Open Access. Powered by Scholars. Published by Universities.®

Forensic Science and Technology Commons

Open Access. Powered by Scholars. Published by Universities.®

2016

Discipline
Institution
Keyword
Publication
Publication Type

Articles 31 - 60 of 85

Full-Text Articles in Forensic Science and Technology

Reverse Engineering A Nit That Unmasks Tor Users, Matthew Miller, Joshua Stroschein, Ashley Podhradsky May 2016

Reverse Engineering A Nit That Unmasks Tor Users, Matthew Miller, Joshua Stroschein, Ashley Podhradsky

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper is a case study of a forensic investigation of a Network Investigative Technique (NIT) used by the FBI to deanonymize users of a The Onion Router (Tor) Hidden Service. The forensic investigators were hired by the defense to determine how the NIT worked. The defendant was ac- cused of using a browser to access illegal information. The authors analyzed the source code, binary files and logs that were used by the NIT. The analysis was used to validate that the NIT collected only necessary and legally authorized information. This paper outlines the publicly available case details, how the …


Malware In The Mobile Device Android Environment, Diana Hintea, Robert Bird, Andrew Walker May 2016

Malware In The Mobile Device Android Environment, Diana Hintea, Robert Bird, Andrew Walker

Annual ADFSL Conference on Digital Forensics, Security and Law

exploit smartphone operating systems has exponentially expanded. Android has become the main target to exploit due to having the largest install base amongst the smartphone operating systems and owing to the open access nature in which application installations are permitted. Many Android users are unaware of the risks associated with a malware infection and to what level current malware scanners protect them. This paper tests how efficient the currently available malware scanners are. To achieve this, ten representative Android security products were selected and tested against a set of 5,560 known and categorized Android malware samples. The tests were carried …


Forensic Analysis Of Smartphone Applications For Privacy Leakage, Diana Hintea, Chrysanthi Taramonli, Robert Bird, Rezhna Yusuf May 2016

Forensic Analysis Of Smartphone Applications For Privacy Leakage, Diana Hintea, Chrysanthi Taramonli, Robert Bird, Rezhna Yusuf

Annual ADFSL Conference on Digital Forensics, Security and Law

Smartphone and tablets are personal devices that have diffused to near universal ubiquity in recent years. As Smartphone users become more privacy-aware and -conscious, research is needed to understand how “leakage” of private information (personally identifiable information – PII) occurs. This study explores how leakage studies in Droid devices should be adapted to Apple iOS devices. The OWASP Zed Attack Proxy (ZAP) is examined for 50 apps in various categories. This study confirms that: (1) most apps transmit unencrypted sensitive PII, (2) SSL is used by some recipient websites, but without corresponding app compliance with SSL, and (3) most apps …


Inferring Previously Uninstalled Applications From Residual Partial Artifacts, Jim Jones, Tahir Khan, Kathryn Laskey, Alex Nelson, Mary Laamanen, Douglas White May 2016

Inferring Previously Uninstalled Applications From Residual Partial Artifacts, Jim Jones, Tahir Khan, Kathryn Laskey, Alex Nelson, Mary Laamanen, Douglas White

Annual ADFSL Conference on Digital Forensics, Security and Law

In this paper, we present an approach and experimental results to suggest the past presence of an application after the application has been uninstalled and the system has remained in use. Current techniques rely on the recovery of intact artifacts and traces, e.g., whole files, Windows Registry entries, or log file entries, while our approach requires no intact artifact recovery and leverages trace evidence in the form of residual partial files. In the case of recently uninstalled applications or an instrumented infrastructure, artifacts and traces may be intact and complete. In most cases, however, digital artifacts and traces are al- …


One-Time Pad Encryption Steganography System, Michael J. Pelosi, Gary Kessler, Michael Scott S. Brown May 2016

One-Time Pad Encryption Steganography System, Michael J. Pelosi, Gary Kessler, Michael Scott S. Brown

Annual ADFSL Conference on Digital Forensics, Security and Law

In this paper we introduce and describe a novel approach to adaptive image steganography which is combined with One-Time Pad encryption, and demonstrate the software which implements this methodology. Testing using the state-of-the-art steganalysis software tool StegExpose concludes the image hiding is reliably secure and undetectable using reasonably-sized message payloads (≤25% message bits per image pixel; bpp). Payload image file format outputs from the software include PNG, BMP, JP2, JXR, J2K, TIFF, and WEBP. A variety of file output formats is empirically important as most steganalysis programs will only accept PNG, BMP, and possibly JPG, as the file inputs.

