Open Access. Powered by Scholars. Published by Universities.®

Forensic Science and Technology Commons

Open Access. Powered by Scholars. Published by Universities.®

2015

Discipline
Institution
Keyword
Publication
Publication Type

Articles 1 - 30 of 68

Full-Text Articles in Forensic Science and Technology

Touch Dna In A Complicated Alleged Child Abuse Case, Heather Miller Coyle Dec 2015

Touch Dna In A Complicated Alleged Child Abuse Case, Heather Miller Coyle

Forensic Science Publications

Touch DNA can be of use in establishing what may have occurred through reconstruction of events based on biological evidence transfer. However, interpretation of results and patterns must be approached with some caution as in the alleged child abuse case detailed here. This case was brought forward as a touch DNA and body fluid case where the male in question was a father reported to have forced a young child to perform oral sex on him. Her pajamas were collected and evaluated for presence of body fluids and associated DNA. The sleeves of the pajamas tested positive for amylase, a …


High Resolution Melt Analysis Of Samples With Differential Dna Methylation To Identify Tissue Source Of Origin, Stephanie M. Ledgerwood Dec 2015

High Resolution Melt Analysis Of Samples With Differential Dna Methylation To Identify Tissue Source Of Origin, Stephanie M. Ledgerwood

Master's Theses

In Forensic Science casework, identifying the source of a tissue can assist in crime scene reconstruction. Currently, presumptive testing methods to identify tissue type are utilized in crime scene laboratories, but there is a need for a more reliable confirmatory test for tissue type identification. High Resolution Melt (HRM) analysis is an innovative technology that has the potential to determine tissue types through variations in DNA methylation patterns. Recently, DNA methylation patterns have been found to correspond with specific tissue types in particular regions of DNA. Two markers, B_SPTB_03 and DDX4 have been effective in differentiating sperm from other tissue …


Whatsapp Network Forensics: Decrypting And Understanding The Whatsapp Call Signaling Messages, Filip Karpisek, Ibrahim Baggili, Frank Breitinger Oct 2015

Whatsapp Network Forensics: Decrypting And Understanding The Whatsapp Call Signaling Messages, Filip Karpisek, Ibrahim Baggili, Frank Breitinger

Electrical & Computer Engineering and Computer Science Faculty Publications

WhatsApp is a widely adopted mobile messaging application with over 800 million users. Recently, a calling feature was added to the application and no comprehensive digital forensic analysis has been performed with regards to this feature at the time of writing this paper. In this work, we describe how we were able to decrypt the network traffic and obtain forensic artifacts that relate to this new calling feature which included the: a) WhatsApp phone numbers, b) WhatsApp server IPs, c) WhatsApp audio codec (Opus), d) WhatsApp call duration, and e) WhatsApp's call termination. We explain the methods and tools used …


Professor Frank Breitinger's Full Bibliography, Frank Breitinger Oct 2015

Professor Frank Breitinger's Full Bibliography, Frank Breitinger

Electrical & Computer Engineering and Computer Science Faculty Publications

No abstract provided.


A Descriptive Analysis Of The Appropriate Use Of Cognitive Bias Terminology In Forensic Science Literature, Courtney A. Winters, Evelyn M. Buday, Trevor I. Stamper Aug 2015

A Descriptive Analysis Of The Appropriate Use Of Cognitive Bias Terminology In Forensic Science Literature, Courtney A. Winters, Evelyn M. Buday, Trevor I. Stamper

The Summer Undergraduate Research Fellowship (SURF) Symposium

Cognitive bias occurs without a person’s awareness and can affect decision-making abilities. In forensic science, bias can be especially detrimental to making accurate decisions about the evidence in a criminal investigation. There are many academic studies in identifying, describing, and suggesting ways to mitigate cognitive biases in forensic science. Many authors will give a known cognitive science concept a new name or create their own bias. This is a problem in the literature because nobody knows for sure how many published studies are referring to or testing the same phenomena since authors are using different definitions or terminology to describe …


Tracking Criminals On Facebook: A Case Study From A Digital Forensics Reu Program, Daniel Weiss, Gary Warner May 2015

Tracking Criminals On Facebook: A Case Study From A Digital Forensics Reu Program, Daniel Weiss, Gary Warner

Annual ADFSL Conference on Digital Forensics, Security and Law

The 2014 Digital Forensics Research Experience for Undergraduates (REU) Program at the University of Alabama at Birmingham (UAB) focused its summer efforts on tracking criminal forums and Facebook groups. The UAB-REU Facebook team was provided with a list of about 60 known criminal groups on Facebook, with a goal to track illegal information posted in these groups and ultimately store the information in a searchable database for use by digital forensic analysts. Over the course of about eight weeks, the UAB-REU Facebook team created a database with over 400 Facebook groups conducting criminal activity along with over 100,000 unique users …


