Open Access. Powered by Scholars. Published by Universities.®

Forensic Science and Technology Commons

Open Access. Powered by Scholars. Published by Universities.®

University of New Haven

Discipline
Keyword
Publication Year
Publication
Publication Type

Articles 91 - 117 of 117

Full-Text Articles in Forensic Science and Technology

Network And Device Forensic Analysis Of Android Social-Messaging Applications, Daniel Walnycky, Ibrahim Baggili, Andrew Marrington, Jason Moore, Frank Breitinger Jan 2015

Network And Device Forensic Analysis Of Android Social-Messaging Applications, Daniel Walnycky, Ibrahim Baggili, Andrew Marrington, Jason Moore, Frank Breitinger

Electrical & Computer Engineering and Computer Science Faculty Publications

In this research we forensically acquire and analyze the device-stored data and network traffic of 20 popular instant messaging applications for Android. We were able to reconstruct some or the entire message content from 16 of the 20 applications tested, which reflects poorly on the security and privacy measures employed by these applications but may be construed positively for evidence collection purposes by digital forensic practitioners. This work shows which features of these instant messaging applications leave evidentiary traces allowing for suspect data to be reconstructed or partially reconstructed, and whether network forensics or device forensics permits the reconstruction of …


An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?, Satyendra Gurjar, Ibrahim Baggili, Frank Breitinger, Alice E. Fischer Jan 2015

An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?, Satyendra Gurjar, Ibrahim Baggili, Frank Breitinger, Alice E. Fischer

Electrical & Computer Engineering and Computer Science Faculty Publications

Hash functions are widespread in computer sciences and have a wide range of applications such as ensuring integrity in cryptographic protocols, structuring database entries (hash tables) or identifying known files in forensic investigations. Besides their cryptographic requirements, a fundamental property of hash functions is efficient and easy computation which is especially important in digital forensics due to the large amount of data that needs to be processed when working on cases. In this paper, we correlate the runtime efficiency of common hashing algorithms (MD5, SHA-family) and their implementation. Our empirical comparison focuses on C-OpenSSL, Python, Ruby, Java on Windows and …


Testing The Forensic Soundness Of Forensic Examination Environments On Bootable Media, Ahmed F.A.L. Mohamed, Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili Aug 2014

Testing The Forensic Soundness Of Forensic Examination Environments On Bootable Media, Ahmed F.A.L. Mohamed, Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is …


Preliminary Forensic Analysis Of The Xbox One, Jason Moore, Ibrahim Baggili, Andrew Marrington, Armindo Rodrigues Aug 2014

Preliminary Forensic Analysis Of The Xbox One, Jason Moore, Ibrahim Baggili, Andrew Marrington, Armindo Rodrigues

Electrical & Computer Engineering and Computer Science Faculty Publications

Video game consoles can no longer be viewed as just gaming consoles but rather as full multimedia machines, capable of desktop computer-like performance. The past has shown that game consoles have been used in criminal activities such as extortion, identity theft, and child pornography, but with their ever-increasing capabilities, the likelihood of the expansion of criminal activities conducted on or over the consoles increases. This research aimed to take the initial step of understanding the Xbox One, the most powerful Microsoft console to date. We report the outcome of conducting a forensic examination of the Xbox One, and we provide …


Life (Logical Ios Forensics Examiner): An Open Source Ios Backup Forensics Examination Tool, Ibrahim Baggili, Shadi Al Awawdeh, Jason Moore May 2014

Life (Logical Ios Forensics Examiner): An Open Source Ios Backup Forensics Examination Tool, Ibrahim Baggili, Shadi Al Awawdeh, Jason Moore

Electrical & Computer Engineering and Computer Science Faculty Publications

In this paper, we present LiFE (Logical iOS Forensics Examiner), an open source iOS backup forensics examination tool. This tool helps both researchers and practitioners alike in both understanding the backup structures of iOS devices and forensically examining iOS backups. The tool is currently capable of parsing device information, call history, voice messages, GPS locations, conversations, notes, images, address books, calendar entries, SMS messages, Aux locations, facebook data and e-mails. The tool consists of both a manual interface (where the user is able to manually examine the backup structures) and an automated examination interface (where the tool pulls out evidence …


