Open Access. Powered by Scholars. Published by Universities.®
Forensic Science and Technology Commons™
Open Access. Powered by Scholars. Published by Universities.®
- Discipline
-
- Physical Sciences and Mathematics (735)
- Computer Sciences (639)
- Information Security (617)
- Engineering (565)
- Law (549)
-
- Computer Law (478)
- Computer Engineering (461)
- Electrical and Computer Engineering (452)
- Sociology (167)
- Criminology and Criminal Justice (145)
- Life Sciences (123)
- Public Affairs, Public Policy and Public Administration (100)
- Social Control, Law, Crime, and Deviance (83)
- Defense and Security Studies (82)
- Other Computer Sciences (80)
- OS and Networks (78)
- Criminology (74)
- National Security Law (74)
- Aviation (72)
- Aviation Safety and Security (70)
- Medicine and Health Sciences (63)
- Chemistry (57)
- Anthropology (52)
- Education (39)
- Evidence (36)
- Psychology (33)
- Biology (29)
- Institution
-
- Embry-Riddle Aeronautical University (497)
- University of New Haven (117)
- City University of New York (CUNY) (108)
- Virginia Commonwealth University (78)
- Bridgewater State University (67)
-
- University of Nebraska - Lincoln (57)
- San Jose State University (53)
- University of Central Florida (37)
- West Virginia University (27)
- The University of Southern Mississippi (23)
- Old Dominion University (16)
- Edith Cowan University (12)
- University of Michigan Law School (11)
- Duke Law (10)
- University at Albany, State University of New York (9)
- University of Mississippi (8)
- Duquesne University (6)
- Marshall University (5)
- Minnesota State University, Mankato (5)
- Air Force Institute of Technology (4)
- Long Island University (4)
- Nova Southeastern University (4)
- Parkland College (4)
- Penn State Dickinson Law (4)
- University of New Hampshire (4)
- University of South Florida (4)
- California State University, San Bernardino (3)
- Montclair State University (3)
- SUNY Buffalo State University (3)
- Bowling Green State University (2)
- Keyword
-
- Forensic science (70)
- Digital forensics (65)
- Forensics (39)
- DNA (25)
- Digital Forensics (23)
-
- Computer forensics (22)
- Cybercrime (21)
- Digital evidence (19)
- Cybersecurity (18)
- Forensic (17)
- Forensic anthropology (17)
- Forensic Science (16)
- Privacy (12)
- Blood (11)
- DNA analysis (11)
- Evidence (11)
- Computer Forensics (10)
- Security (10)
- Approximate matching (9)
- Cryptocurrency (9)
- Cyber forensics (9)
- Cyberbullying (9)
- Education (9)
- Forensic entomology (9)
- Mobile device forensics (9)
- Touch DNA (9)
- Investigation (8)
- Law enforcement (8)
- Mrsh-v2 (8)
- Survey (8)
- Publication Year
- Publication
-
- Journal of Digital Forensics, Security and Law (294)
- Annual ADFSL Conference on Digital Forensics, Security and Law (187)
- Student Theses (97)
- Master of Science in Forensic Science Directed Research Projects (75)
- International Journal of Cybersecurity Intelligence & Cybercrime (67)
-
- Electrical & Computer Engineering and Computer Science Faculty Publications (56)
- Themis: Research Journal of Justice Studies and Forensic Science (43)
- Honors Theses (34)
- Forensic Science Publications (29)
- Master's Theses (29)
- Electronic Theses and Dissertations (28)
- Graduate Theses, Dissertations, and Problem Reports (ETD) (25)
- Nebraska Academy of Sciences: Programs and Proceedings (20)
- Department of Anthropology: Theses and Student Research (16)
- Publications (13)
- Faculty Scholarship (12)
- Articles (9)
- Research outputs 2014 to 2021 (8)
- CHAR (7)
- Dissertations, Theses, and Capstone Projects (6)
- Faculty Research, Scholarly, and Creative Activity (6)
- All Graduate Theses, Dissertations, and Other Capstone Projects (5)
- Electronic Theses and Dissertations, 2020-2023 (5)
- Publications and Research (5)
- Computer Sciences and Electrical Engineering Faculty Research (4)
- Dental Hygiene Faculty Publications (4)
- Discovery Day (formerly Post & Beyond) (4)
- Dissertations (4)
- Faculty Publications (4)
- General Science (4)
- Publication Type
- File Type
Articles 811 - 840 of 1248
Full-Text Articles in Forensic Science and Technology
The Federal Rules Of Civil Procedure: Politics In The 2013-2014 Revision, John W. Bagby, Byron Granda, Emily Benoit, Alexander Logan, Ryan Snell, Joseph J. Schwerha