Towards A Digital Forensics Competency-Based Program: Making Assessment Count, Rose Shumba May 2015

Towards A Digital Forensics Competency-Based Program: Making Assessment Count, Rose Shumba

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper describes an approach that UMUC has initiated to revise its graduate programs to a Competency-Based Education (CBE) curriculum. The approach, which is Learning Demonstration (LD) centric, includes the identification of learning goals and competences, identification and description of the LDs, mapping of the LDs to the competences, scripting the LDs, placing the LDs into the respective courses, validating the developed materials, and the development of the open learning resources. Programs in the Cybersecurity and Information Assurance Department, including the Digital Forensics and Cyber Investigations program, are being revised. An LD centric approach to curriculum development helps align programs …


Phishing Intelligence Using The Simple Set Comparison Tool, Jason Britt, Alan Sprague, Gary Warner May 2015

Phishing Intelligence Using The Simple Set Comparison Tool, Jason Britt, Alan Sprague, Gary Warner

Annual ADFSL Conference on Digital Forensics, Security and Law

Phishing websites, phish, attempt to deceive users into exposing their passwords, user IDs, and other sensitive information by imitating legitimate websites, such as banks, product vendors, and service providers. Phishing investigators need fast automated tools to analyze the volume of phishing attacks seen today. In this paper, we present the Simple Set Comparison tool. The Simple Set Comparison tool is a fast automated tool that groups phish by imitated brand allowing phishing investigators to quickly identify and focus on phish targeting a particular brand. The Simple Set Comparison tool is evaluated against a traditional clustering algorithm over a month's worth …


Identifying Common Characteristics Of Malicious Insiders, Nan Liang, David Biros May 2015

Identifying Common Characteristics Of Malicious Insiders, Nan Liang, David Biros

Annual ADFSL Conference on Digital Forensics, Security and Law

Malicious insiders account for large proportion of security breaches or other kinds of loss for organizations and have drawn attention of both academics and practitioners. Although methods and mechanism have been developed to monitor potential insider via electronic data monitoring, few studies focus on predicting potential malicious insiders. Based on the theory of planned behavior, certain cues should be observed or expressed when an individual performs as a malicious insider. Using text mining to analyze various media content of existing insider cases, we strive to develop a method to identify crucial and common indicators that an individual might be a …


Continuous Monitoring System Based On Systems' Environment, Eli Weintraub, Yuval Cohen May 2015

Continuous Monitoring System Based On Systems' Environment, Eli Weintraub, Yuval Cohen

Annual ADFSL Conference on Digital Forensics, Security and Law

We present a new framework (and its mechanisms) of a Continuous Monitoring System (CMS) having new improved capabilities, and discuss its requirements and implications. The CMS is based on the real-time actual configuration of the system and the environment rather than a theoretic or assumed configuration. Moreover, the CMS predicts organizational damages taking into account chains of impacts among systems' components generated by messaging among software components. In addition, the CMS takes into account all organizational effects of an attack. Its risk measurement takes into account the consequences of a threat, as defines in risk analysis standards. Loss prediction is …


Html5 Zero Configuration Covert Channels: Security Risks And Challenges, Jason Farina, Mark Scanlon, Stephen Kohlmann, Nhien-An Le-Khac, Tahar Kechadi May 2015

Html5 Zero Configuration Covert Channels: Security Risks And Challenges, Jason Farina, Mark Scanlon, Stephen Kohlmann, Nhien-An Le-Khac, Tahar Kechadi

Annual ADFSL Conference on Digital Forensics, Security and Law

In recent months there has been an increase in the popularity and public awareness of secure, cloudless file transfer systems. The aim of these services is to facilitate the secure transfer of files in a peer-to-peer (P2P) fashion over the Internet without the need for centralized authentication or storage. These services can take the form of client installed applications or entirely web browser based interfaces. Due to the P2P nature, there is generally no limit to the file sizes involved or to the volume of data transmitted - and where these limitations do exist they will be purely reliant on …


Measuring Hacking Ability Using A Conceptual Expertise Task, Justin S. Giboney, Jeffrey G. Proudfoot, Sanjay Goel, Joseph S. Valacich May 2015

Measuring Hacking Ability Using A Conceptual Expertise Task, Justin S. Giboney, Jeffrey G. Proudfoot, Sanjay Goel, Joseph S. Valacich

