The use of scientifically derived and proven methods toward the preservation, collection, validation, identification, analysis, interpretation, documentation and presentation of digital evidence derived from digital sources for the purpose of facilitating or furthering the reconstruction of events found to be criminal, or helping to anticipate unauthorized actions shown to be disruptive to planned operations.
Communities
There at least 3 distinct communities within Digital Forensics:
Acquire the evidence without altering or damaging the original
Authenticate the image
Analyze the data without modifying it
Digital Crime Scene
Digital Evidence
Digital data that establish that a crime has been committed, can provide a link between a crime and its victim, or can provide a link between a crime and the perpetrator (Carrier & Spafford, 2003)
Digital Crime Scene
The electronic environment where digital evidence can potentially exist (Rogers, 2005)
Primary & secondary digital scene(s) as well
Locard’s Principle
"When a person commits a crime something is always left at the scene of the crime that was not present when the person arrived."
Forensic Principles
Digital/ Electronic evidence is extremely volatile!
Once the evidence is contaminated it cannot be de-contaminated!
The courts acceptance is based on the best evidence principle
With computer data, printouts or other output readable by sight, and bit stream copies adhere to this principle.
Chain of Custody is crucial
Cyber Forensic Principles
When dealing with digital evidence, all of the general forensic and procedural principles must be applied.
Upon seizing digital evidence actions taken should not change that evidence.
When it is necessary for a person to access original digital evidence, that person should be trained for the purpose.
All activity relating to the seizure, access, storage or transfer of digital evidence must be fully documented, preserved and available for review.
An Individual is responsible for all actions taken with respect to digital evidence whilst the digital evidence is in their possession.
Any agency, which is responsible for seizing, accessing, storing or transferring digital evidence is responsible for compliance with these principles.
Phases of Digital Forensics
Identification
The first step is identifying evidence and potential containers of evidence.
Small scale devices
Non-traditional storage media
Multiple possible crime scenes
Context of the investigation is very important.
Do not operate in a vacuum!
Do not overlook non-electronic sources of evidence
Bit for Bit copying captures all the data on the copied media including hidden and residual data (e.g., slack space, swap, residue, unused space, deleted files etc.)
Often the "smoking gun" is found in the residual data.
Imaging from a disk (drive) to a file is becoming the norm
Multiple cases stored on same media
No risk of data leakage from underlying media
Remember: avoid working from original
Use a write blocker even when examining a copy!
Imaging Authenticity & Integrity
How do we demonstrate that the image is a true unaltered copy of the original?