Open Access. Powered by Scholars. Published by Universities.®

Computer Law Commons

Open Access. Powered by Scholars. Published by Universities.®

2014

Discipline
Institution
Keyword
Publication
Publication Type

Articles 121 - 150 of 173

Full-Text Articles in Computer Law

Using Internet Artifacts To Profile A Child Pornography Suspect, Marcus K. Rogers, Kathryn C. Seigfried-Spellar Jan 2014

Using Internet Artifacts To Profile A Child Pornography Suspect, Marcus K. Rogers, Kathryn C. Seigfried-Spellar

Journal of Digital Forensics, Security and Law

Digital evidence plays a crucial role in child pornography investigations. However, in the following case study, the authors argue that the behavioral analysis or “profiling” of digital evidence can also play a vital role in child pornography investigations. The following case study assessed the Internet Browsing History (Internet Explorer Bookmarks, Mozilla Bookmarks, and Mozilla History) from a suspected child pornography user’s computer. The suspect in this case claimed to be conducting an ad hoc law enforcement investigation. After the URLs were classified (Neutral; Adult Porn; Child Porn; Adult Dating sites; Pictures from Social Networking Profiles; Chat Sessions; Bestiality; Data Cleaning; …


On Cyber Attacks And Signature Based Intrusion Detection For Modbus Based Industrial Control Systems, Wei Gao, Thomas H. Morris Jan 2014

On Cyber Attacks And Signature Based Intrusion Detection For Modbus Based Industrial Control Systems, Wei Gao, Thomas H. Morris

Journal of Digital Forensics, Security and Law

Industrial control system communication networks are vulnerable to reconnaissance, response injection, command injection, and denial of service attacks. Such attacks can lead to an inability to monitor and control industrial control systems and can ultimately lead to system failure. This can result in financial loss for control system operators and economic and safety issues for the citizens who use these services. This paper describes a set of 28 cyber attacks against industrial control systems which use the MODBUS application layer network protocol. The paper also describes a set of standalone and state based intrusion detection system rules which can be …


Idiographic Digital Profiling: Behavioral Analysis Based On Digital Forensics, Chad M. Steel Jan 2014

Idiographic Digital Profiling: Behavioral Analysis Based On Digital Forensics, Chad M. Steel

Journal of Digital Forensics, Security and Law

Idiographic digital profiling (IDP) is the application of behavioral analysis to the field of digital forensics. Previous work in this field takes a nomothetic approach to behavioral analysis by attempting to understand the aggregate behaviors of cybercriminals. This work is the first to take an idiographic approach by examining a particular subject's digital footprints for immediate use in an ongoing investigation. IDP provides a framework for investigators to analyze digital behavioral evidence for the purposes of case planning, subject identification, lead generation, obtaining and executing warrants, and prosecuting offenders.


On Identities In Modern Networks, Libor Polcak, Radek Hranick, Tomas Martınek Jan 2014

On Identities In Modern Networks, Libor Polcak, Radek Hranick, Tomas Martınek

Journal of Digital Forensics, Security and Law

Communicating parties inside computer networks use different kind of identifiers. Some of these identifiers are stable, e.g., logins used to access a specific service, some are only temporary, e.g., dynamically assigned IP addresses. This paper tackles several challenges of lawful interception that emerged in modern networks. The main contribution is the graph model that links identities learnt from various sources distributed in a network. The inferred identities result into an interception of more detailed data in conformance with the issued court order. The approach deals with network address translation, short-lived identifiers and simultaneous usage of different identities. The approach was …


Exploring Forensic Implications Of The Fusion Drive, Shruti Gupta, Marcus Rogers Jan 2014

Exploring Forensic Implications Of The Fusion Drive, Shruti Gupta, Marcus Rogers

Journal of Digital Forensics, Security and Law

This paper explores the forensic implications of Apple’s Fusion Drive. The Fusion Drive is an example of auto-tiered storage. It uses a combination of a flash drive and a magnetic drive. Data is moved between the drives automatically to maximize system performance. This is different from traditional caches because data is moved and not simply copied. The research included understanding the drive structure, populating the drive, and then accessing data in a controlled setting to observe data migration strategies. It was observed that all the data is first written to the flash drive with 4 GB of free space always …


Multi-Stakeholder Case Prioritization In Digital Investigations, Joshua I. James Jan 2014