Annual ADFSL Conference on Digital Forensics, Security and Law

Hackers pose a continuous and unrelenting threat to organizations. Industry and academic researchers alike can benefit from a greater understanding of how hackers engage in criminal behavior. A limiting factor of hacker research is the inability to verify that self-proclaimed hackers participating in research actually possess their purported knowledge and skills. This paper presents current work in developing and validating a conceptual-expertise based tool that can be used to discriminate between novice and expert hackers. The implications of this work are promising since behavioral information systems researchers operating in the information security space will directly benefit from the validation of …


Invited Paper - A Profile Of Prolonged, Persistent Ssh Attack On A Kippo Based Honeynet, Craig Valli, Priya Rabadia, Andrew Woodard May 2015

Invited Paper - A Profile Of Prolonged, Persistent Ssh Attack On A Kippo Based Honeynet, Craig Valli, Priya Rabadia, Andrew Woodard

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper is an investigation focusing on activities detected by SSH honeypots that utilised kippo honeypot software. The honeypots were located across a variety of geographical locations and operational platforms. The honeynet has suffered prolonged, persistent and attack from a /24 network which appears to be of Chinese geographical origin. In addition to these attacks, other attackers have been successful in compromising real hosts in a wide range of other countries that were subsequently involved in attacking the honeypot machines in the honeynet.

Keywords: Cyber Security, SSH, Secure Shell, Honeypots, Kippo


Inivited Paper - Potential Changes To Ediscovery Rules In Federal Court: A Discussion Of The Process, Substantive Changes And Their Applicability And Impact On Virginia Practice, Joseph J. Schwerha, Susan L. Mitchell, John W. Bagby May 2015

Inivited Paper - Potential Changes To Ediscovery Rules In Federal Court: A Discussion Of The Process, Substantive Changes And Their Applicability And Impact On Virginia Practice, Joseph J. Schwerha, Susan L. Mitchell, John W. Bagby

Annual ADFSL Conference on Digital Forensics, Security and Law

The Federal Rules of Civil Procedure (FRCP) are subject to a unique process also once used in revising the Federal Rules of Evidence (FRE). Today, this process is followed in revisions of the FRCP, the Federal Rules of Criminal Procedure and the Federal Bankruptcy Rules. This unique rulemaking process differs significantly from traditional notice and comment rulemaking required for a majority of federal regulatory agencies under the Administrative Procedure Act (APA).1 Most notably, rule-making for the federal courts’ procedural matters remain unaffected by the invalidation of legislative veto. It is still widely, but wrongly believed, that the legislative veto was …


On The Network Performance Of Digital Evidence Acquisition Of Small Scale Devices Over Public Networks, Irvin Homem, Spyridon Dosis May 2015

On The Network Performance Of Digital Evidence Acquisition Of Small Scale Devices Over Public Networks, Irvin Homem, Spyridon Dosis

Annual ADFSL Conference on Digital Forensics, Security and Law

While cybercrime proliferates – becoming more complex and surreptitious on the Internet – the tools and techniques used in performing digital investigations are still largely lagging behind, effectively slowing down law enforcement agencies at large. Real-time remote acquisition of digital evidence over the Internet is still an elusive ideal in the combat against cybercrime. In this paper we briefly describe the architecture of a comprehensive proactive digital investigation system that is termed as the Live Evidence Information Aggregator (LEIA). This system aims at collecting digital evidence from potentially any device in real time over the Internet. Particular focus is made …


A Review Of Recent Case Law Related To Digital Forensics: The Current Issues, Kelly A. Cole, Shruti Gupta, Dheeraj Gurugubelli, Marcus K. Rogers May 2015

A Review Of Recent Case Law Related To Digital Forensics: The Current Issues, Kelly A. Cole, Shruti Gupta, Dheeraj Gurugubelli, Marcus K. Rogers

Annual ADFSL Conference on Digital Forensics, Security and Law

Digital forensics is a new field without established models of investigation. This study uses thematic analysis to explore the different issues seen in the prosecution of digital forensic investigations. The study looks at 100 cases from different federal appellate courts to analyze the cause of the appeal. The issues are categorized into one of four categories, ‘search and seizure’, ‘data analysis’, ‘presentation’ and ‘legal issues’. The majority of the cases reviewed related to the search and seizure activity.