On The Database Lookup Problem Of Approximate Matching, Frank Breitinger, Harald Baier, Douglas White May 2014

On The Database Lookup Problem Of Approximate Matching, Frank Breitinger, Harald Baier, Douglas White

Electrical & Computer Engineering and Computer Science Faculty Publications

Investigating seized devices within digital forensics gets more and more difficult due to the increasing amount of data. Hence, a common procedure uses automated file identification which reduces the amount of data an investigator has to look at by hand. Besides identifying exact duplicates, which is mostly solved using cryptographic hash functions, it is also helpful to detect similar data by applying approximate matching.

Let x denote the number of digests in a database, then the lookup for a single similarity digest has the complexity of O(x). In other words, the digest has to be compared against …


An Experimental Study To Quantify Error Rates Resulting From Measurement Deviation In Area Of Origin Reconstructions Of Blunt Force Impact Patterns, Mark Davison, Timothy Palmbach Apr 2014

An Experimental Study To Quantify Error Rates Resulting From Measurement Deviation In Area Of Origin Reconstructions Of Blunt Force Impact Patterns, Mark Davison, Timothy Palmbach

Forensic Science Publications

The intent of this study was to attempt to quantify error associated with the measurements required in area of origin reconstructions resulting from the analysis of blunt force impact patterns. Mathematical tables were constructed in order to examine trends associated with changing width and length ratios and the influence of impact angle change and area of convergence deviations. The analysis of the trends enabled informed stain selection, mitigating potential error. The analysis of the influence of stain measurement error and gamma angle error was conducted by reconstructing experimentally created blunt force impact patterns using the Tangent Method, comparing the resulting …


Development Of A Quantitative Real-Time Polymerase Chain Reaction (Rt-Pcr) Assay For Plant Species, Kayla Curtis, Heather Miller Coyle Mar 2014

Development Of A Quantitative Real-Time Polymerase Chain Reaction (Rt-Pcr) Assay For Plant Species, Kayla Curtis, Heather Miller Coyle

Forensic Science Publications

In order to facilitate optimal plant DNA quantitation and identification, an assay has been developed that uses generic plant PCR primers that amplify a region in the chloroplast genome of plant samples. The assay uses the SYBR green detection dye to detect the PCR product with a universal PCR primer set to the large subunit of ribulose bisphosphate carboxylase, rbcL, but can be used with any of the universal barcode primers for land plants (rbcL, matK, trnH, psbA). Standard dilutions of control wheat DNA of varying concentrations were tested to create a standard curve. Several plant DNA extractions of different …


Impact Of Tumour Epithelial Subtype On Circulating Micrornas In Breast Cancer Patients, Peadar S. Waters, Roisin M. Dwyer, Cathy Brougham, Claire L. Glynn, Deidre Wall, Peter Hyland, Maria Duignan, Mark Mcloughlin, John Newell, Michael J. Kerin Mar 2014

Impact Of Tumour Epithelial Subtype On Circulating Micrornas In Breast Cancer Patients, Peadar S. Waters, Roisin M. Dwyer, Cathy Brougham, Claire L. Glynn, Deidre Wall, Peter Hyland, Maria Duignan, Mark Mcloughlin, John Newell, Michael J. Kerin

Forensic Science Publications

While a range of miRNAs have been shown to be dysregulated in the circulation of patients with breast cancer, little is known about the relationship between circulating levels and tumour characteristics. The aim of this study was to analyse alterations in circulating miRNA expression during tumour progression in a murine model of breast cancer, and to detemine the clinical relevance of identified miRNAs at both tissue and circulating level in patient samples. Athymic nude mice received a subcutaneous or mammary fat pad injection of MDA-MB-231 cells. Blood sampling was performed at weeks 1, 3 and 6 following tumour induction, and …


