Detect Kernel-Mode Rootkits Via Real Time Logging & Controlling Memory Access,
2017
Stockholm University
Detect Kernel-Mode Rootkits Via Real Time Logging & Controlling Memory Access, Satoshi Tanda, Irvin Homem, Igor Korkin
Annual ADFSL Conference on Digital Forensics, Security and Law
Modern malware and spyware platforms attack existing antivirus solutions and even Microsoft PatchGuard. To protect users and business systems new technologies developed by Intel and AMD CPUs may be applied. To deal with the new malware we propose monitoring and controlling access to the memory in real time using Intel VT-x with EPT. We have checked this concept by developing MemoryMonRWX, which is a bare-metal hypervisor. MemoryMonRWX is able to track and trap all types of memory access: read, write, and execute. MemoryMonRWX also has the following competitive advantages: fine-grained analysis, support of multi-core CPUs and 64-bit Windows 10. MemoryMonRWX …
Harnessing Predictive Models For Assisting Network Forensic Investigations Of Dns Tunnels,
2017
Stockholm University
Harnessing Predictive Models For Assisting Network Forensic Investigations Of Dns Tunnels, Irvin Homem, Panagiotis Papapetrou
Annual ADFSL Conference on Digital Forensics, Security and Law
In recent times, DNS tunneling techniques have been used for malicious purposes, however network security mechanisms struggle to detect them. Network forensic analysis has been proven effective, but is slow and effort intensive as Network Forensics Analysis Tools struggle to deal with undocumented or new network tunneling techniques. In this paper, we present a machine learning approach, based on feature subsets of network traffic evidence, to aid forensic analysis through automating the inference of protocols carried within DNS tunneling techniques. We explore four network protocols, namely, HTTP, HTTPS, FTP, and POP3. Three features are extracted from the DNS tunneled traffic: …
An Accidental Discovery Of Iot Botnets And A Method For Investigating Them With A Custom Lua Dissector,
2017
University of Alabama, Birmingham
An Accidental Discovery Of Iot Botnets And A Method For Investigating Them With A Custom Lua Dissector, Max Gannon, Gary Warner, Arsh Arora
Annual ADFSL Conference on Digital Forensics, Security and Law
This paper presents a case study that occurred while observing peer-to-peer network communications on a botnet monitoring station and shares how tools were developed to discover what ultimately was identified as Mirai and many related IoT DDOS Botnets. The paper explains how researchers developed a customized protocol dissector in Wireshark using the Lua coding language, and how this enabled them to quickly identify new DDOS variants over a five month period of study.
Kelihos Botnet: A Never-Ending Saga,
2017
University of Alabama, Birmingham
Kelihos Botnet: A Never-Ending Saga, Arsh Arora, Max Gannon, Gary Warner
Annual ADFSL Conference on Digital Forensics, Security and Law
This paper investigates the recent behavior of the Kelihos botnet, a spam-sending botnet that accounts for many millions of emails sent each day. The paper demonstrates how a team of students are able to perform a longitudinal malware study, making significant observations and contributions to the understanding of a major botnet using tools and techniques taught in the classroom. From this perspective the paper has two objectives: encouragement and observation. First, by providing insight into the methodology and tools used by student researchers to document and understand a botnet, the paper strives to embolden other academic programs to follow a …
Minimum Education Requirements For Crime Scene Investigators,
2017
San Jose State University
Minimum Education Requirements For Crime Scene Investigators, Araseli Saldivar
Themis: Research Journal of Justice Studies and Forensic Science
The initial crime scene investigation is critical since it is the primary step in the investigative process; therefore, individuals assigned to process a scene should be highly educated. Improperly educated (or uneducated) crime scene investigators (CSIs) can mishandle evidence during an investigation, affecting the outcome of cases. The minimum education requirement for CSIs should transition from a high school diploma—the current requirement—toward a bachelor’s degree. The importance of acquiring a college-level education is observed in a study conducted on crime scene examiners in Australia. To determine the educational requirement for CSIs in the United States, information was gathered electronically from …
Optimizing Collection Of Trace Biological Samples From Vehicle Headrests,
2017
San Jose State University
Optimizing Collection Of Trace Biological Samples From Vehicle Headrests, Kevin Tang, Jesse Ramirez, John Bond, Jocelyn Weart, Yvette Delatorre, Ian Fitch, Steven Lee
Themis: Research Journal of Justice Studies and Forensic Science
Tape-lifting and swabbing are two methods commonly used for collecting biological samples in the United Kingdom and United States to investigate vehicle crimes. Determining the optimal collection method may lead to an increase in generating DNA profiles and crime-solving. The objective of this study is to evaluate the efficiency of adhesive tape and the double-swab collection methods for investigating vehicle crimes with possible touch DNA samples. Two experiments were conducted to evaluate the use of tape-lifts and swabs on spiked common vehicle fabric materials. The efficiency of recovery between the two collection methods was performed using qPCR. The results from …