Multi-Stakeholder Case Prioritization In Digital Investigations, Joshua I. James

Journal of Digital Forensics, Security and Law

This work examines the problem of case prioritization in digital investigations for better utilization of limited criminal investigation resources. Current methods of case prioritization, as well as observed prioritization methods used in digital forensic investigation laboratories are examined. After, a multi-stakeholder approach to case prioritization is given that may help reduce reputational risk to digital forensic laboratories while improving resource allocation. A survey is given that shows differing opinions of investigation priority between Law Enforcement and the public that is used in the development of a prioritization model. Finally, an example case is given to demonstrate the practicality of the …


An Efficient Similarity Digests Database Lookup – A Logarithmic Divide & Conquer Approach, Frank Breitinger, Christian Rathgeb, Harald Baier Jan 2014

An Efficient Similarity Digests Database Lookup – A Logarithmic Divide & Conquer Approach, Frank Breitinger, Christian Rathgeb, Harald Baier

Journal of Digital Forensics, Security and Law

Investigating seized devices within digital forensics represents a challenging task due to the increasing amount of data. Common procedures utilize automated file identification, which reduces the amount of data an investigator has to examine manually. In the past years the research field of approximate matching arises to detect similar data. However, if n denotes the number of similarity digests in a database, then the lookup for a single similarity digest is of complexity of O(n). This paper presents a concept to extend existing approximate matching algorithms, which reduces the lookup complexity from O(n) to O(log(n)). Our proposed approach is based …


Table Of Contents Jan 2014

Table Of Contents

Journal of Digital Forensics, Security and Law

No abstract provided.


From The Editor, Ibrahim Baggili Jan 2014

From The Editor, Ibrahim Baggili

Journal of Digital Forensics, Security and Law

In this issue we have three papers that have made the cut. The first paper titled “The Cost of Privacy: Riley v. California’s Impact on Cell Phone Searches” is timely. In 2014 there was a unanimous decision that requires a warrant for all cell phone searches. This has some strong implications on the forensic analysis of mobile phones, and to that end, this article discusses and summarizes this legal precedent with its practical implications.


Leveraging Decentralization To Extend The Digital Evidence Acquisition Window: Case Study On Bittorrent Sync, Mark Scanlon, Jason Farina, Nhien A. Khac, Tahar Kechadi Jan 2014

Leveraging Decentralization To Extend The Digital Evidence Acquisition Window: Case Study On Bittorrent Sync, Mark Scanlon, Jason Farina, Nhien A. Khac, Tahar Kechadi

Journal of Digital Forensics, Security and Law

File synchronization services such as Dropbox, Google Drive, Microsoft OneDrive, Apple iCloud, etc., are becoming increasingly popular in today’s always-connected world. A popular alternative to the aforementioned services is BitTorrent Sync. This is a decentralized/cloudless file synchronization service and is gaining significant popularity among Internet users with privacy concerns over where their data is stored and who has the ability to access it. The focus of this paper is the remote recovery of digital evidence pertaining to files identified as being accessed or stored on a suspect’s computer or mobile device. A methodology for the identification, investigation, recovery and verification …


Book Review: The X-Ways Forensics Practitioner's Guide, Linda Lau Jan 2014

Book Review: The X-Ways Forensics Practitioner's Guide, Linda Lau

Journal of Digital Forensics, Security and Law

Brett Shavers is a former law enforcement officer, a digital forensics examiner, an adjunct instructor, and a frequent speaker at many conferences. After writing his first book, titled Placing the Suspect Behind the Keyboard: Using Digital Forensics and Investigative Techniques to Identify Cybercrime Suspects, he co-wrote his 2nd book with Eric Zimmerman and Jimmy Weg, who is a knowledgeable technical editor. Both Brett and Eric are experts in cyber forensics, with many years of law enforcement experience at both the state and federal levels.


The Cost Of Privacy: Riley V. California’S Impact On Cell Phone Searches, Jennifer L. Moore, Jonathan Langton, Joseph Pochron Jan 2014

The Cost Of Privacy: Riley V. California’S Impact On Cell Phone Searches, Jennifer L. Moore, Jonathan Langton, Joseph Pochron

Journal of Digital Forensics, Security and Law

Riley v. California is the United States Supreme Court’s first attempt to regulate the searches of cell phones by law enforcement. The 2014 unanimous decision requires a warrant for all cell phone searches incident to arrest absent an emergency. This work summarizes the legal precedent and analyzes the limitations and practical implications of the ruling. General guidelines for members of the criminal justice system at all levels consistent with the Supreme Court’s decision are provided.