Utilizing Dna Analysis To Combat The World Wide Plague Of Present Day Slavery – Trafficking In Persons, Timothy Palmbach, Jeffrey Bloom, Emily Hoynes, Dragan Primorac, Mario Thomas Gaboury Feb 2014

Utilizing Dna Analysis To Combat The World Wide Plague Of Present Day Slavery – Trafficking In Persons, Timothy Palmbach, Jeffrey Bloom, Emily Hoynes, Dragan Primorac, Mario Thomas Gaboury

Forensic Science Publications

A study was conducted to determine if modern forensic DNA typing methods can be properly employed throughout the world with a final goal of increasing arrests, prosecutions, and convictions of perpetrators of modern day trafficking in persons while concurrently reducing the burden of victim testimony in legal proceedings. Without interruption of investigations, collection of samples containing DNA was conducted in a variety of settings. Evidentiary samples were analyzed on the ANDE Rapid DNA system. Many of the collected swabs yielded informative short tandem repeat profiles with Rapid DNA technology.


Unmasking Cancer As A Consequence Of Human Trafficking: A Multidisciplinary Challenge, Barbara Moynihan, Katherine Olive Jan 2014

Unmasking Cancer As A Consequence Of Human Trafficking: A Multidisciplinary Challenge, Barbara Moynihan, Katherine Olive

Forensic Science Publications

This article will focus on the development of cancer as a potential consequence of human trafficking. Various subtle sequelae of trafficking, such as the insidious development of cancer, may not be seen until well after the victim has been freed. There are a myriad of factors that contribute to missed or inadequate health care for victims and survivors of human trafficking. These health care needs (both medical as well as mental health) may be overlooked until many months or years post-trafficking. We will address the risk factors consistent with human trafficking that should be considered by health care professionals who …


An Efficient Similarity Digests Database Lookup -- A Logarithmic Divide And Conquer Approach, Frank Breitinger, Christian Rathgeb, Harald Baier Jan 2014

An Efficient Similarity Digests Database Lookup -- A Logarithmic Divide And Conquer Approach, Frank Breitinger, Christian Rathgeb, Harald Baier

Electrical & Computer Engineering and Computer Science Faculty Publications

Investigating seized devices within digital forensics represents a challenging task due to the increasing amount of data. Common procedures utilize automated file identification, which reduces the amount of data an investigator has to examine manually. In the past years the research field of approximate matching arises to detect similar data. However, if n denotes the number of similarity digests in a database, then the lookup for a single similarity digest is of complexity of O(n). This paper presents a concept to extend existing approximate matching algorithms, which reduces the lookup complexity from O(n) to O(log(n)). Our proposed approach is based …


File Detection On Network Traffic Using Approximate Matching, Frank Breitinger, Ibrahim Baggili Jan 2014

File Detection On Network Traffic Using Approximate Matching, Frank Breitinger, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

In recent years, Internet technologies changed enormously and allow faster Internet connections, higher data rates and mobile usage. Hence, it is possible to send huge amounts of data / files easily which is often used by insiders or attackers to steal intellectual property. As a consequence, data leakage prevention systems (DLPS) have been developed which analyze network traffic and alert in case of a data leak. Although the overall concepts of the detection techniques are known, the systems are mostly closed and commercial. Within this paper we present a new technique for network traffic analysis based on approximate matching (a.k.a …


Quantifying Relevance Of Mobile Digital Evidence As They Relate To Case Types: A Survey And A Guide For Best Practices, Shahzad Saleem, Ibrahim Baggili, Oliver Popov Jan 2014

Quantifying Relevance Of Mobile Digital Evidence As They Relate To Case Types: A Survey And A Guide For Best Practices, Shahzad Saleem, Ibrahim Baggili, Oliver Popov