Keywords: …


Applying Grounded Theory Methods To Digital Forensics Research, Ahmed Almarzooqi, Andrew Jones, Richard Howley May 2016

Applying Grounded Theory Methods To Digital Forensics Research, Ahmed Almarzooqi, Andrew Jones, Richard Howley

Annual ADFSL Conference on Digital Forensics, Security and Law

Deciding on a suitable research methodology is challenging for researchers. In this paper, grounded theory is presented as a systematic and comprehensive qualitative methodology in the emergent field of digital forensics research. This paper applies grounded theory in a digital forensics research project undertaken to study how organisations build and manage digital forensics capabilities. This paper gives a step-by-step guideline to explain the procedures and techniques of using grounded theory in digital forensics research. The paper gives a detailed explanation of how the three grounded theory coding methods (open, axial, and selective coding) can be used in digital forensics research. …


Covert6: A Tool To Corroborate The Existence Of Ipv6 Covert Channels, Raymond A. Hansen, Lourdes Gino, Dominic Savio May 2016

Covert6: A Tool To Corroborate The Existence Of Ipv6 Covert Channels, Raymond A. Hansen, Lourdes Gino, Dominic Savio

Annual ADFSL Conference on Digital Forensics, Security and Law

Covert channels are any communication channel that can be exploited to transfer information in a manner that violates the system’s security policy. Research in the field has shown that, like many communication channels, IPv4 and the TCP/IP protocol suite have been susceptible to covert channels, which could be exploited to leak data or be used for anonymous communications. With the introduction of IPv6, researchers are acutely aware that many vulnerabilities of IPv4 have been remediated in IPv6. However, a proof of concept covert channel system was demonstrated in 2006. A decade later, IPv6 and its related protocols have undergone major …


Acceleration Of Statistical Detection Of Zero-Day Malware In The Memory Dump Using Cuda-Enabled Gpu Hardware, Igor Korkin, Iwan Nesterow May 2016

Acceleration Of Statistical Detection Of Zero-Day Malware In The Memory Dump Using Cuda-Enabled Gpu Hardware, Igor Korkin, Iwan Nesterow

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper focuses on the anticipatory enhancement of methods of detecting stealth software. Cyber security detection tools are insufficiently powerful to reveal the most recent cyber-attacks which use malware. In this paper, we will present first an idea of the highest stealth malware, as this is the most complicated scenario for detection because it combines both existing anti-forensic techniques together with their potential improvements. Second, we will present new detection methods which are resilient to this hidden prototype. To help solve this detection challenge, we have analyzed Windows’ memory content using a new method of Shannon Entropy calculation; methods of …


Using Computer Behavior Profiles To Differentiate Between Users In A Digital Investigation, Shruti Gupta, Marcus Rogers May 2016

Using Computer Behavior Profiles To Differentiate Between Users In A Digital Investigation, Shruti Gupta, Marcus Rogers

Annual ADFSL Conference on Digital Forensics, Security and Law

Most digital crimes involve finding evidence on the computer and then linking it to a suspect using login information, such as a username and a password. However, login information is often shared or compromised. In such a situation, there needs to be a way to identify the user without relying exclusively on login credentials. This paper introduces the concept that users may show behavioral traits which might provide more information about the user on the computer. This hypothesis was tested by conducting an experiment in which subjects were required to perform common tasks on a computer, over multiple sessions. The …


Current Challenges And Future Research Areas For Digital Forensic Investigation, David Lillis, Brett A. Becker, Tadhg O’Sullivan, Mark Scanlon May 2016

Current Challenges And Future Research Areas For Digital Forensic Investigation, David Lillis, Brett A. Becker, Tadhg O’Sullivan, Mark Scanlon