The Federal Rules Of Civil Procedure: Politics In The 2013-2014 Revision, John W. Bagby, Byron Granda, Emily Benoit, Alexander Logan, Ryan Snell, Joseph J. Schwerha
Annual ADFSL Conference on Digital Forensics, Security and Law
Pre-trial discovery is perpetually controversial. Parties advantaged by strict privacy can often avoid justice when this is disadvantageous to their interests. Contrawise, parties advantaged by relaxed litigation privacy can achieve justice when all facts are accessible irrespective of their repositories, ownership or control. American-style pre-trial discovery in civil and regulatory enforcement is relatively rare around the world. U.S. discovery rules open nearly all relevant and non-privileged data for use by opposing parties. The traditional discovery process was costly and time consuming in the world of tangible paper data. However, these burdens have increased, rather than diminished as often predicted, as …
Testing And Evaluating The Harmonised Digital Forensic Investigation Process In Post Mortem Digital Investigation, Emilio R. Mumba, H. S. Venter
Testing And Evaluating The Harmonised Digital Forensic Investigation Process In Post Mortem Digital Investigation, Emilio R. Mumba, H. S. Venter
Annual ADFSL Conference on Digital Forensics, Security and Law
Existing digital forensic investigation process models have provided guidelines for identifying and preserving potential digital evidence captured from a crime scene. However, for any of the digital forensic investigation process models developed across the world to be adopted and fully applied by the scientific community, it has to be tested. For this reason, the Harmonized Digital Forensic Investigation Process (HDFIP) model, currently a working draft towards becoming an international standard for digital forensic investigations (ISO/IEC 27043), needs to be tested.
This paper, therefore, presents the findings of a case study used to test the HDFIP model implemented in the ISO/IEC …
Generation And Handling Of Hard Drive Duplicates As Piece Of Evidence, T. Kemmerich, F. Junge, N. Kuntze, C. Rudolph, B. Endicott-Popovsky, L. Großkopf
Generation And Handling Of Hard Drive Duplicates As Piece Of Evidence, T. Kemmerich, F. Junge, N. Kuntze, C. Rudolph, B. Endicott-Popovsky, L. Großkopf
Annual ADFSL Conference on Digital Forensics, Security and Law
An important area in digital forensics is images of hard disks. The correct production of the images as well as the integrity and authenticity of each hard disk image is essential for the probative force of the image to be used at court. Integrity and authenticity are under suspicion as digital evidence is stored and used by software based systems. Modifications to digital objects are hard or even impossible to track and can occur even accidentally. Even worse, vulnerabilities occur for all current computing systems. Therefore, it is difficult to guarantee a secure environment for forensic investigations. But intended deletions …
Internet Addiction To Child Pornography, Rachel Sitarz, Marcus Rogers, Lonnie Bentley, Eugene Jackson
Internet Addiction To Child Pornography, Rachel Sitarz, Marcus Rogers, Lonnie Bentley, Eugene Jackson
Annual ADFSL Conference on Digital Forensics, Security and Law
During the present age and time, it seems as though people in society have become addicted to nearly anything and everything, whether it be to a substance, an activity or an object. The Internet and pornography is no exception. While commonly thought of as a deviant behavior, many are displaying addictions towards the Internet and pornography. More alarming, however, are those who are viewing, downloading, or trading child pornography and displaying addictive Internet behaviors, for they are spending excessive amounts of time engaging in the proliferation of child pornographic materials. For this reason, addiction to the Internet and usage of …
Using Internet Artifacts To Profile A Child Pornography Suspect, Marcus K. Rogers, Kathryn C. Seigfried-Spellar
Using Internet Artifacts To Profile A Child Pornography Suspect, Marcus K. Rogers, Kathryn C. Seigfried-Spellar
Annual ADFSL Conference on Digital Forensics, Security and Law