Physical Match: Unique Fracture Patterns In Wooden Popsicle Sticks,
2017
San Jose State University
Physical Match: Unique Fracture Patterns In Wooden Popsicle Sticks, Yiu Ming Sunny Lau
Themis: Research Journal of Justice Studies and Forensic Science
Physical match (or physical fit) evidence was considered reliable in court for years, until the Daubert case, which required standardized scientific methodology on all forensic evidence. Physical matching faces the same criticism as other forms of physical evidence (specifically, that it lacks a scientific foundation). Physical matching is based on the idea that when an object is fractured, the shape of each fragment is unique and it is not possible to recreate a fragment that is identical to any other. In this study, fifty wooden popsicle sticks were broken in half, the pieces were mixed, and then reconstructed using physical …
Forensics’ Fight: A Need For Aggressive Strategies Against Confirmation Bias,
2017
San Jose State University
Forensics’ Fight: A Need For Aggressive Strategies Against Confirmation Bias, Madison Mcgowan
Themis: Research Journal of Justice Studies and Forensic Science
In 2009, the National Academy of Sciences produced a lengthy report illuminating significant weaknesses present within the forensic community. One complex fault found in forensics was conformation bias. Since it is within human nature to make decisions based on contextual information, assumptions, and pre-held opinions, confirmation bias is an issue that will continue to persist. Therefore, stronger efforts must be made to recognize and abate the problem of bias within the field of forensics in order to preserve the notion that forensic science exists to serve principles of both truth and justice. Accordingly, this paper argues for the fight against …
An Evaluation Of Escience Lab Kits For Online Learning,
2017
San Jose State University
An Evaluation Of Escience Lab Kits For Online Learning, Diana Orozco
Themis: Research Journal of Justice Studies and Forensic Science
Higher education online science courses generally lack the hands-on components essential in understanding theories, methods, and techniques in chemistry and biology. Companies like eScience Labs construct kits to facilitate online learning, which provide students with hands-on activities relevant to their science courses. In order to evaluate ease, efficacy, and comprehension of the forensic science kits by eScience Labs was completed while writing observations of the activities during and after completion; the lab manual learning objectives were compared to results of activities and two stopwatches took elapsed time of each activity to compare with the stated times in the kit manual. …
Moral Time And Homicide Investigations.,
2017
University of Louisville
Moral Time And Homicide Investigations., David Stuart Lapsey Jr.
Electronic Theses and Dissertations
Previous literature explores the many dimensions of homicide investigations, including case and individual characteristics, evidence and investigative activities. However, little research delves into situational characteristics and their relationship to specific homicides, charge severity sought by prosecutors and sentence length given to homicide offenders. The current study sampled homicide cases (N=68) to gather baseline information and data regarding judicial outcomes. Donald Black’s Theory of Moral Time (2011) is tested and utilized as the study’s conceptual framework for the study’s hypotheses.
Chemical Identification Of Synthetic Cannabinoids In Herbal Incense Products,
2017
CUNY John Jay College
Chemical Identification Of Synthetic Cannabinoids In Herbal Incense Products, Karol F. Alvarez Heredia
Student Theses
The emergence of synthetic cannabinoids is an ongoing challenge for forensic, clinical analytical chemists and toxicologists. Different analogs are continuously introduced in the market to circumvent the legislation and to enhance their pharmacological activity. In the present project, a total of seven synthetic cannabinoids were identified in four herbal incense products by employing GCMS, and LC-TOF. Fractional collection of four out of the seven synthetic cannabinoids was performed using HPLC followed by the collection of FTIR-ATR spectra. Five out of seven synthetic cannabinoids were classified as indazole carboxamide derivatives, which include 5Fluoro-EMB-Pinaca, 5Fluoro-AMB, MA-Chminaca, AB-Chminaca, and 5Fluoro-AKB-48. The remaining two …
Jurisdiction, Privacy, And Ownership: Dna Technology And Field Dynamics In Conflict-Related Mass Fatalities,
2017
Independent Researcher
Jurisdiction, Privacy, And Ownership: Dna Technology And Field Dynamics In Conflict-Related Mass Fatalities, Stefan Schmitt, Dallas Mazoori
Genocide Studies and Prevention: An International Journal
This article explores the dynamics and challenges of undertaking human identifications in states experiencing armed conflict or emerging therefrom. It emphasises the integral role of the State in human identifications and the need for the legal acts of the State in identifying an individual and confirming their death to be integrated into any humanitarian response to repatriating the dead. Conflict-related mass fatalities occur in uncontrolled circumstances, making DNA-based human identifications necessary. In states lacking the necessary forensic infrastructure, the promise of expedited human identifications through outsourcing DNA work can lead to the State abdicating the necessary jurisdiction and scientific transparency …
Tracking The Sexual Assault Kit Backlog,
2017
Duquesne University
