the unit internal casework database (2018-2019 past cases) and 6 semi-structured interviews with different stakeholders. The study is divided between an active participation in the digital forensic work (handling, analysing digital objects and reporting) and a passive participation in field work. Different uses and expectations of the digital forensic unit services depending on the investigation context were observed during the analysis of the field search notes, casework database and while conducting the interviews. The findings also allowed for the categorization and timelining of the types of activities conducted by a digital forensic unit.
Forensic document examination is characterized by its longevity, diversity, and evolution over time. Predominantly, published research within this field has focused on handwriting examination, the articulation of forensic conclusions, and the development of technical instrumental advancements, focusing on the use of document examination in the resolution of casework. This is a persistent and common problem within forensic science that Kirk identified in 1963 and that other authors have reaffirmed more recently. Ultimately, this has resulted in the potential of forensic intelligence, remaining relatively underexplored in the field of document examination. Forensic intelligence is a different way to view and analyze traces, shifting the focus from the traditional identification of source and activity, to instead identifying trends in criminal activity to assist in the reduction, prevention, and proactive disruption of crime. Despite a distinct disparity between these strands of research, there has been a persevering evolution toward the implementation of a systematic forensic intelligence method for the examination of fraudulent identity documents. Since its initial inception into the research community, this method has expanded and been implemented across Europe, and Canada, with tests also being conducted in Australia. These first tangible steps toward a forensic intelligence capacity within document examination have also inspired new work using forensic intelligence and systematic comparisons within the field of handwriting examination, as well as the recognition of the transversal potential of this method, with it being applied to both physical and digital documents. In this review, the fields of document examination and forensic intelligence will first be introduced, along with a subsequent examination of the research that has led to the creation of a forensic intelligence model within the field of document examination. It should be noted that this review has largely been limited to a review of research that has been published in English and French due to the language of the authors. This article is categorized under: Crime Scene Investigation > From Traces to Intelligence and Evidence Forensic Chemistry and Trace Evidence > Emerging Technologies and Methods Crime Scene Investigation > Epistemology and Method
From the beginnings of Silk Road in 2011, anonymous online marketplaces have continued to grow despite the best efforts of law enforcement. While these ever-present marketplaces remain flooded with illicit drugs and related paraphernalia, the sale and distribution of fraudulent identity documents remains a persistent problem, with these items consistently appearing for sale on both the open and dark web. While fraudulent Australian documents are some of the most popular products for sale, there is still much that is unknown about the Australian criminal market and its place within anonymous online marketplaces. Given the success of previous research in understanding the illicit drug trade through examining these marketplaces, this work examines two markets to gain an understanding of where Australian document fraud sits within this digital ecosystem. Two anonymous online marketplaces were crawled across 2020 and 2021, White House Market (WHM), and Empire Market. This data was extracted and examined to identify trends within both the international online market and the online market specifically for Australian documents, both of which have been relatively underexplored in the online space. To help illuminate the features of the market, the types of documents for sale, supply and demand trends, and trafficking flows along with vendor-related trends (e.g. product diversification and presence across markets) were examined. Each market was examined individually and then, where possible, comparisons were drawn to gain a more holistic understanding of the online fraudulent document market, with a specific focus on Australian products. Results indicate that, while the fraudulent document portion of the market is small, it is diverse, with numerous different identity-related products for sale, the most common being driver’s licences from the United States (U.S.) and Australia, with digital documents dominating the whole marketplace. Overall, the most popular U.S. products were those that could be used to facilitate identity fraud, with the most popular Australian products being driver’s licences and ID packs, likely linked to the presence of the 100-point identity check system used in Australia. This study demonstrates that anonymous online marketplaces have thus far been under-utilised in the study of the fraudulent document market, and that to properly understand the illicit market for fraudulent documents and personal information both the online and physical sides of the market should be considered. This information, if properly utilised, can improve the current understanding of this persistent criminal environment, building on previous research and assisting policymakers in making informed decisions.
