Open Access. Powered by Scholars. Published by Universities.®
Forensic Science and Technology Commons™
Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Physical Sciences and Mathematics (735)
- Computer Sciences (639)
- Information Security (617)
- Engineering (565)
- Law (549)
-
- Computer Law (478)
- Computer Engineering (461)
- Electrical and Computer Engineering (452)
- Sociology (167)
- Criminology and Criminal Justice (145)
- Life Sciences (123)
- Public Affairs, Public Policy and Public Administration (100)
- Social Control, Law, Crime, and Deviance (83)
- Defense and Security Studies (82)
- Other Computer Sciences (80)
- OS and Networks (78)
- Criminology (74)
- National Security Law (74)
- Aviation (72)
- Aviation Safety and Security (70)
- Medicine and Health Sciences (63)
- Chemistry (57)
- Anthropology (52)
- Education (39)
- Evidence (36)
- Psychology (33)
- Biology (29)
- Institution
-
- Embry-Riddle Aeronautical University (497)
- University of New Haven (117)
- City University of New York (CUNY) (108)
- Virginia Commonwealth University (78)
- Bridgewater State University (67)
-
- University of Nebraska - Lincoln (57)
- San Jose State University (53)
- University of Central Florida (37)
- West Virginia University (27)
- The University of Southern Mississippi (23)
- Old Dominion University (16)
- Edith Cowan University (12)
- University of Michigan Law School (11)
- Duke Law (10)
- University at Albany, State University of New York (9)
- University of Mississippi (8)
- Duquesne University (6)
- Marshall University (5)
- Minnesota State University, Mankato (5)
- Air Force Institute of Technology (4)
- Long Island University (4)
- Nova Southeastern University (4)
- Parkland College (4)
- Penn State Dickinson Law (4)
- University of New Hampshire (4)
- University of South Florida (4)
- California State University, San Bernardino (3)
- Montclair State University (3)
- SUNY Buffalo State University (3)
- Bowling Green State University (2)
- Keyword
-
- Forensic science (70)
- Digital forensics (65)
- Forensics (39)
- DNA (25)
- Digital Forensics (23)
-
- Computer forensics (22)
- Cybercrime (21)
- Digital evidence (19)
- Cybersecurity (18)
- Forensic (17)
- Forensic anthropology (17)
- Forensic Science (16)
- Privacy (12)
- Blood (11)
- DNA analysis (11)
- Evidence (11)
- Computer Forensics (10)
- Security (10)
- Approximate matching (9)
- Cryptocurrency (9)
- Cyber forensics (9)
- Cyberbullying (9)
- Education (9)
- Forensic entomology (9)
- Mobile device forensics (9)
- Touch DNA (9)
- Investigation (8)
- Law enforcement (8)
- Mrsh-v2 (8)
- Survey (8)
- Publication Year
- Publication
-
- Journal of Digital Forensics, Security and Law (294)
- Annual ADFSL Conference on Digital Forensics, Security and Law (187)
- Student Theses (97)
- Master of Science in Forensic Science Directed Research Projects (75)
- International Journal of Cybersecurity Intelligence & Cybercrime (67)
-
- Electrical & Computer Engineering and Computer Science Faculty Publications (56)
- Themis: Research Journal of Justice Studies and Forensic Science (43)
- Honors Theses (34)
- Forensic Science Publications (29)
- Master's Theses (29)
- Electronic Theses and Dissertations (28)
- Graduate Theses, Dissertations, and Problem Reports (ETD) (25)
- Nebraska Academy of Sciences: Programs and Proceedings (20)
- Department of Anthropology: Theses and Student Research (16)
- Publications (13)
- Faculty Scholarship (12)
- Articles (9)
- Research outputs 2014 to 2021 (8)
- CHAR (7)
- Dissertations, Theses, and Capstone Projects (6)
- Faculty Research, Scholarly, and Creative Activity (6)
- All Graduate Theses, Dissertations, and Other Capstone Projects (5)
- Electronic Theses and Dissertations, 2020-2023 (5)
- Publications and Research (5)
- Computer Sciences and Electrical Engineering Faculty Research (4)
- Dental Hygiene Faculty Publications (4)
- Discovery Day (formerly Post & Beyond) (4)
- Dissertations (4)
- Faculty Publications (4)
- General Science (4)
- Publication Type
- File Type
Articles 781 - 810 of 1248
Full-Text Articles in Forensic Science and Technology
Cyber Black Box/Event Data Recorder: Legal And Ethical Perspectives And Challenges With Digital Forensics, Michael Losavio, Pavel Pastukov, Svetlana Polyakova
Cyber Black Box/Event Data Recorder: Legal And Ethical Perspectives And Challenges With Digital Forensics, Michael Losavio, Pavel Pastukov, Svetlana Polyakova
