Creating Realistic Corpora For Security And Forensic Education,
2011
School of Information and Library Science, University of North Carolina, Chapel Hill, NC
Creating Realistic Corpora For Security And Forensic Education, Kam Woods, Christopher A. Lee, Simson Garfinkel, David Dittrich, Adam Russell, Kris Kearton
Annual ADFSL Conference on Digital Forensics, Security and Law
We present work on the design, implementation, distribution, and use of realistic forensic datasets to support digital forensics and security education. We describe in particular the “M57-Patents” scenario, a multi-modal corpus consisting of hard drive images, RAM images, network captures, and images from other devices typically found in forensics investigations such as USB drives and cellphones. Corpus creation has been performed as part of a scripted scenario; subsequently it is less “noisy” than real-world data but retains the complexity necessary to support a wide variety of forensic education activities. Realistic forensic corpora allow direct comparison of approaches and tools across …
Developing A Forensic Continuous Audit Model,
2011
Gregory, Sharer & Stuart Term Professor in Forensic Accounting, College of Business, University of South Florida, St. Petersburg
Developing A Forensic Continuous Audit Model, Grover S. Kearns, Katherine J. Barker
Annual ADFSL Conference on Digital Forensics, Security and Law
Despite increased attention to internal controls and risk assessment, traditional audit approaches do not seem to be highly effective in uncovering the majority of frauds. Less than 20 percent of all occupational frauds are uncovered by auditors. Forensic accounting has recognized the need for automated approaches to fraud analysis yet research has not examined the benefits of forensic continuous auditing as a method to detect and deter corporate fraud. The purpose of this paper is to show how such an approach is possible. A model is presented that supports the acceptance of forensic continuous auditing by auditors and management as …
Development Of A Distributed Print‐Out Monitoring System For Efficient Forensic Investigation,
2011
Hitachi, Ltd., Yokohama Research Laboratory, Graduate School of Informatics, Kyoto University
Development Of A Distributed Print‐Out Monitoring System For Efficient Forensic Investigation, Satoshi Kai, Tetsutaro Uehara
Annual ADFSL Conference on Digital Forensics, Security and Law
If information leakage occurs, an investigator is instructed to specify what documents were leaked and who leaked them. In the present work, a distributed print-out monitoring system—which consists of a virtual printer driver and print-out policy/log management servers—was developed. For easily matching the discovered (i.e., leaked) paper document with the print-out log, the virtual printer driver acquires full-text of printed-out documents by DDI hooking technique to check the content, transforms a spool file to a picture file and creates both a thumbnail and text log for forensic investigation afterwards. The log size is as only about 0.04 times bigger than …
Mac Os X Forensics: Password Discovery,
2011
Virginia Commonwealth University, Richmond, Virginia
Mac Os X Forensics: Password Discovery, David Primeaux, Robert Dahlberg, Kamnab Keo, Stephen Larson, B. Pennell, K. Sherman
Annual ADFSL Conference on Digital Forensics, Security and Law
OS X provides a password-rich environment in which passwords protect OS X resources and perhaps many other resources accessed through OS X. Every password an investigator discovers in an OS X environment has the potential for use in discovering other such passwords, and any discovered passwords may also be useful in other aspects of an investigation, not directly related to the OS X environment. This research advises the use of multiple attack vectors in approaching the password problem in an OS X system, including the more generally applicable non-OS X-specific techniques such as social engineering or well-known password cracking techniques …
Software Piracy Forensics: Impact And Implications Of Post‐Piracy Modifications,
2011
Cyber Forensic Consultant, Polpaya Mana, Thiruthiyad, Calicut, Kerala India
Software Piracy Forensics: Impact And Implications Of Post‐Piracy Modifications, Vinod Bhattathiripad, S. Santhosh Baboo
Annual ADFSL Conference on Digital Forensics, Security and Law
Piracy is potentially possible at any stage of the lifetime of the software. In a post-piracy situation, however, the growth of the respective versions of the software (both the original and pirated) is expected to be in different directions as a result of expectedly different implementation strategies. This paper shows how such post-piracy modifications are of special interest to a cyber crime expert investigating software piracy and suggests that the present software piracy forensic (or software copyright infringement investigation) approaches require amendments to take in such modifications. For this purpose, the paper also presents a format that is jargon-free, so …
Understanding Issues In Cloud Forensics: Two Hypothetical Case Studies,
2011
Cyber Defense Lab, Department of CSEE, University of Maryland, Baltimore County (UMBC)
Understanding Issues In Cloud Forensics: Two Hypothetical Case Studies, Josiah Dykstra, Alan T. Sherman
Annual ADFSL Conference on Digital Forensics, Security and Law
The inevitable vulnerabilities and criminal targeting of cloud environments demand an understanding of how digital forensic investigations of the cloud can be accomplished. We present two hypothetical case studies of cloud crimes; child pornography being hosted in the cloud, and a compromised cloudbased website. Our cases highlight shortcomings of current forensic practices and laws. We describe significant challenges with cloud forensics, including forensic acquisition, evidence preservation and chain of custody, and open problems for continued research.