Keywords: Computer Investigation, Case Law, Digital Forensics, Legal Issues, and Courts


A New Cyber Forensic Philosophy For Digital Watermarks In The Context Of Copyright Laws, Vinod P. Bhattathiripad, Sneha Sudhakaran, Roshna K. Thalayaniyil May 2015

A New Cyber Forensic Philosophy For Digital Watermarks In The Context Of Copyright Laws, Vinod P. Bhattathiripad, Sneha Sudhakaran, Roshna K. Thalayaniyil

Annual ADFSL Conference on Digital Forensics, Security and Law

The objective of this paper is to propose a new cyber forensic philosophy for watermark in the context of copyright laws for the benefit of the forensic community and the judiciary worldwide. The paper first briefly introduces various types of watermarks, and then situates watermarks in the context of the ideaexpression dichotomy and the copyright laws. It then explains the forensic importance of watermarks and proposes a forensic philosophy for them in the context of copyright laws. Finally, the paper stresses the vital need to incorporate watermarks in the forensic tests to establish software copyright infringement and also urges the …


A Survey Of Software-Based String Matching Algorithms For Forensic Analysis, Yi-Ching Liao May 2015

A Survey Of Software-Based String Matching Algorithms For Forensic Analysis, Yi-Ching Liao

Annual ADFSL Conference on Digital Forensics, Security and Law

Employing a fast string matching algorithm is essential for minimizing the overhead of extracting structured files from a raw disk image. In this paper, we summarize the concept, implementation, and main features of ten software-based string matching algorithms, and evaluate their applicability for forensic analysis. We provide comparisons between the selected software-based string matching algorithms from the perspective of forensic analysis by conducting their performance evaluation for file carving. According to the experimental results, the Shift-Or algorithm (R. Baeza-Yates & Gonnet, 1992) and the Karp-Rabin algorithm (Karp & Rabin, 1987) have the minimized search time for identifying the locations of …


Investigating Forensics Values Of Windows Jump Lists Data, Ahmad Ghafarian May 2015

Investigating Forensics Values Of Windows Jump Lists Data, Ahmad Ghafarian

Annual ADFSL Conference on Digital Forensics, Security and Law

Starting with Windows 7, Microsoft introduced a new feature to the Windows Operating Systems called Jump Lists. Jump Lists stores information about user activities on the host machine. These activities may include links to the recently visited web pages, applications executed, or files processed. Computer forensics investigators may find traces of misuse in Jump Lists auto saved files. In this research, we investigate the forensics values of Jump Lists data. Specifically, we use several tools to view Jump Lists data on a virtual machine. We show that each tool reveal certain types of information about user’s activity on the host …


An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?, Satyendra Gurjar, Ibrahim Baggili, Frank Breitinger, Alice Fischer May 2015

An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?, Satyendra Gurjar, Ibrahim Baggili, Frank Breitinger, Alice Fischer

Annual ADFSL Conference on Digital Forensics, Security and Law

Hash functions are widespread in computer sciences and have a wide range of applications such as ensuring integrity in cryptographic protocols, structuring database entries (hash tables) or identifying known files in forensic investigations. Besides their cryptographic requirements, a fundamental property of hash functions is efficient and easy computation which is especially important in digital forensics due to the large amount of data that needs to be processed when working on cases. In this paper, we correlate the runtime efficiency of common hashing algorithms (MD5, SHA-family) and their implementation. Our empirical comparison focuses on C-OpenSSL, Python, Ruby, Java on Windows and …


Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations, Igor Korkin May 2015

Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations, Igor Korkin

Annual ADFSL Conference on Digital Forensics, Security and Law

Hardware virtualization technologies play a significant role in cyber security. On the one hand these technologies enhance security levels, by designing a trusted operating system. On the other hand these technologies can be taken up into modern malware which is rather hard to detect. None of the existing methods is able to efficiently detect a hypervisor in the face of countermeasures such as time cheating, temporary self-uninstalling, memory hiding etc. New hypervisor detection methods which will be described in this paper can detect a hypervisor under these countermeasures and even count several nested ones. These novel approaches rely on the …


The Use Of Criminal Profilers In The Prosecution Of Serial Killers, Chelsea Van Aken May 2015

The Use Of Criminal Profilers In The Prosecution Of Serial Killers, Chelsea Van Aken

Themis: Research Journal of Justice Studies and Forensic Science

The purpose of this paper is to analyze the concept of criminal profiling in terms of serial killers in the United States. The research provided in this paper was found using the most recent research available on the topic. The FBI’s Behavioral Unit, or National Center for the Analysis of Violent Crime (NCAVC), is the current leading law enforcement agency that investigates these types of crimes. They utilize definitions, typographies, and motives to create a criminal profile to investigate serial killings. Ultimately, these profiles are inadequate because they are inconclusive and exclude multiple suspects that are potentially dangerous. Therefore, criminal …