Journal of Digital Forensics, Security and Law
With ubiquitous computing and the growth of the Internet of Things, there is vast expansion in the deployment and use of event data recording systems in a variety of environments. From the ships’ logs of antiquity through the evolution of personal devices for recording personal and environmental activities, these devices offer rich forensic and evidentiary opportunities that smash against rights of privacy and personality. The technical configurations of these devices provide for greater scope of sensing, interconnection options for local, near, and cloud storage of data, and the possibility of powerful analytics. This creates the unique situation of near-total data …
Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations, Igor Korkin
Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations, Igor Korkin
Journal of Digital Forensics, Security and Law
Hardware virtualization technologies play a significant role in cyber security. On the one hand these technologies enhance security levels, by designing a trusted operating system. On the other hand these technologies can be taken up into modern malware which is rather hard to detect. None of the existing methods is able to efficiently detect a hypervisor in the face of countermeasures such as time cheating, temporary self uninstalling, memory hiding etc. New hypervisor detection methods which will be described in this paper can detect a hypervisor under these countermeasures and even count several nested ones. These novel approaches rely on …
Data Extraction On Mtk-Based Android Mobile Phone Forensics, Joe Kong
Data Extraction On Mtk-Based Android Mobile Phone Forensics, Joe Kong
Journal of Digital Forensics, Security and Law
In conducting criminal investigations it is quite common that forensic examiners need to recover evidentiary data from smartphones used by offenders. However, examiners encountered difficulties in acquiring complete memory dump from MTK Android phones, a popular brand of smartphones, due to a lack of technical knowledge on the phone architecture and that system manuals are not always available. This research will perform tests to capture data from MTK Android phone by applying selected forensic tools and compare their effectiveness by analyzing the extracted results. It is anticipated that a generic extraction tool, once identified, can be used on different brands …
Exploring The Use Of Plc Debugging Tools For Digital Forensic Investigations On Scada Systems, Tina Wu, Jason R.C. Nurse
Exploring The Use Of Plc Debugging Tools For Digital Forensic Investigations On Scada Systems, Tina Wu, Jason R.C. Nurse
Journal of Digital Forensics, Security and Law
The Stuxnet malware attack has provided strong evidence for the development of a forensic capability to aid in thorough post-incident investigations. Current live forensic tools are typically used to acquire and examine memory from computers running either Windows or Unix. This makes them incompatible with embedded devices found on SCADA systems that have their own bespoke operating system. Currently, only a limited number of forensics tools have been developed for SCADA systems, with no development of tools to acquire the program code from PLCs. In this paper, we explore this problem with two main hypotheses in mind. Our first hypothesis …
Forensic Acquisition Of Imvu: A Case Study, Robert Van Voorst, M-Tahar Kechadi, Nhien-An Le-Khac
Forensic Acquisition Of Imvu: A Case Study, Robert Van Voorst, M-Tahar Kechadi, Nhien-An Le-Khac
Journal of Digital Forensics, Security and Law
There are many applications available for personal computers and mobile devices that facilitate users in meeting potential partners. There is, however, a risk associated with the level of anonymity on using instant message applications, because there exists the potential for predators to attract and lure vulnerable users. Today Instant Messaging within a Virtual Universe (IMVU) combines custom avatars, chat or instant message (IM), community, content creation, commerce, and anonymity. IMVU is also being exploited by criminals to commit a wide variety of offenses. However, there are very few researches on digital forensic acquisition of IMVU applications. In this paper, we …
Tracking And Taxonomy Of Cyberlocker Link Sharers Based On Behavior Analysis, Xiao-Xi Fan, Kam-Pui Chow