Digital evidence plays a crucial role in child pornography investigations. However, in the following case study, the authors argue that the behavioral analysis or “profiling” of digital evidence can also play a vital role in child pornography investigations. The following case study assessed the Internet Browsing History (Internet Explorer Bookmarks, Mozilla Bookmarks, and Mozilla History) from a suspected child pornography user’s computer. The suspect in this case claimed to be conducting an ad hoc law enforcement investigation. After the URLs were classified (Neutral; Adult Porn; Child Porn; Adult Dating sites; Pictures from Social Networking Profiles; Chat Sessions; Bestiality; Data Cleaning; …
Life (Logical Iosforensics Examiner): An Open Source Iosbackup Forensics Examination Tool, Ibrahim Baggili, Shadi Al Awawdeh, Jason Moore
Life (Logical Iosforensics Examiner): An Open Source Iosbackup Forensics Examination Tool, Ibrahim Baggili, Shadi Al Awawdeh, Jason Moore
Annual ADFSL Conference on Digital Forensics, Security and Law
In this paper, we present LiFE (Logical iOS Forensics Examiner), an open source iOS backup forensics examination tool. This tool helps both researchers and practitioners alike in both understanding the backup structures of iOS devices and forensically examining iOS backups. The tool is currently capable of parsing device information, call history, voice messages, GPS locations, conversations, notes, images, address books, calendar entries, SMS messages, Aux locations, facebook data and e-mails. The tool consists of both a manual interface (where the user is able to manually examine the backup structures) and an automated examination interface (where the tool pulls out evidence …
Why Penetration Testing Is A Limited Use Choice For Sound Cyber Security Practice, Craig Valli, Andrew Woodward, Peter Hannay, Mike Johnstone
Why Penetration Testing Is A Limited Use Choice For Sound Cyber Security Practice, Craig Valli, Andrew Woodward, Peter Hannay, Mike Johnstone
Annual ADFSL Conference on Digital Forensics, Security and Law
Penetration testing of networks is a process that is overused when demonstrating or evaluating the cyber security posture of an organisation. Most penetration testing is not aligned with the actual intent of the testing, but rather is driven by a management directive of wanting to be seen to be addressing the issue of cyber security. The use of penetration testing is commonly a reaction to an adverse audit outcome or as a result of being penetrated in the first place. Penetration testing used in this fashion delivers little or no value to the organisation being tested for a number of …
Awareness Of Scam E-Mails: An Exploratory Research Study, Tejashree D. Datar, Kelly A. Cole, Marcus K. Rogers
Awareness Of Scam E-Mails: An Exploratory Research Study, Tejashree D. Datar, Kelly A. Cole, Marcus K. Rogers
Annual ADFSL Conference on Digital Forensics, Security and Law
The goal of this research was to find the factors that influence a user’s ability to identify e-mail scams. It also aimed to understand user’s awareness regarding e-mail scams and actions that need to be taken if and when victimized. This study was conducted on a university campus with 163 participants. This study presented the participants with two scam e-mails and two legitimate e-mails and asked the participants to correctly identify these e-mails as scam or legitimate. The study focused on the ability of people to differentiate between scam and legitimate e-mails. The study attempted to determine factors that influence …
Dna Typing Compatibility With A One Step Saliva Screening Test, Nicole Roda, Steven B. Lee, Brooke Barloewen, Tahnee Mehmet
Dna Typing Compatibility With A One Step Saliva Screening Test, Nicole Roda, Steven B. Lee, Brooke Barloewen, Tahnee Mehmet
Themis: Research Journal of Justice Studies and Forensic Science
Screening a substrate for bodily fluids is an extremely important step for locating areas that may contain DNA. Several different methods have been developed for saliva (1). The Phadebas® Forensic Press (PFP) test is a presumptive saliva test that utilizes a preloaded paper that will react with the enzyme amylase, a component of saliva (2-5). Because of its ability to screen for amylase while simultaneously locating stains, the PFP may prove to be an effective, rapid method for screening. However it is important to assess whether the PFP introduces any inhibitors (7) to downstream processing such as PCR amplification. Based …