Annual ADFSL Conference on Digital Forensics, Security and Law

Given the ever-increasing prevalence of technology in modern life, there is a corresponding increase in the likelihood of digital devices being pertinent to a criminal investigation or civil litigation. As a direct consequence, the number of investigations requiring digital forensic expertise is resulting in huge digital evidence backlogs being encountered by law enforcement agencies throughout the world. It can be anticipated that the number of cases requiring digital forensic analysis will greatly increase in the future. It is also likely that each case will require the analysis of an increasing number of devices including computers, smartphones, tablets, cloud-based services, Internet …


Forensic Analysis Of Ares Galaxy Peer-To-Peer Network, Frank Kolenbrander, Nhien-An Le-Khac, Tahar Kechadi May 2016

Forensic Analysis Of Ares Galaxy Peer-To-Peer Network, Frank Kolenbrander, Nhien-An Le-Khac, Tahar Kechadi

Annual ADFSL Conference on Digital Forensics, Security and Law

Child Abuse Material (CAM) is widely available on P2P networks. Over the last decade several tools were made for 24/7 monitoring of peer-to-peer (P2P) networks to discover suspects that use these networks for downloading and distribution of CAM. For some countries the amount of cases generated by these tools is so great that Law Enforcement (LE) just cannot handle them all. This is not only leading to backlogs and prioritizing of cases but also leading to discussions about the possibility of disrupting these networks and sending warning messages to potential CAM offenders. Recently, investigators are reporting that they are creating …


Keynote Speaker, Chuck Easttom May 2016

Keynote Speaker, Chuck Easttom

Annual ADFSL Conference on Digital Forensics, Security and Law

Conference Keynote Speaker, Chuck Easttom


The Csi Effect: Fact Or Fiction?, Kavita Alejo May 2016

The Csi Effect: Fact Or Fiction?, Kavita Alejo

Themis: Research Journal of Justice Studies and Forensic Science

The CSI effect has been a subject undergoing intense scrutiny in recent years. With the ever-increasing number of television shows, such as CSI and all of its spinoffs, that poorly represent the field of forensic science, there has also been a growing concern over the effects that media has on the legal system. Prosecutors argue that the CSI effect raises their burden of proof and makes jurors more likely to acquit in cases involving little or no forensic evidence, while defense lawyers claim that jurors are more inclined to wrongfully convict based on their unrealistic perceptions of forensic evidence. This …


Applications Of Forensic Evidence In Criminal Cases, Emily Wheeler May 2016

Applications Of Forensic Evidence In Criminal Cases, Emily Wheeler

Themis: Research Journal of Justice Studies and Forensic Science

In 2003, Massachusetts governor Mitt Romney proposed a plan for an infallible death penalty that required irrefutable scientific evidence, effectively removing any doubt regarding potential innocence in death penalty cases. Forensic science encompasses many scientific disciplines including natural sciences and pattern analysis, but not all such areas experience equal amounts of general acceptance or influence in criminal cases. While DNA analysis and fingerprint identification using the Integrated Automated Fingerprint Identification System (IAFIS) are both widely accepted forensic applications, recent events expose concerns regarding the authenticity of other disciplines such as hair and bite mark comparison. Before policymakers address the issue …


The Utilization Of Mobile Technology For Crime Scene Investigation In The San Francisco Bay Area, Marc Logrande May 2016

The Utilization Of Mobile Technology For Crime Scene Investigation In The San Francisco Bay Area, Marc Logrande

Themis: Research Journal of Justice Studies and Forensic Science

The research presented aims to explore factors affecting the decision to adopt a mobile crime scene investigation application in police departments throughout the San Francisco Bay Area. To accomplish this goal, the mobile technology acceptance model was used in designing a survey for data collection. This model utilizes four categories to interpret the factors that influence a police officer’s decision to accept or reject mobile technologies: performance, security and reliability, management style, and cognitive acceptance. Nine police departments were sampled through a series of in-person and over-the-phone interviews to obtain data regarding factors affecting the adoption of a mobile crime …


Beyond Dna: Epigenetics And Proteomics In Forensic Science, Diane F. Eilerts May 2016