Tracking And Taxonomy Of Cyberlocker Link Sharers Based On Behavior Analysis, Xiao-Xi Fan, Kam-Pui Chow
Journal of Digital Forensics, Security and Law
The growing popularity of cyberlocker service has led to significant impact on the Internet that it is considered as one of the biggest contributors to the global Internet traffic estimated to be illegally traded content. Due to the anonymity property of cyberlocker, it is difficult for investigators to track user identity directly on cyberlocker site. In order to find the potential relationships between cyberlocker users, we propose a framework to collect cyberlocker related data from public forums where cyberlocker users usually distribute cyberlocker links for others to download and identity information can be gathered easily. Different kinds of sharing behaviors …
A Survey Of Botnet Detection Techniques By Command And Control Infrastructure, Thomas S. Hyslip, Jason M. Pittman
A Survey Of Botnet Detection Techniques By Command And Control Infrastructure, Thomas S. Hyslip, Jason M. Pittman
Journal of Digital Forensics, Security and Law
Botnets have evolved to become one of the most serious threats to the Internet and there is substantial research on both botnets and botnet detection techniques. This survey reviewed the history of botnets and botnet detection techniques. The survey showed traditional botnet detection techniques rely on passive techniques, primarily honeypots, and that honeypots are not effective at detecting peer-to-peer and other decentralized botnets. Furthermore, the detection techniques aimed at decentralized and peer-to-peer botnets focus on detecting communications between the infected bots. Recent research has shown hierarchical clustering of flow data and machine learning are effective techniques for detecting botnet peer-to-peer …
Multiple Stain Histology Of Skeletal Fractures: Healing And Microtaphonomy, John Wellington Powell
Multiple Stain Histology Of Skeletal Fractures: Healing And Microtaphonomy, John Wellington Powell
USF Tampa Graduate Theses and Dissertations
The forensic examination of wounds is one of the key elements of analysis performed by forensic anthropologists and forensic pathologists. Gross examination and histological analysis can be used to determine the timing of the wound and its cause. While forensic pathologists are trained to analyze hard and soft tissue wounds, forensic anthropologists, bioarchaeologists, and paleopathologists, focus on hard tissue. Forensic anthropologists have the added benefit of potentially working with residual soft tissue and would benefit from the incorporation of microscopy techniques that take advantage of the soft tissue to better understand perimortem events. Little research has been published that examines …
A Novel Method For Confirming The Presence Of Volatile Reduced Sulfide Compounds Via Inductively Coupled Plasma-Optical Emission Spectroscopy, Krystal Lynne Parker
A Novel Method For Confirming The Presence Of Volatile Reduced Sulfide Compounds Via Inductively Coupled Plasma-Optical Emission Spectroscopy, Krystal Lynne Parker
Master's Theses
Millions of dollars in destruction in the past decade have resulted from the use of Chinese drywall in homes. There are also potential health hazards related to this corrosive material. As such, it is important to find a way to identify Chinese drywall. Drywall can be tested for certain markers, such as strontium, sulfur, and carbonates to identify it as corrosive Chinese drywall. The laboratory preparation and analysis should be efficient and cost effective. The methods previously used, such as an X-ray fluorescence gun have had issues with getting a proper reading due to the layers of other materials found …
Bite Marks On Skin And Clay: A Comparative Analysis, R K. Gorea, O. P. Jasuja, Abdulwahab Ali Abuderman, Abhinav Gorea
Bite Marks On Skin And Clay: A Comparative Analysis, R K. Gorea, O. P. Jasuja, Abdulwahab Ali Abuderman, Abhinav Gorea
Research outputs 2014 to 2021
Bite marks are always unique because teeth are distinctive. Bite marks are often observed at the crime scene in sexual and in physical assault cases on the skin of the victims and sometimes on edible leftovers in burglary cases. This piece of evidence is often ignored, but if properly harvested and investigated, bite marks may prove useful in apprehending and successfully prosecuting the criminals. Due to the importance of bite marks, we conducted a progressive randomised experimental study conducted on volunteers. A total of 188 bite marks on clay were studied. Based on these findings, 93.34% of the volunteers could …