Life (Logical Ios Forensics Examiner): An Open Source Ios Backup Forensics Examination Tool, Ibrahim Baggili, Shadi Al Awawdeh, Jason Moore
Life (Logical Ios Forensics Examiner): An Open Source Ios Backup Forensics Examination Tool, Ibrahim Baggili, Shadi Al Awawdeh, Jason Moore
Electrical & Computer Engineering and Computer Science Faculty Publications
In this paper, we present LiFE (Logical iOS Forensics Examiner), an open source iOS backup forensics examination tool. This tool helps both researchers and practitioners alike in both understanding the backup structures of iOS devices and forensically examining iOS backups. The tool is currently capable of parsing device information, call history, voice messages, GPS locations, conversations, notes, images, address books, calendar entries, SMS messages, Aux locations, facebook data and e-mails. The tool consists of both a manual interface (where the user is able to manually examine the backup structures) and an automated examination interface (where the tool pulls out evidence …
On The Database Lookup Problem Of Approximate Matching, Frank Breitinger, Harald Baier, Douglas White
On The Database Lookup Problem Of Approximate Matching, Frank Breitinger, Harald Baier, Douglas White
Electrical & Computer Engineering and Computer Science Faculty Publications
Investigating seized devices within digital forensics gets more and more difficult due to the increasing amount of data. Hence, a common procedure uses automated file identification which reduces the amount of data an investigator has to look at by hand. Besides identifying exact duplicates, which is mostly solved using cryptographic hash functions, it is also helpful to detect similar data by applying approximate matching.
Let x denote the number of digests in a database, then the lookup for a single similarity digest has the complexity of O(x). In other words, the digest has to be compared against …
An Experimental Study To Quantify Error Rates Resulting From Measurement Deviation In Area Of Origin Reconstructions Of Blunt Force Impact Patterns, Mark Davison, Timothy Palmbach
An Experimental Study To Quantify Error Rates Resulting From Measurement Deviation In Area Of Origin Reconstructions Of Blunt Force Impact Patterns, Mark Davison, Timothy Palmbach
Forensic Science Publications
The intent of this study was to attempt to quantify error associated with the measurements required in area of origin reconstructions resulting from the analysis of blunt force impact patterns. Mathematical tables were constructed in order to examine trends associated with changing width and length ratios and the influence of impact angle change and area of convergence deviations. The analysis of the trends enabled informed stain selection, mitigating potential error. The analysis of the influence of stain measurement error and gamma angle error was conducted by reconstructing experimentally created blunt force impact patterns using the Tangent Method, comparing the resulting …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2014, 134th Anniversary Year, One Hundred-Twenty-Fourth Annual Meeting, April 11, 2014
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Collegiate Academy: Biology
Chemistry and Physics
Collegiate Academy: Chemistry and Physics
Applied Science and Technology
Biological and Medical Sciences
Aeronautics and Space Science, Poster Session
Anthropology
Maiben Memorial Lecture: "Education, Careers and Opportunities in Engineering and Metallurgy in Nebraska," Terry Rasmussen, Nucor Steel, Norfolk, Nebraska
Teaching of Science and Mathematics
Anthropology
Earth Science
Development Of A Quantitative Real-Time Polymerase Chain Reaction (Rt-Pcr) Assay For Plant Species, Kayla Curtis, Heather Miller Coyle
Development Of A Quantitative Real-Time Polymerase Chain Reaction (Rt-Pcr) Assay For Plant Species, Kayla Curtis, Heather Miller Coyle
Forensic Science Publications