Keywords: Cloud computing, cloud forensics, digital forensics, case studies
A Practitioners Guide To The Forensic Investigation Of Xbox 360 Gaming Consoles,
2011
Drexel University
A Practitioners Guide To The Forensic Investigation Of Xbox 360 Gaming Consoles, Ashley L. Podhradsky, Rob D’Ovidio, Cindy Casey
Annual ADFSL Conference on Digital Forensics, Security and Law
Given the ubiquitous nature of computing, individuals now have nearly 24-7 access to the internet. People are not just going online through traditional means with a PC anymore, they are now frequently using nontraditional devices such as cell phones, smart phones, and gaming consoles. Given the increased use of gaming consoles for online access, there is also an increased use of gaming consoles to commit criminal activity. The digital forensic community has been tasked with creating new approaches for forensically analyzing gaming consoles. In this research paper the authors demonstrate different tools, both commercial and open source, available to forensically …
Sampling: Making Electronic Discovery More Cost Effective,
2011
Metropolitan State University, St. Paul, Minnesota
Sampling: Making Electronic Discovery More Cost Effective, Milton Luoma, Vicki Luoma
Annual ADFSL Conference on Digital Forensics, Security and Law
With the huge volumes of electronic data subject to discovery in virtually every instance of litigation, time and costs of conducting discovery have become exceedingly important when litigants plan their discovery strategies. Rather than incurring the costs of having lawyers review every document produced in response to a discovery request in search of relevant evidence, a cost effective strategy for document review planning is to use statistical sampling of the database of documents to determine the likelihood of finding relevant evidence by reviewing additional documents. This paper reviews and discusses how sampling can be used to make document review more …
Digital Forensics And The Law,
2011
Sam Houston State University, Department of Computer Science
Digital Forensics And The Law, Karon N. Murff, Hugh E. Gardenier, Martha L. Gardenier
Annual ADFSL Conference on Digital Forensics, Security and Law
As computers and digital devices become more entrenched in our way of life, they become tools for both good and nefarious purposes. When the digital world collides with the legal world, a vast chasm is created. This paper will reflect how the legal community is failing to meet its obligation to provide adequate representation due to a lack of education about digital (computer) forensics. Whether in a civil litigation setting or a criminal setting, attorneys, prosecutors and judges have inadequate knowledge when it comes to the important questions they need to ask regarding digital evidence. Reliance on expert witnesses is …
As Antitrust Case Ends, Microsoft Is Victorious In Defeat,
2011
Western Michigan University
As Antitrust Case Ends, Microsoft Is Victorious In Defeat, Norman Hawker, Robert H. Lande
All Faculty Scholarship
As the final judgment in the celebrated Microsoft case ends, this piece very briefly assesses the impact of its remedy. When evaluated in terms of its most important goals, the remedy has proven to be a failure. Microsoft's monopoly power in the PC operating systems market is now as great as it was when the case was brought in 1998 or the remedy was ordered in 2002. The article also very briefly discusses the implications of this remedy for Google and AT&T.
Tanggung Jawab Hukum Penyelenggara Sistem Elektronik (Law Responsibility Of The Electronic System Providers),
2011
Faculty of Law Universitas Indonesia
Tanggung Jawab Hukum Penyelenggara Sistem Elektronik (Law Responsibility Of The Electronic System Providers), Abdul Salam
Indonesia Law Review
Reviewing Edmon Makarim’s book which is about Law Responsibility of the Electronic System Providers, remind us that easiness and availability of electronic system in electronic transaction in private or public happen because the role of electronic system providers. Behind the important and central role, there is big responsibility for electronic system providers. But because of wide of definition of provision of electronic system and so many people who involve in electronic system providers, there is a question in our mind, how is the shape of responsibility of the electronic system providers if the electronic system which is held is broken …
Name Calling On The Internet: The Problems Faced By Victims Of Defamatory Content In Cyberspace,
2011
, Benjamin N. Cardozo School of Yeshiva University, LL.M. candidate
Name Calling On The Internet: The Problems Faced By Victims Of Defamatory Content In Cyberspace, Sarudzai Chitsa
Cornell Law School Inter-University Graduate Student Conference Papers
In the past decade or so, internet libel has become one of the hot topics in internet law. Internationally, courts have dealt with an enormous amount of cases brought by both the suppliers and consumers of the internet services. Although the advent of the World Wide Web has come with many legal problems; this paper will only focus at the problems that are being faced by the victims of defamatory speech on the internet in trying to seek compensation through the courts. These problems include, inter alia, the reluctance of the courts in unmasking the identity of the authors of …
Regulation Of Gaming Device Software Development: Nevada’S Paradigm Shift On Independent Contractors,
2011
University of Nevada, Las Vegas -- William S. Boyd School of Law