The "Csi Effect" And Its Potential Impact On Juror Decisions, John Alldredge May 2015

The "Csi Effect" And Its Potential Impact On Juror Decisions, John Alldredge

Themis: Research Journal of Justice Studies and Forensic Science

The “CSI Effect” was first described in the media as a phenomenon resulting from viewing forensic and crime based television shows. This effect influences jurors to have unrealistic expectations of forensic science during a criminal trial and affect jurors’ decisions in the conviction or acquittal process. Research has shown the “CSI Effect” has a possible pro-defense bias, in that jurors are less likely to convict without the presence of some sort of forensic evidence. Some studies show actors in the criminal justice system are changing their tactics, as if this effect has a significant influence, causing them to request unnecessary …


Reducing Contamination In Forensic Science, Carly Balk May 2015

Reducing Contamination In Forensic Science, Carly Balk

Themis: Research Journal of Justice Studies and Forensic Science

The sensitivity of modern forensic techniques has drastically increased, with sensitive technology detecting even the smallest traces of DNA evidence left behind. This has made it possible to detect DNA profiles deposited through contamination. When DNA contamination occurs in forensic science, it has the potential to change the outcome of a criminal investigation and may have significant social and financial repercussions. A compilation of global research shows that DNA evidence transfer can occur during forensic product manufacturing, the fingerprinting process, or even autopsy and crime lab examinations. These vital areas of the forensic investigation are vulnerable to contamination, and national …


Mathematics In Forensic Firearm Examination, Erin N. Zalewski May 2015

Mathematics In Forensic Firearm Examination, Erin N. Zalewski

Renée Crown University Honors Thesis Projects - All

Forensic Science encompasses many disciplines that employ the scientific method to examine, analyze, and interpret physical evidence in the courtroom. The discipline of Forensic Firearm Examination involves the examination and comparison of ballistic evidence components to determine if they came from the same source. In other words, firearm examiners are tasked with determining whether spent cartridge cases or bullets were fired through the same gun. Examination of ballistic evidence can involve the employment of automated matching systems, comparison microscopy, and mathematical analysis. The comparison microscope is the tool of the firearm examiner and allows for the simultaneous view of ballistic …


Program And Proceedings: Nebraska Academy Of Sciences 1880–2015, 135th Anniversary Year, One Hundred-Twenty-Fifth Annual Meeting Apr 2015

Program And Proceedings: Nebraska Academy Of Sciences 1880–2015, 135th Anniversary Year, One Hundred-Twenty-Fifth Annual Meeting

Nebraska Academy of Sciences: Programs and Proceedings

Program

Aeronautics and Space Science

Chemistry and Physics

Collegiate Academy: Biology

Collegiate Academy: Chemistry and Physics

Anthropology

Biological and Medical Sciences

Junior Academy, Senior High Competition

Aeronautics and Space Science, Poster Session

Maiben Memorial Lecture: “Nebraska Biocontainment Unit Planning and Response to Ebola,” Ebola team, University of nebraska medical Center

Applied Science and Technology

Earth Science

Teaching of Science and Math

Junior Academy, Junior High Competition


Brief For Professor Albert E. Scherr As Amicus Curiae In Support Of Petitioner, Albert E. Scherr Feb 2015

Brief For Professor Albert E. Scherr As Amicus Curiae In Support Of Petitioner, Albert E. Scherr

Law Faculty Scholarship

INTRODUCTION AND SUMMARY OF ARGUMENT Professor Scherr agrees with petitioner that review is warranted because the Maryland Court of Appeals decision is erroneous. The Fourth Amendment does not sanction police harvesting of DNA without probable cause and a warrant and without the subject’s knowledge or consent, to be used however the authorities deem appropriate and without restriction. The Maryland Court of Appeals’ decision is contrary to the Supreme Court’s jurisprudence as articulated in the Riley v. California – Maryland v. King – United States v. Jones trilogy. This case fits squarely in the center of the triangle formed by that …


Science 208 Forensic Science Ii: Death Analysis Spring 2015, John Moore Jan 2015

Science 208 Forensic Science Ii: Death Analysis Spring 2015, John Moore

General Science

No abstract provided.


Science 208 Forensic Science Ii: Death Analysis Fall 2015, John Moore Jan 2015

Science 208 Forensic Science Ii: Death Analysis Fall 2015, John Moore

General Science

No abstract provided.


Science 108-001 Essentials Of Forensic Science Fall 2015, Christina Beatty Jan 2015

Science 108-001 Essentials Of Forensic Science Fall 2015, Christina Beatty

General Science

No abstract provided.