Electrical & Computer Engineering and Computer Science Faculty Publications

In this work, a survey was conducted to help quantify the relevance of nineteen types of evidence (such as SMS) to seven types of digital investigations associated with mobile devices (MD) (such as child pornography). 97 % of the respondents agreed that every type of digital evidence has a different level of relevance to further or solve a particular investigation. From 55 serious participants, a data set of 5,772 responses regarding the relevance of nineteen types of digital evidence for all the seven types of digital investigations was obtained. The results showed that (i) SMS belongs to the most relevant …


Automated Evaluation Of Approximate Matching Algorithms On Real Data, Frank Breitinger, Vassil Roussev Jan 2014

Automated Evaluation Of Approximate Matching Algorithms On Real Data, Frank Breitinger, Vassil Roussev

Electrical & Computer Engineering and Computer Science Faculty Publications

Bytewise approximate matching is a relatively new area within digital forensics, but its importance is growing quickly as practitioners are looking for fast methods to screen and analyze the increasing amounts of data in forensic investigations. The essential idea is to complement the use of cryptographic hash functions to detect data objects with bytewise identical representation with the capability to find objects with bytewise similarrepresentations.

Unlike cryptographic hash functions, which have been studied and tested for a long time, approximate matching ones are still in their early development stages and evaluation methodology is still evolving. Broadly, prior approaches have …


Ground Penetrating Radar Use In Three Contrasting Soil Textures In Southern Ontario, Amanda C. Lowe, David V. Beresford, David O. Carter, Franco Gaspari, R. Christopher O'Brien, Shari L. Forbes Jul 2013

Ground Penetrating Radar Use In Three Contrasting Soil Textures In Southern Ontario, Amanda C. Lowe, David V. Beresford, David O. Carter, Franco Gaspari, R. Christopher O'Brien, Shari L. Forbes

Forensic Science Publications

Ground penetrating radar (GPR) is a non-invasive, geophysical tool that can be used for the identification of clandestine graves. GPR operates by detecting density differences in soil by the transmission of high frequency electromagnetic waves from an antenna. Domestic pig (Sus scrofa domesticus) carcasses were clothed in 100% cotton t-shirts and 50% cotton/50% polyester briefs, and buried at a consistent depth at three field sites of contrasting soil texture (silty clay loam, fine sand and fine sandy loam) in southern Ontario. GPR was used to detect and monitor the graves for a period of 14 months post-burial. Analysis of collected …


Isolation Of Secreted Micrornas (Mirnas) From Cell-Conditioned Media, Claire L. Glynn, Sonja Khan, Michael J. Kerin, Roisin M. Dwyer Apr 2013

Isolation Of Secreted Micrornas (Mirnas) From Cell-Conditioned Media, Claire L. Glynn, Sonja Khan, Michael J. Kerin, Roisin M. Dwyer

Forensic Science Publications

MicroRNAs (miRNAs) have been found to be stable in the circulation of cancer patients raising their potential as circulating biomarkers of disease. The specific source and role, however, of miRNAs in the circulation is unknown and requires elucidation to determine their true potential. In this study, along with primary tissue explants and primary stromal cells, three breast cancer cell lines were employed, including T47D, MDA-MB-231 and SK-BR-3. Tissue explants were harvested in theatre, with informed patient consent, and included tumour, tumour associated normal, and diseased lymph node samples. Cell-conditioned media containing all factors secreted by the cells were harvested. MiRNAs …


Forensic Analysis Of Social Networking Applications On Mobile Devices, Noora Al Mutawa, Ibrahim Baggili, Andrew Marrington Jan 2012

Forensic Analysis Of Social Networking Applications On Mobile Devices, Noora Al Mutawa, Ibrahim Baggili, Andrew Marrington

Electrical & Computer Engineering and Computer Science Faculty Publications

The increased use of social networking applications on smartphones makes these devices a goldmine for forensic investigators. Potential evidence can be held on these devices and recovered with the right tools and examination methods. This paper focuses on conducting forensic analyses on three widely used social networking applications on smartphones: Facebook, Twitter, and MySpace. The tests were conducted on three popular smartphones: BlackBerrys, iPhones, and Android phones. The tests consisted of installing the social networking applications on each device, conducting common user activities through each application, acquiring a forensically sound logical image of each device, and performing manual forensic analysis …