The serial character of document fraud and its connection to organised crime groups who produce, sell and/or use fraudulent documents is a challenge for security and crime fighting. As a response, the added value of forensic intelligence is increasingly recognised. Using a forensic profiling method and a dedicated system deployed in Switzerland, document examiners can detect series (i.e., documents that share a common source) of fraudulent documents conveniently and efficiently. This detection can trigger or orientate investigations, supports crime intelligence efforts, and facilitates cross-jurisdictional cooperation. This study aims to assess the suitability of the forensic profiling system for international purpose and the efficiency of the method to detect cross-border series. The forensic profiling system has been deployed in France in the framework of a cross-border pilot project conducted by the School of Criminal Justice from the University of Lausanne and the French National Police (Division Nationale de Lutte contre la Fraude Documentaire et à l'Identité) over the period July 2019-May 2020. Data from the Swiss and French forensic profiling systems were compared to each other to detect cross-border series. The study sought to create operating conditions as close as possible to the real-life conditions of the profiling systems. The results are extremely positive both quantitatively and qualitatively. They demonstrate the benefit of setting up a systematic exchange of forensic data issued from profiling systems for fraudulent identity documents between France and Switzerland, let alone between any other countries. The results open up a very promising prospect for a sustained operational implementation by the police services of both countries and the extension of the exchanges internationally.
Perpetrators of offences missing from police files limit the capacity to investigate criminal behaviour for criminological research and operational purposes. Recent studies have shown that forensic DNA databanks, which include samples of DNA not yet matched to an individual, have the potential to address this problem. By examining information associated with criminal cases that involved DNA matches, we demonstrate that individuals who cannot be identified through DNA differ from those for whom such identification is possible. Based on data from 19 years of DNA matches in Quebec, Canada, we were able to assess the co-offending and repeat offending behavior of unidentified and identified individuals as well as the diversification, level of severity, and types of offenses. We found that the crimes of the 1,448 individuals who had not been identified were marginal as compared with those of individuals who had been identified. Unidentified individuals were more likely to act alone in repeated crimes, to be involved in fewer cases, to use less violence, and to become more specialized with increased activity. Our results are consistent with other studies that demonstrate that the criminal activity of unidentified individuals accords with the exposure hypothesis. The association of these findings with a network analysis approach is innovative and could have a greater than expected impact on investigations and policies, as well as having implications for forensic intelligence.
The manufacture and distribution of fraudulent identity documents (IDs) is a pervasive and prolific crime problem, enabling the activities of organized crime networks and terrorist cells. As reactive policing methods are ill-equipped to handle the transversal and repetitive nature of document fraud, in 2012 Baechler et al. suggested a complementary method that uses the systematic profiling and comparison of fraudulent IDs to identify those produced by the same source. While this method has been successful in Europe, it is yet to be implemented worldwide, and there is currently little known about the Australian fraudulent document climate. In this pilot study, 43 fraudulent IDs from Sydney-based New South Wales police stations were examined. Adapting the method used in Europe, these documents were imaged, and their visual characteristics were extracted before being organized into an excel database and manually compared. The characteristics chosen are fundamentally linked to the manufacturing process, including the printing methods and replication of security features. Of the documents examined 88% were linked to at least one other document, and five series emerged. These results suggest that the Australian document market may be structured, and that there may be prolific offenders operating at its core, much like in Europe.
Over the years, forensic science has primarily positioned itself as a service provider for the criminal justice system, following the dominant and traditional reactive law enforcement model. Unfortunately, this focus has limited its capacity to provide knowledge about crime systems and to support other forms of policing styles through forensic intelligence. Although forensic intelligence research has steadily developed over the last few years, it is rarely covered in the core of academic teaching and research programs. Developing forensic intelligence programs would empower graduates with an awareness of forensic intelligence meaning and models, creating great opportunities to shape their future professional activities and progressively shift the dominant paradigm through a bottom-up approach. In this article, the teaching and learning strategies in forensic intelligence developed at the University of Lausanne (Switzerland) and adapted at the University of Technology Sydney (Australia) and the Université du Québec à Trois-Rivières (Canada) are presented. The objective behind the strategy is to reflect on and work on real case scenarios using a progressive teaching and learning approach that builds upon the theory and practical exercise putting students in real-life situations. Through this innovative learning process, students move away from the Court as the sole end purpose of forensic science. They learn to adopt different roles, adopt a proactive attitude as well as work individually and collaboratively. This teaching and learning strategy breaks the current silos observed in the forensic science discipline by focusing on processes and critical thinking. It can be foreseen, through the evolution of crime and policing models, that the learning and teaching strategy described in this article offers and will offer the students with many new job opportunities. The article concludes with the advantages that such teaching and learning programs in forensic intelligence bring to the forensic science community.