Quantifying Relevance Of Mobile Digital Evidence As They Relate To Case Types: A Survey And A Guide For Best Practice, Shahzad Saleem, Ibrahim Baggili, Oliver Popov Jan 2014

Quantifying Relevance Of Mobile Digital Evidence As They Relate To Case Types: A Survey And A Guide For Best Practice, Shahzad Saleem, Ibrahim Baggili, Oliver Popov

Journal of Digital Forensics, Security and Law

In this work, a survey was conducted to help quantify the relevance of nineteen types of evidence (such as SMS) to seven types of digital investigations associated with mobile devices (MD) (such as child pornography). 97 % of the respondents agreed that every type of digital evidence has a different level of relevance to further or solve a particular investigation. From 55 serious participants, a dataset of 5,772 responses regarding the relevance of nineteen types of digital evidence for all the seven types of digital investigations was obtained. The results showed that (i) SMS belongs to the most relevant type …


Table Of Contents Jan 2014

Table Of Contents

Journal of Digital Forensics, Security and Law

No abstract provided.


Developing A Conceptual Framework For Modeling Deviant Cyber Flash Mob: A Socio-Computational Approach Leveraging Hypergraph Constructs, Samer Al-Khateeb, Nitin Agarwal Jan 2014

Developing A Conceptual Framework For Modeling Deviant Cyber Flash Mob: A Socio-Computational Approach Leveraging Hypergraph Constructs, Samer Al-Khateeb, Nitin Agarwal

Journal of Digital Forensics, Security and Law

In a Flash Mob (FM) a group of people get together in the physical world perform an unpredicted act and disperse quickly. Cyber Flash Mob (CFM) is the cyber manifestation of flash mob coordinated primarily using social media. Deviant Cyber Flash Mob (or, DCFM) is a special case of CFM, which is categorized as the new face of transnational crime organizations (TCOs). The DCFM phenomenon can be considered as a form of a cyber-collective action that is defined as an action aiming to improve group’s conditions (such as, status or power). In this paper, we conduct a conceptual analysis of …


Hacking Health Care: Authentication Security In The Age Of Meaningful Use , Gordon Gantt Jr. Jan 2014

Hacking Health Care: Authentication Security In The Age Of Meaningful Use , Gordon Gantt Jr.

Journal of Law and Health

The rapid adoption of EHRs (Electronic Health Records), to store and communicate highly personal data, raises serious concerns in terms of privacy, security, and civil and criminal liability. This note will examine the current statutory framework for addressing electronic breaches in the health care context, examine the vulnerabilities of EHRs, and look to the established world of online banking for possible legislative and practical solutions to the challenge of keeping private health information private. Finally, this note will propose key amendments to the Health Insurance Portability and Accountability Act (HIPAA) regulations to enhance authentication security.


Machine Learning And Law, Harry Surden Jan 2014

Machine Learning And Law, Harry Surden

Publications

This Article explores the application of machine learning techniques within the practice of law. Broadly speaking “machine learning” refers to computer algorithms that have the ability to “learn” or improve in performance over time on some task. In general, machine learning algorithms are designed to detect patterns in data and then apply these patterns going forward to new data in order to automate particular tasks. Outside of law, machine learning techniques have been successfully applied to automate tasks that were once thought to necessitate human intelligence — for example language translation, fraud-detection, driving automobiles, facial recognition, and data-mining. If performing …


Finding The Signal In The Noise: Information Governance, Analytics, And The Future Of Legal Practice, Bennett B. Borden, Jason R. Baron Jan 2014

Finding The Signal In The Noise: Information Governance, Analytics, And The Future Of Legal Practice, Bennett B. Borden, Jason R. Baron

Richmond Journal of Law & Technology

In the watershed year of 2012, the world of law witnessed the first concrete discussion of how predictive analytics may be used to make legal practice more efficient. That the conversation about the use of predictive analytics has emerged out of the e-Discovery sector of the law is not all that surprising: in the last decade and with increasing force since 2006— with the passage of revised Federal Rules of Civil Procedure that expressly took into account the fact that lawyers must confront “electronically stored information” in all its varieties—there has been a growing recognition among courts and commentators that …


Cybersecurity And The Administrative National Security State: Framing The Issues For Federal Legislation, David G. Delaney Jan 2014