Reliability Of Eyewitness Reports To A Major Aviation Accident, Dave English, Michael Kuzel
Reliability Of Eyewitness Reports To A Major Aviation Accident, Dave English, Michael Kuzel
International Journal of Aviation, Aeronautics, and Aerospace
There is a paucity of studies on the reliability of eyewitness reports to aviation crashes. We examine witness statements to a widely observed major airline accident to determine if reported accident investigator distrust of details in eyewitness reports is supported by empirical evidence. The extensive archival witness record (N > 300) of a wide-body airliner crash in clear daylight conditions is subjected to statistical analysis to test eyewitness reliability. Even with over 200 witnesses within a three square kilometre (1.6 square mile) area answering a binary observation question, the variance is sometimes high enough to preclude forming statistically significant conclusions …
Humanitarian Technologies And Genocide Prevention: A Critical Inquiry, Colette Mazzucelli
Humanitarian Technologies And Genocide Prevention: A Critical Inquiry, Colette Mazzucelli
Genocide Studies and Prevention: An International Journal
No abstract provided.
Documenting Mass Rape: Medical Evidence Collection Techniques As Humanitarian Technology, Jaimie Morse
Documenting Mass Rape: Medical Evidence Collection Techniques As Humanitarian Technology, Jaimie Morse
Genocide Studies and Prevention: An International Journal
Aim: Emerging global networks of human rights activists, doctors, and nurses have advocated for increased collection of medical evidence in conflict-affected countries to corroborate allegations of sexual violence and facilitate prosecution in international and domestic courts. Such initiatives are part of broader shifts in human rights advocacy to document human rights violations using rigorous, standardized methodologies. In this paper, I consider three principal forms of medical evidence to document sexual violence and their use in these settings: the patient medical record, the medical certificate, and the sexual assault medical forensic exam (commonly known as the “rape kit”).
Methods: Combining archival …
Genetic Markers For Sex Identification In Forensic Dna Analysis, Erin Butler, Richard Li
Genetic Markers For Sex Identification In Forensic Dna Analysis, Erin Butler, Richard Li
Publications and Research
The ability to determine the sex of an individual based on DNA evidence can be crucial in instances such as identification of victims of mass disaster, missing persons investigations, and sexual assault cases. The Y chromosome marker amelogenin is currently in widespread use for determination of chromosomal sex of an unknown DNA donor and differentiating the relative contributions of male and female DNA in a mixed forensic sample. However, many cases of the failure of the amelogenin marker to correctly determine the sex of DNA donors have been reported, causing the usefulness of the amelogenin marker in forensics to be …
Csi Effect And Forensic Science/Criminal Justice Degree Programs, Megan Dutton Mccay
Csi Effect And Forensic Science/Criminal Justice Degree Programs, Megan Dutton Mccay
Dissertations
This research sought to determine the relationship between obtaining a criminal justice or forensic science degree and the CSI Effect followed by whether the students were satisfied with their major selection. Additionally, this research sought to determine if there were discrepancies between students’ expectations before entering the forensic science or criminal justice degree program and students’ attitudes while enrolled in the forensic science or criminal justice degree program. One hundred and ninety-six participants responded to a 33-item survey instrument over a three week time period. It was determined there was a television influence on students’ major selection in the forensic …
Testing The Forensic Soundness Of Forensic Examination Environments On Bootable Media, Ahmed F.A.L. Mohamed, Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili
Testing The Forensic Soundness Of Forensic Examination Environments On Bootable Media, Ahmed F.A.L. Mohamed, Andrew Marrington, Farkhund Iqbal, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
In this work we experimentally examine the forensic soundness of the use of forensic bootable CD/DVDs as forensic examination environments. Several Linux distributions with bootable CD/DVDs which are marketed as forensic examination environments are used to perform a forensic analysis of a captured computer system. Before and after the bootable CD/DVD examination, the computer system's hard disk is removed and a forensic image acquired by a second system using a hardware write blocker. The images acquired before and after the bootable CD/DVD examination are hashed and the hash values compared. Where the hash values are inconsistent, a differential analysis is …
Preliminary Forensic Analysis Of The Xbox One, Jason Moore, Ibrahim Baggili, Andrew Marrington, Armindo Rodrigues
Preliminary Forensic Analysis Of The Xbox One, Jason Moore, Ibrahim Baggili, Andrew Marrington, Armindo Rodrigues
Electrical & Computer Engineering and Computer Science Faculty Publications
Video game consoles can no longer be viewed as just gaming consoles but rather as full multimedia machines, capable of desktop computer-like performance. The past has shown that game consoles have been used in criminal activities such as extortion, identity theft, and child pornography, but with their ever-increasing capabilities, the likelihood of the expansion of criminal activities conducted on or over the consoles increases. This research aimed to take the initial step of understanding the Xbox One, the most powerful Microsoft console to date. We report the outcome of conducting a forensic examination of the Xbox One, and we provide …
Exploring The Perception Towards Enhancing Credentials By Certification Of Latent Fingerprint Examiners In The Southern United States, Christopher G. Brewer
Exploring The Perception Towards Enhancing Credentials By Certification Of Latent Fingerprint Examiners In The Southern United States, Christopher G. Brewer
Honors Theses
With several applications of forensic processes coming into question, becoming a reputable expert witness in a court of law can be dire. This pilot study explores the professional opinions of latent fingerprint examiners employed by state criminal investigation departments. Research was geared towards measuring the notion that gaining certification through institutions such as the International Association for Identification (IAI) aids in the perception of latent fingerprint examiners’ credibility and confidence as expert witnesses. The sample population of latent fingerprint examiners (LFPEs) was gathered using a digital survey issued to the forensic laboratories and divisions housed within state criminal investigation units. …
Forensicloud: An Architecture For Digital Forensic Analysis In The Cloud, Cody Miller, Dae Glendowne, David Dampier, Kendall Blaylock
Forensicloud: An Architecture For Digital Forensic Analysis In The Cloud, Cody Miller, Dae Glendowne, David Dampier, Kendall Blaylock
Computer Sciences and Electrical Engineering Faculty Research
The amount of data that must be processed in current digital forensic examinations continues to rise. Both the volume and diversity of data are obstacles to the timely completion of forensic investigations. Additionally, some law enforcement agencies do not have the resources to handle cases of even moderate size. To address these issues we have developed an architecture for a cloud-based distributed processing platform we have named Forensicloud. This architecture is designed to reduce the time taken to process digital evidence by leveraging the power of a high performance computing platform and by adapting existing tools to operate within this …
From The Editor-In-Chief, Ibrahim A. Baggili
From The Editor-In-Chief, Ibrahim A. Baggili
Journal of Digital Forensics, Security and Law
We are proud to share with you this special edition issue of the JDFSL. This year, JDFSL partnered with both the 6th International Conference on Digital Forensics and Cyber Crime (ICDF2C) and Systematic Approaches to Digital Forensic Engineering (SADFE)–two prominent conferences in our field that were co-hosted. Fifty-three papers were submitted, and the Technical Program Committee accepted only 17 after a rigorous review process.