Beyond Dna: Epigenetics And Proteomics In Forensic Science, Diane F. Eilerts

Themis: Research Journal of Justice Studies and Forensic Science

The use of genetic evidence in criminal cases is well established and has improved the public opinion and credibility of forensic science. However, several shortcomings associated with current genetic profiling techniques exist. Scientific research aimed at increasing the overall knowledge and understanding of biological factors will lead to the development of methods capable of improving the discriminating power of DNA evidence, overcoming limitations associated with DNA evidence, or complementing current methods of DNA profiling. Increased research in the fields of epigenetics and proteomics are particularly promising and relevant to forensic science. Research suggests that epigenetic biomarkers can be used to …


Form-Blindness And Its Implications: A Verification Study, Meredith G. Moody May 2016

Form-Blindness And Its Implications: A Verification Study, Meredith G. Moody

Honors Theses

Form-blindness is not an eye problem. It is a perceptual inability to distinguish the small differences between shapes, colors, and patterns. This research examines this phenomenon by using a previously-established exam to study form-blindness and its implications. Demographic variables such as age, major, GPA, and sex are also looked at to see what potential impact they might have on a person’s performance on the exam. The form-blindness tests administered during this study were graded and then analyzed using descriptive statistics and multiple linear regression. In the end, no statistical significance was found for the demographic variables of age, GPA, major, …


A Validation Study Of Zar-Pro Fluorescent Blood Lifting Strips, Carter L. Depew May 2016

A Validation Study Of Zar-Pro Fluorescent Blood Lifting Strips, Carter L. Depew

Honors Theses

It is well known within the latent fingerprint discipline that collection of bloody impressions can be difficult and destructive. This pilot study aims to validate the use of Zar-Pro Fluorescent Blood Lifting Strips© in the collection of bloody fingerprint impressions, and then compare the technique outcomes that of the currently used method – photography. This study used both collection methods to extract bloody impressions from white copy paper and aluminum metal. The impressions were aged over a two-week period prior to collection. A numerical score – representative of the identifiable minutiae points – was then obtained using the Smart Extract …


Program And Proceedings: Nebraska Academy Of Sciences 1880–2016, 136th Anniversary Year, One Hundred-Twenty-Sixth Annual Meeting Apr 2016

Program And Proceedings: Nebraska Academy Of Sciences 1880–2016, 136th Anniversary Year, One Hundred-Twenty-Sixth Annual Meeting

Nebraska Academy of Sciences: Programs and Proceedings

Program

Aeronautics and Space Science

Chemistry and Physics

Collegiate Academy: Biology

Earth Science

Biological and Medical Sciences

Anthropology

Collegiate Academy: Chemistry and Physics

Environmental Sciences

Aeronautics and Space Science, Poster Session

Maiben Memorial Lecture: Juliane Soukup, “Riboswitches Turn Students onto Research” Teaching of Science and Mathematics

Applied Science and Technology

History and Philosophy of Science


A Cyber Forensics Needs Analysis Survey: Revisiting The Domain's Needs A Decade Later, Vikram S. Harichandran, Frank Breitinger, Ibrahim Baggili, Andrew Marrington Mar 2016

A Cyber Forensics Needs Analysis Survey: Revisiting The Domain's Needs A Decade Later, Vikram S. Harichandran, Frank Breitinger, Ibrahim Baggili, Andrew Marrington

Electrical & Computer Engineering and Computer Science Faculty Publications

The number of successful cyber attacks continues to increase, threatening financial and personal security worldwide. Cyber/digital forensics is undergoing a paradigm shift in which evidence is frequently massive in size, demands live acquisition, and may be insufficient to convict a criminal residing in another legal jurisdiction. This paper presents the findings of the first broad needs analysis survey in cyber forensics in nearly a decade, aimed at obtaining an updated consensus of professional attitudes in order to optimize resource allocation and to prioritize problems and possible solutions more efficiently. Results from the 99 respondents gave compelling testimony that the following …


A Method And A Case Study For The Selection Of The Best Available Tool For Mobile Device Forensics Using Decision Analysis, Shahzad Saleem, Oliver Popov, Ibrahim Baggili Mar 2016

A Method And A Case Study For The Selection Of The Best Available Tool For Mobile Device Forensics Using Decision Analysis, Shahzad Saleem, Oliver Popov, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