Tracking The Sexual Assault Kit Backlog, Kallie Crawford, Lyndsie Ferrara
Undergraduate Research and Scholarship Symposium
The backlog of untested sexual assault kits is a national problem. Numerous federal funding opportunities offer the forensic science and law enforcement communities valuable resources needed to test the kits, but issues still remain. The majority of resources are focused on the collection and testing of sexual assault kits, but the tracking of the kits has not been a primary focus. This research highlights improvements that can be made to better understand the current backlog and improve the future processing and tracking of kits. Given the lack of a universal evidence tracking database among agencies, tracking sexual assault kits seems …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2017, 137th Anniversary Year, One Hundred-Twenty-Seventh Annual Meeting,
2017
University of Nebraska - Lincoln
Program And Proceedings: Nebraska Academy Of Sciences 1880–2017, 137th Anniversary Year, One Hundred-Twenty-Seventh Annual Meeting
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Chemistry and Physics
Collegiate Academy: Biology
Collegiate Academy: Chemistry and Physics
Biological and Medical Sciences
Aeronautics and Space Science: Poster Session
Applied Science and Technology
Maiben Memorial Lecture
Anthropology
Earth Science
Applied Science and Technology
Teaching of Science and Mathematics
Environmental Sciences
Friend of Science Award: Kacie Baum and Todd Young
Special Issue Of Best Papers From The 11th International Conference On Systematic Approaches To Digital Forensic Engineering (Sadfe 2016),
2017
Embry-Riddle Aeronautical University
Special Issue Of Best Papers From The 11th International Conference On Systematic Approaches To Digital Forensic Engineering (Sadfe 2016)
Journal of Digital Forensics, Security and Law
The SADFE series feature the different editions of the International Conference on Systematic Approaches to Digital Forensics Engineering. Now in its eleventh edition, SADFE has established itself as the premier conference for researchers and practitioners working in Systematic Approaches to Digital Forensics Engineering.
SADFE 2016, the eleventh international conference on Systematic Approaches to Digital Forensic Engineering was held in Kyoto, Japan, September 20 - 22, 2016.
Digital forensics engineering and the curation of digital collections in cultural institutions face pressing and overlapping challenges related to provenance, chain of custody, authenticity, integrity, and identity. The generation, analysis and sustainability of digital …
Compression Of Virtual-Machine Memory In Dynamic Malware Analysis,
2017
Mississippi State University
Compression Of Virtual-Machine Memory In Dynamic Malware Analysis, James E. Fowler Ph.D.
Journal of Digital Forensics, Security and Law
Lossless compression of memory dumps from virtual machines that run malware samples is considered with the goal of significantly reducing archival costs in dynamic-malware-analysis applications. Given that, in such dynamic-analysis scenarios, malware samples are typically run in virtual machines just long enough to activate any self-decryption or other detection- avoidance maneuvers, the virtual-machine memory typically changes little from that of the baseline state, with the difference being attributable in large degree to the loading of additional executables and libraries. Consequently, delta coding is proposed to compress the current virtual-machine memory dump by coding its differences with respect to a predicted …
Front Matter,
2017
Embry-Riddle Aeronautical University
Find Me If You Can: Mobile Gps Mapping Applications Forensic Analysis & Snavp The Open Source, Modular, Extensible Parser,
2017
University of New Haven
Find Me If You Can: Mobile Gps Mapping Applications Forensic Analysis & Snavp The Open Source, Modular, Extensible Parser, Jason Moore, Ibrahim Baggili, Frank Breitinger
Journal of Digital Forensics, Security and Law
The use of smartphones as navigation devices has become more prevalent. The ubiquity of hand-held navigation devices such as Garmins or Toms Toms has been falling whereas the ownership of smartphones and their adoption as GPS devices is growing. This work provides a comprehensive study of the most popular smartphone mapping applications, namely Google Maps, Apple Maps, Waze, MapQuest, Bing, and Scout, on both Android and iOS. It details what data was found, where it was found, and how it was acquired for each application. Based on the findings, the work allowed for the construction of a tool capable of …
A Forensic Email Analysis Tool Using Dynamic Visualization,
2017
University of Erlangen-Nuremberg
A Forensic Email Analysis Tool Using Dynamic Visualization, Johannes Stadlinger, Andreas Dewald
Journal of Digital Forensics, Security and Law
Communication between people counts to the most important information of today’s business. As a result, in case of forensic investigations in big companies, analysis of communication data in general and especially email, as the still most widely used business communication platform with an immense and still growing volume, is a typical task in digital forensics. One of the challenges is to identify the relevant communication partners and structures in the suspects surrounding as quickly as possible in order to react appropriately and identify further targets of evaluation. Due to the amount of emails in typical inboxes, reading through all the …
Table Of Contents,
2017
Embry-Riddle Aeronautical University
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