Incarceration And Reintegration: How It Impacts Mental Health, April M. Marier, Alex Alfredo Reyes
Incarceration And Reintegration: How It Impacts Mental Health, April M. Marier, Alex Alfredo Reyes
Electronic Theses, Projects, and Dissertations
ABSTRACT
Background: Previous criminal justice policies have been non-effective leading to overpopulated prisons and unsuccessful reintegration. There is a lack of effective supportive and/or rehabilitative services resulting in high rates of recidivism and mental health implications. Objective: This study investigated the perceived impact that incarceration and reintegration with little to no supportive and/or rehabilitative services has on the mental health status of an individual. The emphasis was on participant perception and not on professional reports because of underreporting and lack of attention to mental health in the criminal justice system. Methods: Focus groups in the Inland Empire and Coachella Valley …
Hot Zone Identification: Analyzing Effects Of Data Sampling On Spam Clustering, Rasib Khan, Mainul Mizan, Ragib Hasan, Alan Sprague
Hot Zone Identification: Analyzing Effects Of Data Sampling On Spam Clustering, Rasib Khan, Mainul Mizan, Ragib Hasan, Alan Sprague
Annual ADFSL Conference on Digital Forensics, Security and Law
Email is the most common and comparatively the most efficient means of exchanging information in today's world. However, given the widespread use of emails in all sectors, they have been the target of spammers since the beginning. Filtering spam emails has now led to critical actions such as forensic activities based on mining spam email. The data mine for spam emails at the University of Alabama at Birmingham is considered to be one of the most prominent resources for mining and identifying spam sources. It is a widely researched repository used by researchers from different global organizations. The usual process …
Investigative Techniques Of N-Way Vendor Agreement And Network Analysis Demonstrated With Fake Antivirus, Gary Warner, Mike Nagy, Kyle Jones, Kevin Mitchem
Investigative Techniques Of N-Way Vendor Agreement And Network Analysis Demonstrated With Fake Antivirus, Gary Warner, Mike Nagy, Kyle Jones, Kevin Mitchem
Annual ADFSL Conference on Digital Forensics, Security and Law
Fake AntiVirus (FakeAV) malware experienced a resurgence in the fall of 2013 after falling out of favor after several high profile arrests. FakeAV presents two unique challenges to investigators. First, because each criminal organization running a FakeAV affiliate system regularly alters the appearance of their system, it is sometimes difficult to know whether an incoming criminal complaint or malware sample is related to one ring or the other. Secondly, because FakeAV is delivered in a “Pay Per Install” affiliate model, in addition to the ring-leaders of each major ring, there are many high-volume malware infection rings who are all using …
Work In Progress: An Architecture For Network Path Reconstruction Via Backtraced Ospf Lsdb Synchronization, Raymond A. Hansen
Work In Progress: An Architecture For Network Path Reconstruction Via Backtraced Ospf Lsdb Synchronization, Raymond A. Hansen
Annual ADFSL Conference on Digital Forensics, Security and Law
There has been extensive work in crime scene reconstruction of physical locations, and much is known in terms of digital forensics of computing devices. However, the network has remained a nebulous combination of entities that are largely ignored during an investigation due to the transient nature of the data that flows through the networks. This paper introduces an architecture for network path reconstruction using the network layer reachability information shared via OSPF Link State Advertisements and the routines and functions of OSPF::rt_sched() as applied to the construction of identical Link State Databases for all routers within an Area.
Application Of Toral Automorphisms To Preserve Confidentiality Principle In Video Live Streaming, Enrique García-Carbajal, Clara Cruz-Ramos, Mariko Nakano-Miyatake
Application Of Toral Automorphisms To Preserve Confidentiality Principle In Video Live Streaming, Enrique García-Carbajal, Clara Cruz-Ramos, Mariko Nakano-Miyatake
Annual ADFSL Conference on Digital Forensics, Security and Law
Most of the Live Video Systems do not preserve the Confidentiality principle, and send all frames of the video without any protection, allowing an easy “man in the middle” attack. But when it does, it uses cryptographic techniques over streaming data or makes use of secure channel systems. This generates low frame rate and demands many processor resources. In fact native Live Video Streaming demands many resources of all System.