Document fraud is a transnational form of crime, and its serial character has already been highlighted. To combat this phenomenon, the Interstate Database of Fraudulent Identity Documents (BIDIF) has been created and implemented in Switzerland. It supports the comparison of documents and the detection of series, i.e., documents that share a common source. To efficiently use such a system, forensic document examiners would benefit from a harmonised and proven profiling method. Thus, the aim of this study is to develop a method for comparing documents and establishing series. The method is meant to improve the detection capabilities of forensic document examiners operating BIDIF or engaged in the profiling of fraudulent documents. First, a method based on the visual characteristics of digitised images of fraudulent identity documents has been developed. Subsequently, the method was qualitatively and quantitatively evaluated using four tests. The first test verified the ability of the method to detect pre-existing series. The second test checked the capability of the method to detect links amongst isolated documents. Finally, two further tests were carried out to compare the method impact on the successful detection of series. These tests were carried out by professional forensic document examiners and Master students in forensic science, respectively. This allowed a comparison of the method influence on series detection. The method allowed a significant increase in the number of series and links detected, while also decreasing the occurrence of false negatives and false positives. Furthermore, links were more rapidly detected.
AbstractDifferent data processing methods can support the detection and analysis of various forms of crime patterns. The authors document the influence and role of forensic science and how this has been transformed by digitalization. Forensic intelligence is key and they illustrate their argument of its potential by discussing two new forensic intelligence systems and their underlying digital infrastructure, one facilitating the forensic comparison of fraudulent ID documents (ProFID) and the other the monitoring of online frauds (PICSEL).
Abstract Different data processing methods can support the detection and analysis of various forms of crime patterns. The authors document the influence and role of forensic science and how this has been transformed by digitalization. Forensic intelligence is key and they illustrate their argument of its potential by discussing two new forensic intelligence systems and their underlying digital infrastructure, one facilitating the forensic comparison of fraudulent ID documents (ProFID) and the other the monitoring of online frauds (PICSEL).
et de Suisse romande : une étude de cas comparative 3
Chapter 5 was previously published non-open access. It has now been changed to open access under a CC BY 4.0 license and the copyright holder updated to ‘The Author(s)’.
Criminal offenders missing from police files limit the capacity to reconstruct criminal networks for criminological research and operational purposes. Recent studies show that forensic DNA databanks offer potential to address this problem, through large-scale analysis of DNA matches, many of which involve unidentified offenders. Applying social network analysis (SNA) to 18 years of DNA match data from Québec, Canada, we found that 1400 unknowns do not occupy more marginal positions in the network than 13,000 known offenders, and explain up to 18% of SNA values (e.g., betweenness centrality) for the latter while supporting 46% of their clustering values. Our results contrast with previous studies, showing moreover that unknown individuals who are positioned centrally in a network may have a larger impact than previously expected on investigation policing with implications for forensic intelligence.
In the area of illicit drugs, forensic case data have proven effective at detecting links between seizures and providing greater insights into illicit drug markets. This research explored the application of mathematical and statistical techniques to several chemical profiles of Australian methylamphetamine seizures. The main aim was to create and deliver a method that would expand the use of illicit drug profiling for strategic intelligence purposes, contributing to the fight against illicit drug trafficking. The use of comparison metrics and clustering analysis to determine links between existing illicit drug specimens and subsequent new specimens was evaluated and automated. Relational, temporal and spatial analyses were subsequently used to gain an insight into illicit drug markets. Relational analysis identified clusters of seizures central to the network. Temporal analysis then provided insights into the behaviour of distribution markets, specifically the emergence and extinction of certain clusters of seizures over time. Spatial analysis aided the understanding of the inter-jurisdictional nature of illicit drug markets. These analyses allowed for the generation of strategic intelligence relating to when and where the Australian methylamphetamine illicit drug market was the most active. Additionally, the strategic level trends identified clusters of seizures that were worth investigating further. These clusters were explored through a case study, which exploited additional chemical profiling data to provide drug market knowledge at an operational level. In turn, the intelligence produced at various levels could allow relevant law enforcement agencies to take necessary measures in disrupting markets.
Forensic technologies are now more easily transportable, fast and useable in the field by non-specialists. They help detect, collect and analyse a large volume of new and diverse traces generated by criminal activities. These changes, in order of magnitude, induce rapid digital transformations of forensic processes, requiring a radical shift in roles and tasks for traditional forensic and police structures. Examples are presented to help characterise these developments that are subject to many tensions. The new complex situation prompts interrogations about the suitability of a law enforcement paradigm of policing that mainly define the scope of forensic science as ancillary to the criminal justice system. The current context offers instead many opportunities to express the value of forensic thinking in proactive policing. Traceology, as the science of traces, is proposed as the overarching approach to pave the way for balanced, regulated and efficient approaches to intelligence and policing.