Ipad2 Logical Acquisition: Automated Or Manual Examination?, Somaya Ali, Sumaya Alhosani, Farah Alzarooni, Ibrahim Baggili Jan 2012

Ipad2 Logical Acquisition: Automated Or Manual Examination?, Somaya Ali, Sumaya Alhosani, Farah Alzarooni, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

Due to their usage increase worldwide, iPads are on the path of becoming key sources of digital evidence in criminal investigations. This research investigated the logical backup acquisition and examination of the iPad2 device using the Apple iTunes backup utility while manually examining the backup data (manual examination) and automatically parsing the backup data (Lantern software-automated examination).The results indicate that a manual examination of the logical backup structure from iTunes reveals more digital evidence, especially if installed application data is required for an investigation. However, the researchers note that if a quick triage is needed of an iOS device, then …


Field Testing Of Collection Cards For Cannabis Sativa Samples With A Single Hexanucleotide Dna Marker, Lindsey Allgeier, John Hemenway, Nicholas Shirley, Tommy Lanier, Heather Miller Coyle Sep 2011

Field Testing Of Collection Cards For Cannabis Sativa Samples With A Single Hexanucleotide Dna Marker, Lindsey Allgeier, John Hemenway, Nicholas Shirley, Tommy Lanier, Heather Miller Coyle

Forensic Science Publications

Abstract:  The validity and feasibility of using DNA collection cards in the field for preservation and analysis of Cannabis sativa genotypes were investigated using a highly specific hexanucleotide marker. Collection cards were submitted to the National Marijuana Initiative, which selectively trained and managed the collection of specific types of samples from a variety of participating agencies. Samples collected at seizure sites included fresh marijuana leaf samples, dried “dispensary” samples, U.S. border seizures, and hashish. Using a standardized PCR kit with custom-labeled oligonucleotide primers specific to marijuana, collection cards produced eight genotypes and 13 different alleles, extremely low baselines, and no …


Survey On Cloud Forensics And Critical Criteria For Cloud Forensic Capability: A Preliminary Analysis, Keyun Ruan, Ibrahim Baggili, Joe Carthy, Tahar Kechadi Jan 2011

Survey On Cloud Forensics And Critical Criteria For Cloud Forensic Capability: A Preliminary Analysis, Keyun Ruan, Ibrahim Baggili, Joe Carthy, Tahar Kechadi

Electrical & Computer Engineering and Computer Science Faculty Publications

In this paper we present the current results and analysis of the survey “Cloud forensics and critical criteria for cloud forensic capability” carried out towards digital forensic experts and practitioners. This survey was created in order to gain a better understanding on some of the key questions of the new field - cloud forensics - before further research and development. We aim to understand concepts such as its definition, the most challenging issues, most valuable research directions, and the critical criteria for cloud forensic capability.


Cat Detect (Computer Activity Timeline Detection): A Tool For Detecting Inconsistency In Computer Activity Timelines, Andrew Marrington, Ibrahim Baggili, George Mohay, Andrew Clark Jan 2011

Cat Detect (Computer Activity Timeline Detection): A Tool For Detecting Inconsistency In Computer Activity Timelines, Andrew Marrington, Ibrahim Baggili, George Mohay, Andrew Clark

Electrical & Computer Engineering and Computer Science Faculty Publications

The construction of timelines of computer activity is a part of many digital investigations. These timelines of events are composed of traces of historical activity drawn from system logs and potentially from evidence of events found in the computer file system. A potential problem with the use of such information is that some of it may be inconsistent and contradictory thus compromising its value. This work introduces a software tool (CAT Detect) for the detection of inconsistency within timelines of computer activity. We examine the impact of deliberate tampering through experiments conducted with our prototype software tool. Based on the …