In order to facilitate optimal plant DNA quantitation and identification, an assay has been developed that uses generic plant PCR primers that amplify a region in the chloroplast genome of plant samples. The assay uses the SYBR green detection dye to detect the PCR product with a universal PCR primer set to the large subunit of ribulose bisphosphate carboxylase, rbcL, but can be used with any of the universal barcode primers for land plants (rbcL, matK, trnH, psbA). Standard dilutions of control wheat DNA of varying concentrations were tested to create a standard curve. Several plant DNA extractions of different …
An Enzymatic Method To Process Decomposed Non-Human Bone For Forensic Dna Analysis, Richard Li, Melissa Gaud, Smriti Nair
An Enzymatic Method To Process Decomposed Non-Human Bone For Forensic Dna Analysis, Richard Li, Melissa Gaud, Smriti Nair
Publications and Research
Forensic analysis of DNA from non-human bones can be important in investigating a variety of forensic cases. However, decomposed bone is difficult to process for isolating DNA. In this study, a previously established enzymatic method was utilized to process bone samples that simulate decomposed specimens. Our results demonstrated that this enzymatic processing method is effective for removing decomposed soft tissues and outer surface materials such as mineralized bone connective tissue of bone fragment samples. Our data suggested that this method can be used in the initial sample preparation for cleaning the outer surface of decomposed non-human skeletal fragments. This study …
Impact Of Tumour Epithelial Subtype On Circulating Micrornas In Breast Cancer Patients, Peadar S. Waters, Roisin M. Dwyer, Cathy Brougham, Claire L. Glynn, Deidre Wall, Peter Hyland, Maria Duignan, Mark Mcloughlin, John Newell, Michael J. Kerin
Impact Of Tumour Epithelial Subtype On Circulating Micrornas In Breast Cancer Patients, Peadar S. Waters, Roisin M. Dwyer, Cathy Brougham, Claire L. Glynn, Deidre Wall, Peter Hyland, Maria Duignan, Mark Mcloughlin, John Newell, Michael J. Kerin
Forensic Science Publications
While a range of miRNAs have been shown to be dysregulated in the circulation of patients with breast cancer, little is known about the relationship between circulating levels and tumour characteristics. The aim of this study was to analyse alterations in circulating miRNA expression during tumour progression in a murine model of breast cancer, and to detemine the clinical relevance of identified miRNAs at both tissue and circulating level in patient samples. Athymic nude mice received a subcutaneous or mammary fat pad injection of MDA-MB-231 cells. Blood sampling was performed at weeks 1, 3 and 6 following tumour induction, and …
Women As Expert Witnesses: A Review Of The Literature, Tess M. S. Neal
Women As Expert Witnesses: A Review Of The Literature, Tess M. S. Neal
University of Nebraska Public Policy Center: Publications
This review of women’s participation in the legal system as expert witnesses examines the empirical literature on the perceived credibility and persuasiveness of women compared with men experts. The effects of expert gender are complex and sometimes depend on the circumstances of the case. Some studies find no differences, some find favorable effects for women and others for men, and still others find that expert gender interacts with other circumstances of the case. The findings are interpreted through social role theory and the role incongruity theory of prejudice. Future directions for research are identified and implications are considered for attorneys …
Utilizing Dna Analysis To Combat The World Wide Plague Of Present Day Slavery – Trafficking In Persons, Timothy Palmbach, Jeffrey Bloom, Emily Hoynes, Dragan Primorac, Mario Thomas Gaboury
Utilizing Dna Analysis To Combat The World Wide Plague Of Present Day Slavery – Trafficking In Persons, Timothy Palmbach, Jeffrey Bloom, Emily Hoynes, Dragan Primorac, Mario Thomas Gaboury
Forensic Science Publications
A study was conducted to determine if modern forensic DNA typing methods can be properly employed throughout the world with a final goal of increasing arrests, prosecutions, and convictions of perpetrators of modern day trafficking in persons while concurrently reducing the burden of victim testimony in legal proceedings. Without interruption of investigations, collection of samples containing DNA was conducted in a variety of settings. Evidentiary samples were analyzed on the ANDE Rapid DNA system. Many of the collected swabs yielded informative short tandem repeat profiles with Rapid DNA technology.