A nearly universal practice among forensic DNA scientists includes mentioning an unrelated person as the possible alternative source of a DNA stain, when one in fact refers to an unknown person. Hence, experts typically express their conclusions with statements like: “The probability of the DNA evidence is X times higher if the suspect is the source of the trace than if another person unrelated to the suspect is the source of the trace.” Published forensic guidelines encourage such allusions to the unrelated person. However, as the authors show here, rational reasoning and population genetic principles do not require the conditioning of the evidential value on the unrelatedness between the unknown individual and the person of interest (e.g., a suspect). Surprisingly, this important semantic issue has been overlooked for decades, despite its potential to mislead the interpretation of DNA evidence by criminal justice system stakeholders.
L’article propose un modèle continu, non linéaire, itératif et collaboratif de l’enquête. Celui-ci décrit le processus d’enquête appliqué au traitement des problèmes criminels et sécuritaires, faisant appel à des notions clés telles que l’entropie, le raisonnement hypothético-déductif, la méthode scientifique et la pensée itérative. Le modèle se concentre sur la démarche inférentielle et intellectuelle de l’enquête plutôt que sur les aspects procéduraux, qui varient selon les pays et les juridictions ou selon les types de crime. Inspiré de théories préexistantes de l’enquête, ce modèle offre un cadre cohérent et intégratif aux différentes méthodes d’enquête qui concourent au traitement de l’information et à la compréhension des évènements et des phénomènes. Le modèle permet aux enquêteurs, au sens large, de guider leur raisonnement et leur prise de décisions, ainsi que de situer leurs contributions tout au long du processus d’enquête. Il facilite ainsi la collaboration entre tous les acteurs, à commencer par les inspecteurs, les analystes criminels, les investigateurs numériques et les criminalistes, pour atteindre leurs objectifs communs au service de la justice, de la sécurité et de la société. À l’appui d’exemples issus de notre pratique, nous traçons ici le cheminement intellectuel qui amène à poser ce modèle progressif et collaboratif. Cette vision, qui place les intersections en son centre, ébranle les barrières classiques érigées dans les théories et la pratique. Nous décrivons les enjeux, les avantages et les limites de ce modèle.
Forensic science has been evolving towards a separation of more and more specialised tasks, with forensic practitioners increasingly identifying themselves with only one sub-discipline or task of forensic science. Such divisions are viewed as a threat to the advancement of science because they tend to polarise researchers and tear apart scientific communities. The objective of this article is to highlight that a piece of information is not either intelligence or evidence, and that a forensic scientist is not either an investigator or an evaluator, but that these notions must all be applied in conjunction to successfully understand a criminal problem or solve a case. To capture the scope, strength and contribution of forensic science, this paper proposes a progressive but non-linear continuous model that could serve as a guide for forensic reasoning and processes. In this approach, hypothetico-deductive reasoning, iterative thinking and the notion of entropy are used to frame the continuum, situate forensic scientists' operating contexts and decision points. Situations and examples drawn from experience and practice are used to illustrate the approach. The authors argue that forensic science, as a discipline, should not be defined according to the context it serves (i.e. an investigation, a court decision or an intelligence process), but as a general, scientific and holistic trace-focused practice that contributes to a broad range of goals in various contexts. Since forensic science does not work in isolation, the approach also provides a useful basis as to how forensic scientists should contribute to collective and collaborative problem-solving to improve justice and security.
While police chiefs are the main managers in policing, this chapter also underlines their role in the provision of forensic science, hardly known to be able to help define policing. A recent survey of high-ranking officers of various police forces in Quebec showed that police managers tend to focus mainly, if not exclusively, on the ability of forensic science to serve justice. It is therefore argued that the police managers' conception of forensic science may hinder its potential to be proactively implemented in policing models. This situation should be addressed, as a more holistic application of forensic science could offer relevant insights to policing, including threat identification and resource allocations.
This article proposes a continuous, non-linear, iterative, and collaborative model for the investigation process used to identify and deal with criminal and security problems, relying on key concepts such as entropy, hypothetical-deductive reasoning, scientific method, and iterative thinking. The model focuses on the inferential and intellectual aspects of investigations rather than the procedural aspects, which can vary depending on the country in which the crime was committed or the type of crime. Inspired by existing theories of investigation, this model offers a coherent and integrative framework for processing information and understanding events and phenomena. The model provides guidance for investigators in reasoning and decision-making and situates their contributions during the investigation process. It should ultimately facilitate collaboration between different stakeholders (investigators, criminal analysts, digital investigators, and criminalists) to help them achieve their common objectives in the service of justice, security, and society. Using situations and examples drawn from our work, we describe the intellectual path that led us to develop this progressive and collaborative model. The model, which places meeting places at its centre, undermines the traditional barriers between theory and practice. The challenges, advantages, and limits of this model are also discussed.