The Scavenging Behaviour Of The Australian Raven (Corvus Coronoides): Patterns And Influencing Factors, R. Christopher O'Brien, Alexande Larcombe, Jan Meyer, Shari L. Forbes, Ian Dadour Dec 2010

The Scavenging Behaviour Of The Australian Raven (Corvus Coronoides): Patterns And Influencing Factors, R. Christopher O'Brien, Alexande Larcombe, Jan Meyer, Shari L. Forbes, Ian Dadour

Forensic Science Publications

The Australian Raven (Corvus coronoides) is a widespread, abundant corvid which is often considered a pest species, due to the thought that it predates on livestock, ruin crops, and is often seen feeding on refuse, in both urban and rural areas. The species is known to feed on a range of material from seeds in ploughed fields to human refuse and decomposing organic material. A large proportion of its diet consists of carrion, and as such, the Australian Raven is an effective detrivorous species capable of removing and consuming dead and decomposing carcasses. This research examined the scavenging …


Iphone 3gs Forensics: Logical Analysis Using Apple Itunes Backup Utility, Mona Bader, Ibrahim Baggili Sep 2010

Iphone 3gs Forensics: Logical Analysis Using Apple Itunes Backup Utility, Mona Bader, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

The iPhone mobile is used worldwide due to its enhanced computing capabilities, increased storage capacity as well as its attractive touch interface. These characteristics made the iPhone a popular smart phone device. The increased use of the iPhone lead it to become a potential source of digital evidence in criminal investigations. Therefore, iPhone forensics turned into an essential practice for forensic and security practitioners today. This research aimed at investigating and examining the logical backup acquisition of the iPhone 3GS mobile device using the Apple iTunes backup utility. It was found that significant data of forensic value such as e-mail …


Generating System Requirements For A Mobile Digital Evidence Collection System: A Preliminary Step Towards Enhancing The Forensic Collection Of Digital Devices, Ibrahim Baggili Jan 2010

Generating System Requirements For A Mobile Digital Evidence Collection System: A Preliminary Step Towards Enhancing The Forensic Collection Of Digital Devices, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

Collecting digital devices in a forensically sound manner is becoming more critical since 80% of all cases have some sort of digital evidence involved in them (Rogers, 2006, p. 1) .The process of documenting and tagging digital devices is cumbersome and involves details that might not apply to other types of evidence, since each evidence item has unique physical characteristics (Hesitis & Wilbon, 2005, p. 17). The process becomes less manageable when a large number of digital devices are seized. This paper examines the information and issues investigators should be aware of when collecting digital devices at crime scenes. Furthermore, …


Analysis Of Minerals Using Linearly Polarized Infrared Microspectroscopy, Brooke Weinger Kammrath, Pauline E. Leary, John A. Reffner Jul 2009

Analysis Of Minerals Using Linearly Polarized Infrared Microspectroscopy, Brooke Weinger Kammrath, Pauline E. Leary, John A. Reffner

Forensic Science Publications

This is an extended abstract of a paper presented at Microscopy and Microanalysis 2009 in Richmond, Virginia, USA, July 26 – July 30, 2009.


Self-Reported Cyber Crime: An Analysis On The Effects Of Anonymity And Pre-Employment Integrity, Ibrahim Baggili, Marcus Rogers Jan 2009

Self-Reported Cyber Crime: An Analysis On The Effects Of Anonymity And Pre-Employment Integrity, Ibrahim Baggili, Marcus Rogers

Electrical & Computer Engineering and Computer Science Faculty Publications

A key issue facing today’s society is the increase in cyber crimes. Cyber crimes pose threats to nations, organizations and individuals across the globe. Much of the research in cyber crime has risen from computer science-centric programs, and little experimental research has been performed on the psychology of cyber crime. This has caused a knowledge gap in the study of cyber crime. To this end, this research focuses on understanding psychological concepts related to cyber crime. Through an experimental design, participants were randomly assigned to three groups with varying degrees of anonymity. After each treatment, participants were asked to self-report …