The omnipresence of mobile devices (or small scale digital devices - SSDD) and more importantly the utility of their associated applications for our daily activities, which range from financial transactions to learning, and from entertainment to distributed social presence, create an abundance of digital evidence for each individual. Some of the evidence may be a result of illegal activities that need to be identified, understood and eventually prevented in the future. There are numerous tools for acquiring and analyzing digital evidence extracted from mobile devices. The diversity of SSDDs, types of evidence generated and the number of tools used to …


Quick Mass Screening Methods Of Potential Mass Murderers & Killers By Car Accidents From Recent Facial Photographs, Yoshiaki Omura Jan 2016

Quick Mass Screening Methods Of Potential Mass Murderers & Killers By Car Accidents From Recent Facial Photographs, Yoshiaki Omura

NYMC Faculty Conference Abstracts

Recently, there have been many mass murders of innocent people in various places. We found simple, quick, reliable method of detecting those potential murderers. These potential murderers can be screened from pupils of facial photographs used for various application forms in less than 4 min. by finding large negative value of (-)9~(-)12 of abnormal opening (-) of non-invasive O-Ring Test in one or both sides of the pupil, using BDORT which received US patent in 1993. Presence or absence of microorganism infection can be screened non-invasively by the use of broad-spectrum anti-viral, anti-bacterial, and anti-fungal agent within 3 min. An …


Improving Forensic Software Tool Performance In Detecting Fraud For Financial Statements, Brian Cusack, Tau’Aho Ahokov Jan 2016

Improving Forensic Software Tool Performance In Detecting Fraud For Financial Statements, Brian Cusack, Tau’Aho Ahokov

Australian Digital Forensics Conference

The use of computer forensics is important for forensic accounting practice because most accounting information is in digital forms today. The access to evidence is increasingly more complex and in far greater volumes than in previous decades. The effective and efficient means of detecting fraud are required for the public to maintain their confidence in the reliability of accounting audit and the reputation of accounting firms. The software tools used by forensic accounting can be called into question. Many appear inadequate when faced with the complexity of fraud and there needs to be the development of automated and specialist problem-solving …


Overcoming Human Trafficking Via Operations Research And Analytics: Opportunities For Methods, Models, And Applications, Renata A. Konrad, Andrew C. Trapp, Timothy Palmbach Jan 2016

Overcoming Human Trafficking Via Operations Research And Analytics: Opportunities For Methods, Models, And Applications, Renata A. Konrad, Andrew C. Trapp, Timothy Palmbach

Forensic Science Publications

Human trafficking is a transnational complex societal and economic issue. While human trafficking has been studied in a variety of contexts, including criminology, sociological, and clinical domains, to date there has been very little coverage in the operations research (OR) and analytics community. This paper highlights how operations research and analytics techniques can be used to address the growing issue of human trafficking. It is intended to give insight to operations research and analytics professionals into the unique concerns, problems, and challenges in human trafficking; the relevance of OR and analytics to key pillars of human trafficking including prevention, protection, …


Species Identification Of Golden And Bald Eagle Talons Using Morphometrics, Avery J. Appleton, R. Christopher O'Brien, Pepper W. Trail Jan 2016

Species Identification Of Golden And Bald Eagle Talons Using Morphometrics, Avery J. Appleton, R. Christopher O'Brien, Pepper W. Trail

Forensic Science Publications

The Golden Eagle (Aquila chrysaetos) and Bald Eagle (Haliaeetus leucocephalus) are the largest avian predators in North America, and are thus species of great ecological importance and cultural significance. There is a long history of human use of eagle body parts, and this use continues today: Bald and Golden eagles are among the North American birds most affected by the illegal wildlife trade. Detached eagle talons are often recovered in both law enforcement and archaeological contexts, but data to allow morphological identification of these talons have been lacking. This study documents measureable differences in the morphology of Bald Eagle and …


Screening Of Exosomal Micrornas From Colorectal Cancer Cells, Cillian Clancy, Sonja Khan, Claire L. Glynn, Emma Holian, Peter Dockery, Pierce Lalor, James A.L. Brown, Myles Joyce, Michael J. Kerin, Roisin M. Dwyer Jan 2016

Screening Of Exosomal Micrornas From Colorectal Cancer Cells, Cillian Clancy, Sonja Khan, Claire L. Glynn, Emma Holian, Peter Dockery, Pierce Lalor, James A.L. Brown, Myles Joyce, Michael J. Kerin, Roisin M. Dwyer