Unmasking Cancer As A Consequence Of Human Trafficking: A Multidisciplinary Challenge, Barbara Moynihan, Katherine Olive
Unmasking Cancer As A Consequence Of Human Trafficking: A Multidisciplinary Challenge, Barbara Moynihan, Katherine Olive
Forensic Science Publications
This article will focus on the development of cancer as a potential consequence of human trafficking. Various subtle sequelae of trafficking, such as the insidious development of cancer, may not be seen until well after the victim has been freed. There are a myriad of factors that contribute to missed or inadequate health care for victims and survivors of human trafficking. These health care needs (both medical as well as mental health) may be overlooked until many months or years post-trafficking. We will address the risk factors consistent with human trafficking that should be considered by health care professionals who …
An Efficient Similarity Digests Database Lookup -- A Logarithmic Divide And Conquer Approach, Frank Breitinger, Christian Rathgeb, Harald Baier
An Efficient Similarity Digests Database Lookup -- A Logarithmic Divide And Conquer Approach, Frank Breitinger, Christian Rathgeb, Harald Baier
Electrical & Computer Engineering and Computer Science Faculty Publications
Investigating seized devices within digital forensics represents a challenging task due to the increasing amount of data. Common procedures utilize automated file identification, which reduces the amount of data an investigator has to examine manually. In the past years the research field of approximate matching arises to detect similar data. However, if n denotes the number of similarity digests in a database, then the lookup for a single similarity digest is of complexity of O(n). This paper presents a concept to extend existing approximate matching algorithms, which reduces the lookup complexity from O(n) to O(log(n)). Our proposed approach is based …
Refusal To Autopsy: A Societal Practice In Pakistan Context, Laila Akber Cassum
Refusal To Autopsy: A Societal Practice In Pakistan Context, Laila Akber Cassum
School of Nursing & Midwifery
Autopsies or post-mortem examinations have become a common practice in Western medicine for verifying the cause of death, and to obtain additional scientific information on certain diseases. In monotheistic religions autopsies present several ethical questions even though the advantages attributed to post-mortems in the West are well acknowledged by people living in this modern world. In Islamic Republic of Pakistan where Islam is the prevailing religion followed by the Muslims, Pakistani society have diverse perception, assumptions and hypothesis on the concept of autopsy. This presumption is due to presence of diverse objections raised in religious and sociocultural context. In our …
File Detection On Network Traffic Using Approximate Matching, Frank Breitinger, Ibrahim Baggili
File Detection On Network Traffic Using Approximate Matching, Frank Breitinger, Ibrahim Baggili
Electrical & Computer Engineering and Computer Science Faculty Publications
In recent years, Internet technologies changed enormously and allow faster Internet connections, higher data rates and mobile usage. Hence, it is possible to send huge amounts of data / files easily which is often used by insiders or attackers to steal intellectual property. As a consequence, data leakage prevention systems (DLPS) have been developed which analyze network traffic and alert in case of a data leak. Although the overall concepts of the detection techniques are known, the systems are mostly closed and commercial. Within this paper we present a new technique for network traffic analysis based on approximate matching (a.k.a …
Quantifying Relevance Of Mobile Digital Evidence As They Relate To Case Types: A Survey And A Guide For Best Practices, Shahzad Saleem, Ibrahim Baggili, Oliver Popov
Quantifying Relevance Of Mobile Digital Evidence As They Relate To Case Types: A Survey And A Guide For Best Practices, Shahzad Saleem, Ibrahim Baggili, Oliver Popov
Electrical & Computer Engineering and Computer Science Faculty Publications
In this work, a survey was conducted to help quantify the relevance of nineteen types of evidence (such as SMS) to seven types of digital investigations associated with mobile devices (MD) (such as child pornography). 97 % of the respondents agreed that every type of digital evidence has a different level of relevance to further or solve a particular investigation. From 55 serious participants, a data set of 5,772 responses regarding the relevance of nineteen types of digital evidence for all the seven types of digital investigations was obtained. The results showed that (i) SMS belongs to the most relevant …
Shadow Dwellers: The Underregulated World Of State And Local Dna Databases, Stephen Mercer, Jessica D. Gabel
Shadow Dwellers: The Underregulated World Of State And Local Dna Databases, Stephen Mercer, Jessica D. Gabel
Faculty Publications By Year
No abstract provided.