Cybersecurity And The Administrative National Security State: Framing The Issues For Federal Legislation, David G. Delaney

Articles by Maurer Faculty

In the digital age, every part of federal government has critical cybersecurity interests. Many of those issues are brought into sharp focus by Edward Snowden's disclosure of sensitive government cyber intelligence programs conducted by the National Security Agency, the Federal Bureau of Investigation, and the Central Intelligence Agency. Courts are reviewing various constitutional and statutory challenges to those programs, two government review groups have reported on related legal and policy issues, and Congress is considering cyber intelligence reform proposals. All of this action comes on the heels of significant efforts by successive administrations to restructure government and pass comprehensive cybersecurity …


From State Street Bank To Cls Bank And Back: Reforming Software Patents To Promote Innovation, Parker Hancock Jan 2014

From State Street Bank To Cls Bank And Back: Reforming Software Patents To Promote Innovation, Parker Hancock

Vanderbilt Journal of Entertainment & Technology Law

For the past several decades, the Supreme Court and Federal Circuit have struggled to determine if, and under what circumstances, software is patentable. Once again, the Federal Circuit had an opportunity to provide clarity when it granted en banc review in CLS Bank. The resulting opinion contained a cursory per curiam decision and numerous concurrences and dissents, showing that the question is far from answered. Ultimately, the struggle over software patentability is not itself the problem, but a symptom of other problems in the patent system. Specifically, other substantive requirements of patentability are not weeding out overly broad patents because …


Governing, Exchanging, Securing: Big Data And The Production Of Digital Knowledge, Bernard E. Harcourt Jan 2014

Governing, Exchanging, Securing: Big Data And The Production Of Digital Knowledge, Bernard E. Harcourt

Faculty Scholarship

The emergence of Big Data challenges the conventional boundaries between governing, exchange, and security. It ambiguates the lines between commerce and surveillance, between governing and exchanging, between democracy and the police state. The new digital knowledge reproduces consuming subjects who wittingly or unwittingly allow themselves to be watched, tracked, linked and predicted in a blurred amalgam of commercial and governmental projects. Linking back and forth from consumer data to government information to social media, these new webs of information become available to anyone who can purchase the information. How is it that governmental, commercial and security interests have converged, coincided, …


Legislating Trust, John D. Gregory Jan 2014

Legislating Trust, John D. Gregory

Canadian Journal of Law and Technology

As governments in Canada and elsewhere have considered statutes to ensure that electronic communications are legally effective, they have invariably had to face questions about the reliability of those communications. Can we trust electronic messages, documents, and signatures? Are they the same in law as if they were on paper? What conditions should be imposed in order to give us the right assurances that we can trust them? To answer these questions properly, we need to understand the nature of “trust” and the extent to which legislation can be a source of it, and what other sources should be enlisted …


Atteinte À La Vie Privée Et Publicité Comportementale, Virginie Blanchette-Séguin Jan 2014

Atteinte À La Vie Privée Et Publicité Comportementale, Virginie Blanchette-Séguin

Canadian Journal of Law and Technology

Le présent texte aura pour objet les questions relatives à la vie privée que soulève la publicité comportementale et le suivi des activités des individus qu’elle implique par définition. Pour ce faire, nous délimiterons d’abord le spectre du droit à la vie privée en droit québécois dans ce contexte (I.) et nous poursuivrons selon une approche plus critique en nous prononçant sur les différents arguments pouvant être soulevés quant à l’absence d’une perception humaine dans une violation potentielle du droit à la vie privée (II.)


Fan Fiction And Canadian Copyright Law: Defending Fan Narratives In The Wake Of Canada's Copyright Reforms, Rebecca Katz Jan 2014

Fan Fiction And Canadian Copyright Law: Defending Fan Narratives In The Wake Of Canada's Copyright Reforms, Rebecca Katz

Canadian Journal of Law and Technology

Amateur, non-commercial writing based on contemporary copyrighted works — “fan fiction” — is a practice that is worth defending despite its unclear status vis a vis copyright law. In this article, I assess how Canadian fan authors may defend their works using Canadian copyright law. I argue that the recent copyright reforms are promising for fan and other second generation creators. The new fair dealing categories of parody and satire are positive steps, though the broad and technologically neutral non-commercial user-generated content provi-sion may be the most promising reform of all. I begin with an exploration of the benefits of …