Regulation Of Gaming Device Software Development: Nevada’S Paradigm Shift On Independent Contractors, Dan R. Reaser
UNLV Gaming Law Journal
On April 22, 2010, the Nevada Gaming Commission (hereinafter the “Commission”) adopted a number of amendments to Regulation 14 governing the manufacture of gaming devices. A subset of these amendments were promulgated pursuant to changes to the Nevada Gaming Control Act (hereinafter the “Act”) during the Seventy-Fifth Session of the Nevada Legislature. The rules relate to “control programs” and the independent contractors who design, develop, program, produce, or compose software, source language or executable code compiled into the control program of a new gaming device or of a modification to a gaming device submitted for approval. These particular rules became …
Jacobsen Revisited: Conditions, Covenants And The Future Of Open-Source Software Licenses,
2011
University of Washington School of Law
Jacobsen Revisited: Conditions, Covenants And The Future Of Open-Source Software Licenses, Yamini Menon
Washington Journal of Law, Technology & Arts
Open-source software licensing has become mainstream in the field of software development. Nowhere is this more evident than in the 2008 Federal Circuit decision Jacobsen v. Katzer, where the court first interpreted the terms of an open-source software license. The Jacobsen decision offers an important first step in how to interpret the terms of an open-source license, though it does not address how to interpret licenses other than the Artistic License. This Article explores how Jacobsen’s reasoning can be used to interpret the terms of other open-source licenses, particularly the GPL v.2, GPL v.3, Apache License v.2, BSD …
Teens, Technology, And Cyberstalking: The Domestic Violence Wave Of The Future?,
2011
Alexander Blewett III School of Law at the University of Montana
Teens, Technology, And Cyberstalking: The Domestic Violence Wave Of The Future?, Andrew King-Ries
Faculty Law Review Articles
The American criminal justice system, (therefore), is facing a future domestic violence crisis. Unfortunately, authorities-both parents and law enforcement-tend to minimize the seriousness of violence within adolescent relationships and to minimize the seriousness of stalking. In addition, given the prevalence and embrace of technology by teenagers, criminalizing "normal" teenage behavior seems counter-productive. While an effective criminal justice system response to this problem has yet to be developed, the first step will be for parents and law enforcement to recognize the risk and take it seriously. The second step will be to "renorm" unhealthy teenage relationship norms. It is possible that …
Gimme A Brekka!: Deciphering "Authorization" Under The Cfaa And How Employers Can Protect Their Data,
2011
University of Washington School of Law
Gimme A Brekka!: Deciphering "Authorization" Under The Cfaa And How Employers Can Protect Their Data, Amber L. Leaders
Washington Journal of Law, Technology & Arts
Federal circuit courts offer conflicting interpretations of when an employee violates the Computer Fraud and Abuse Act (CFAA) by accessing an employer’s computer system without authorization. Enacted originally as an anti-hacker statute, the language of the CFAA proves ambiguous when courts attempt to apply its sanctions to individuals given access to a computer (such as an employee by an employer). Circuit Courts have interpreted the statute differently, generally applying one of two theories to reach their interpretations: (1) agency theory; or (2) looking to the plain language of the statute and the rule of lenity. These differing interpretations have resulted …
First-Class Objects,
2011
Cornell Law School
First-Class Objects, James Grimmelmann
Cornell Law Faculty Publications
What is the difference between "James Grimmelmann" and "@grimmelm" and why should we care? Some computer systems, like Facebook and credit reporting agencies, are inherently "about" people. Others are not. This essay argues that the key technical difference is whether they use unique identifiers to refer to people in their databases. From this single distinction, a host of social and humanistic consequences follow. The essay taxonomizes them and teases out some of their implications for privacy law.
Jurisprudence For A Digital Age: Free Software And The Need For A New Media Legal Authority,
2011
University of the District of Columbia School of Law
Jurisprudence For A Digital Age: Free Software And The Need For A New Media Legal Authority, Nicholas Clark
University of the District of Columbia Law Review
No abstract provided.
Revising The Analysis Of Personal Jurisdiction To Accommodate Internet-Based Personal Contacts,
2011
University of the District of Columbia School of Law
Revising The Analysis Of Personal Jurisdiction To Accommodate Internet-Based Personal Contacts, Matthew L. Perdoni
University of the District of Columbia Law Review
From online banking, to cyber-shopping, to the growth of social-networking websites, the Internet is a medium for human interaction as much as it is a part of modern commerce and business, and now encompasses nearly every facet of American life. By all indications, use will become more widespread and complex over time. The Internet now facilitates the modern functional equivalent of human interaction, and provides worldwide access to users with the mere click of a button. For these reasons, examining the role of the Internet in the law is critical. Particularly, it is necessary to consider whether and to what …
Back Matter,
2011
Embry-Riddle Aeronautical University