"It's Not About You": Exploring The Liminal Experiences Of Graduate Forensic Coaches, Christopher Paul Outzen
"It's Not About You": Exploring The Liminal Experiences Of Graduate Forensic Coaches, Christopher Paul Outzen
All Graduate Theses, Dissertations, and Other Capstone Projects
The following document is a capstone thesis project focusing on the unique experiences of graduate forensic coaches through lens of liminality, a performance theory used to describe a sense of being between social identities when going through a rite of passage. The author contends that this liminal experience has unique characteristics which are important to consider in the context of identity and forensic culture. In order to gather data, the author utilized qualitative, semi-structured interviews with current graduate forensic coaches. The resulting interviews were interpreted using a process of open coding to determine key themes of the experience. The author …
Using Internet Artifacts To Profile A Child Pornography Suspect, Marcus K. Rogers, Kathryn C. Seigfried-Spellar
Using Internet Artifacts To Profile A Child Pornography Suspect, Marcus K. Rogers, Kathryn C. Seigfried-Spellar
Journal of Digital Forensics, Security and Law
Digital evidence plays a crucial role in child pornography investigations. However, in the following case study, the authors argue that the behavioral analysis or “profiling” of digital evidence can also play a vital role in child pornography investigations. The following case study assessed the Internet Browsing History (Internet Explorer Bookmarks, Mozilla Bookmarks, and Mozilla History) from a suspected child pornography user’s computer. The suspect in this case claimed to be conducting an ad hoc law enforcement investigation. After the URLs were classified (Neutral; Adult Porn; Child Porn; Adult Dating sites; Pictures from Social Networking Profiles; Chat Sessions; Bestiality; Data Cleaning; …
On Cyber Attacks And Signature Based Intrusion Detection For Modbus Based Industrial Control Systems, Wei Gao, Thomas H. Morris
On Cyber Attacks And Signature Based Intrusion Detection For Modbus Based Industrial Control Systems, Wei Gao, Thomas H. Morris
Journal of Digital Forensics, Security and Law
Industrial control system communication networks are vulnerable to reconnaissance, response injection, command injection, and denial of service attacks. Such attacks can lead to an inability to monitor and control industrial control systems and can ultimately lead to system failure. This can result in financial loss for control system operators and economic and safety issues for the citizens who use these services. This paper describes a set of 28 cyber attacks against industrial control systems which use the MODBUS application layer network protocol. The paper also describes a set of standalone and state based intrusion detection system rules which can be …
Idiographic Digital Profiling: Behavioral Analysis Based On Digital Forensics, Chad M. Steel
Idiographic Digital Profiling: Behavioral Analysis Based On Digital Forensics, Chad M. Steel
Journal of Digital Forensics, Security and Law
Idiographic digital profiling (IDP) is the application of behavioral analysis to the field of digital forensics. Previous work in this field takes a nomothetic approach to behavioral analysis by attempting to understand the aggregate behaviors of cybercriminals. This work is the first to take an idiographic approach by examining a particular subject's digital footprints for immediate use in an ongoing investigation. IDP provides a framework for investigators to analyze digital behavioral evidence for the purposes of case planning, subject identification, lead generation, obtaining and executing warrants, and prosecuting offenders.
On Identities In Modern Networks, Libor Polcak, Radek Hranick, Tomas Martınek
On Identities In Modern Networks, Libor Polcak, Radek Hranick, Tomas Martınek
Journal of Digital Forensics, Security and Law
Communicating parties inside computer networks use different kind of identifiers. Some of these identifiers are stable, e.g., logins used to access a specific service, some are only temporary, e.g., dynamically assigned IP addresses. This paper tackles several challenges of lawful interception that emerged in modern networks. The main contribution is the graph model that links identities learnt from various sources distributed in a network. The inferred identities result into an interception of more detailed data in conformance with the issued court order. The approach deals with network address translation, short-lived identifiers and simultaneous usage of different identities. The approach was …
Exploring Forensic Implications Of The Fusion Drive, Shruti Gupta, Marcus Rogers
Exploring Forensic Implications Of The Fusion Drive, Shruti Gupta, Marcus Rogers
Journal of Digital Forensics, Security and Law
This paper explores the forensic implications of Apple’s Fusion Drive. The Fusion Drive is an example of auto-tiered storage. It uses a combination of a flash drive and a magnetic drive. Data is moved between the drives automatically to maximize system performance. This is different from traditional caches because data is moved and not simply copied. The research included understanding the drive structure, populating the drive, and then accessing data in a controlled setting to observe data migration strategies. It was observed that all the data is first written to the flash drive with 4 GB of free space always …