Understanding And Contextualizing Precedents In E-Discovery: The Illusion Of Stare Decisis And Best Practices To Avoid Reliance On Outdated Guidance, Jonathan M. Redgrave, Keltie Hays Peay, Mathea K.E. Bulander Jan 2014

Understanding And Contextualizing Precedents In E-Discovery: The Illusion Of Stare Decisis And Best Practices To Avoid Reliance On Outdated Guidance, Jonathan M. Redgrave, Keltie Hays Peay, Mathea K.E. Bulander

Richmond Journal of Law & Technology

But as precedents survive like the clavicle in the cat, long after the use they once served is at an end, and the reason for them has been forgotten, the result of following them must often be failure and confusion from the merely logical point of view.


Cover Letter, Laura M. Bedson Jan 2014

Cover Letter, Laura M. Bedson

Richmond Journal of Law & Technology

The Richmond Journal of Law and Technology is pleased to present the first issue of the Twenty-First Volume. With its first publication in 1995, JOLT became the world’s first law review to be published exclusively online. It was with that original publication that JOLT established itself as one of the leading publications in the legal technology field. Today, JOLT has continued the bold tradition of publishing articles to further scholarship in areas of new and emerging fields that fall at the intersection of technology and the law.


Clapper V. Amnesty International And Data Privacy Litigation: Is A Change To The Law “Certainly Impending”?, John L. Jacobus, Benjamin B. Watson Jan 2014

Clapper V. Amnesty International And Data Privacy Litigation: Is A Change To The Law “Certainly Impending”?, John L. Jacobus, Benjamin B. Watson

Richmond Journal of Law & Technology

On December 19, 2013, the retailer Target announced that unauthorized third parties had gained access to its customer payment information. While Target originally estimated that the security breach affected 40 million of its customers, a subsequent investigation revealed that anywhere from 70 to 110 million people—almost one in three Americans—may have had their sensitive payment information stolen. In response, the retailer offered free credit monitoring services and assured affected customers that they would not be responsible for fraudulent charges made with their payment information.


Legal Phantoms In Cyberspace: The Problematic Status Of Information As A Weapon And A Target Under International Humanitarian Law, Jack M. Beard Jan 2014

Legal Phantoms In Cyberspace: The Problematic Status Of Information As A Weapon And A Target Under International Humanitarian Law, Jack M. Beard

Vanderbilt Journal of Transnational Law

Reports of state-sponsored harmful cyber intrusions abound. The prevailing view among academics holds that if the effects or consequences of such intrusions are sufficiently damaging, international humanitarian law (IHL) should generally govern them--and recourse to armed force may also be justified against states responsible for these actions under the jus ad bellum. This Article argues, however, that there are serious problems and perils in relying on analogies with physical armed force to extend these legal regimes to most events in cyberspace. Armed conflict models applied to the use of information as a weapon and a target are instead likely to …


More Than The Sum Of All Parts: Taking On Ip And It Theft Through A Global Partnership, Andrew F. Popper Jan 2014

More Than The Sum Of All Parts: Taking On Ip And It Theft Through A Global Partnership, Andrew F. Popper

Scholarly Articles in Law Reviews & Journals

The core of this Article describes some of the efforts, both within and outside the United States, to control the epidemic of intellectual property and information technology (IP and IT) theft. Those engaged in the battle include prosecutors and judges, individuals and trade associations, and politicians and policymakers from all points on the political spectrum. And yet, even with so many forces working to stem the tide, the losses are staggering.

An innovator with the potential to change his or her future as well as the prosperity of the surrounding economy, whether in Kentucky or Kinshasa, will be dissuaded from …


Maryland Personal Jurisdiction Law In The Cyberspace Content, Saad Gul Jan 2014

Maryland Personal Jurisdiction Law In The Cyberspace Content, Saad Gul

University of Baltimore Law Forum

A century ago, personal jurisdiction largely hinged on a simple litmus test: the defendant’s presence in the forum state. The issue of personal jurisdiction gained prevalence as the nation evolved from its earlier days of detached, semi-sovereign entities, whose citizens rarely interacted, to a nation where interstate commerce had increased, with interstate litigation growing correspondingly. In Pennoyer v. Neff, the Supreme Court of the United States effectively limited a state’s jurisdiction to persons physically present within its territorial borders. However, in today’s increasingly interconnected world, physical presence appears to represent an anachronism set in the post-Civil War, horse-and-buggy America of …