In this paper we propose a technique to preserve confidentiality in Video Live Streaming applying a confusing visual method making use of the Toral Automorphism Spatial Transformation over each frame. …
Visualizing Instant Messaging Author Writeprints For Forensic Analysis, Angela Orebaugh, Jason Kinser, Jeremy Allnutt
Visualizing Instant Messaging Author Writeprints For Forensic Analysis, Angela Orebaugh, Jason Kinser, Jeremy Allnutt
Annual ADFSL Conference on Digital Forensics, Security and Law
As cybercrime continues to increase, new cyber forensics techniques are needed to combat the constant challenge of Internet anonymity. In instant messaging (IM) communications, criminals use virtual identities to hide their true identity, which hinders social accountability and facilitates cybercrime. Current instant messaging products are not addressing the anonymity and ease of impersonation over instant messaging. It is necessary to have IM cyber forensics techniques to assist in identifying cyber criminals as part of the criminal investigation. Instant messaging behavioral biometrics include online writing habits, which may be used to create an author writeprint to assist in identifying an author …
Botnet Forensic Investigation Techniques And Cost Evaluation, Brian Cusack
Botnet Forensic Investigation Techniques And Cost Evaluation, Brian Cusack
Annual ADFSL Conference on Digital Forensics, Security and Law
Botnets are responsible for a large percentage of damages and criminal activity on the Internet. They have shifted attacks from push activities to pull techniques for the distribution of malwares and continue to provide economic advantages to the exploiters at the expense of other legitimate Internet service users. In our research we asked; what is the cost of the procedural steps for forensically investigating a Botnet attack? The research method applies investigation guidelines provided by other researchers and evaluates these guidelines in terms of the cost to a digital forensic investigator. We conclude that investigation of Botnet attacks is both …
Development And Dissemination Of A New Multidisciplinary Undergraduate Curriculum In Digital Forensics, Masooda Bashir, Jenny A. Applequist, Roy H. Campbell, Lizanne Destefano, Gabriela L. Garcia, Anthony Lang
Development And Dissemination Of A New Multidisciplinary Undergraduate Curriculum In Digital Forensics, Masooda Bashir, Jenny A. Applequist, Roy H. Campbell, Lizanne Destefano, Gabriela L. Garcia, Anthony Lang
Annual ADFSL Conference on Digital Forensics, Security and Law
The Information Trust Institute (ITI) at the University of Illinois at Urbana-Champaign is developing an entirely new multidisciplinary undergraduate curriculum on the topic of digital forensics, and this paper presents the findings of the development process, including initial results and evaluation of a pilot offering of the coursework to students. The curriculum consists of a four-course sequence, including introductory and advanced lecture courses with parallel laboratory courses, followed by an advanced course. The content has been designed to reflect both the emerging national standards and the strong multidisciplinary character of the profession of digital forensics, and includes modules developed collaboratively …
Computer Forensics For Accountants, Grover S. Kearns
Computer Forensics For Accountants, Grover S. Kearns
Annual ADFSL Conference on Digital Forensics, Security and Law
Digital attacks on organizations are becoming more common and more sophisticated. Firms are interested in providing data security and having an effective means to respond to attacks. Accountants possess important investigative and analytical skills that serve to uncover fraud in forensic investigations. Some accounting students take courses in forensic accounting but few colleges offer a course in computer forensics for accountants. Educators wishing to develop such a course may find developing the curriculum daunting. A major element of such a course is the use of forensic software. This paper argues the importance of computer forensics to accounting students and offers …
Applying Memory Forensics To Rootkit Detection, Igor Korkin, Ivan Nesterov
Applying Memory Forensics To Rootkit Detection, Igor Korkin, Ivan Nesterov
Annual ADFSL Conference on Digital Forensics, Security and Law
Volatile memory dump and its analysis is an essential part of digital forensics. Among a number of various software and hardware approaches for memory dumping there are authors who point out that some of these approaches are not resilient to various anti-forensic techniques, and others that require a reboot or are highly platform dependent. New resilient tools have certain disadvantages such as low speed or vulnerability to rootkits which directly manipulate kernel structures, e.g., page tables. A new memory forensic system – Malware Analysis System for Hidden Knotty Anomalies (MASHKA) is described in this paper. It is resilient to popular …