Forensic Science Publications

BACKGROUND: Cells release extracellular membrane vesicles including microvesicles known as exosomes. Exosomes contain microRNAs (miRNAs) however the full range within colorectal cancer cell secreted exosomes is unknown. OBJECTIVE: To identify the full range of exosome encapsulated miRNAs secreted from 2 colorectal cancer cell lines and to investigate engineering of exosomes over-expressing miRNAs. METHODS: Exosomes were isolated from HCT-116 and HT-29 cell lines. RNA was extracted from exosomes and microRNA array performed. Cells were engineered to express miR-379 (HCT-116-379) or a non-targeting control (HCT-116-NTC) and functional effects were determined. Exosomes secreted by engineered cells were transferred to recipient cells and the …


Bytewise Approximate Matching: The Good, The Bad, And The Unknown, Vikram S. Harichandran, Frank Breitinger, Ibrahim Baggili Jan 2016

Bytewise Approximate Matching: The Good, The Bad, And The Unknown, Vikram S. Harichandran, Frank Breitinger, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

Hash functions are established and well-known in digital forensics, where they are commonly used for proving integrity and file identification (i.e., hash all files on a seized device and compare the fingerprints against a reference database). However, with respect to the latter operation, an active adversary can easily overcome this approach because traditional hashes are designed to be sensitive to altering an input; output will significantly change if a single bit is flipped. Therefore, researchers developed approximate matching, which is a rather new, less prominent area but was conceived as a more robust counterpart to traditional hashing. Since the conception …


A Study Of The Fepac Accredited Graduate Forensic Science Programs' Curricula, Catherine Genice Rushton Jan 2016

A Study Of The Fepac Accredited Graduate Forensic Science Programs' Curricula, Catherine Genice Rushton

Theses, Dissertations and Capstones

The National Institute of Justice (1999) and the National Academy of Sciences (2009) recommended that forensic science training shift from on-the-job training to formal education. However, the reports cited inconsistencies in the curricula of the forensic science degree programs as an impediment to this. The Forensic Science Education Programs Accreditation Commission (FEPAC) Standards were created to address this issue; however, no studies have been conducted to determine how the accreditation standards have been implemented by the FEPAC accredited graduate programs. This study evaluated the self-study responses (n=11) and website information (n=17) specific to FEPAC’s Graduate Curriculum Standards to determine how …


Exploring Deviant Hacker Networks (Dhm) On Social Media Platforms, Samer Al-Khateeb, Kevin J. Conlan, Nitin Agarwal, Ibrahim Baggili, Frank Breitinger Jan 2016

Exploring Deviant Hacker Networks (Dhm) On Social Media Platforms, Samer Al-Khateeb, Kevin J. Conlan, Nitin Agarwal, Ibrahim Baggili, Frank Breitinger

Journal of Digital Forensics, Security and Law

Online Social Networks (OSNs) have grown exponentially over the past decade. The initial use of social media for benign purposes (e.g., to socialize with friends, browse pictures and photographs, and communicate with family members overseas) has now transitioned to include malicious activities (e.g., cybercrime, cyberterrorism, and cyberwarfare). These nefarious uses of OSNs poses a significant threat to society, and thus requires research attention. In this exploratory work, we study activities of one deviant groups: hacker groups on social media, which we term Deviant Hacker Networks (DHN). We investigated the connection between different DHNs on Twitter: how they are connected, identified …


Log Analysis Using Temporal Logic And Reconstruction Approach: Web Server Case, Murat Gunestas, Zeki Bilgin Jan 2016

Log Analysis Using Temporal Logic And Reconstruction Approach: Web Server Case, Murat Gunestas, Zeki Bilgin

Journal of Digital Forensics, Security and Law

We present a post-mortem log analysis method based on Temporal Logic (TL), Event Processing Language (EPL), and reconstruction approach. After showing that the proposed method could be adapted to any misuse event or attack, we specifically investigate the case of web server misuses. To this end, we examine 5 different misuses on Wordpress web servers, and generate corresponding log files of these attacks for forensic analysis. Then we establish attack patterns and formalize them by means of a special case of temporal logic, i.e. many sorted first order metric temporal logic (MSFOMTL). Later on, we implement these attack patterns in …