Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations,
2015
National Research Nuclear University Moscow Engineering & Physics Institute (NRNU MEPhI), Department of Cryptology and Discrete Mathematics, Russia
Two Challenges Of Stealthy Hypervisors Detection: Time Cheating And Data Fluctuations, Igor Korkin
Annual ADFSL Conference on Digital Forensics, Security and Law
Hardware virtualization technologies play a significant role in cyber security. On the one hand these technologies enhance security levels, by designing a trusted operating system. On the other hand these technologies can be taken up into modern malware which is rather hard to detect. None of the existing methods is able to efficiently detect a hypervisor in the face of countermeasures such as time cheating, temporary self-uninstalling, memory hiding etc. New hypervisor detection methods which will be described in this paper can detect a hypervisor under these countermeasures and even count several nested ones. These novel approaches rely on the …
The Use Of Criminal Profilers In The Prosecution Of Serial Killers,
2015
San Jose State University
The Use Of Criminal Profilers In The Prosecution Of Serial Killers, Chelsea Van Aken
Themis: Research Journal of Justice Studies and Forensic Science
The purpose of this paper is to analyze the concept of criminal profiling in terms of serial killers in the United States. The research provided in this paper was found using the most recent research available on the topic. The FBI’s Behavioral Unit, or National Center for the Analysis of Violent Crime (NCAVC), is the current leading law enforcement agency that investigates these types of crimes. They utilize definitions, typographies, and motives to create a criminal profile to investigate serial killings. Ultimately, these profiles are inadequate because they are inconclusive and exclude multiple suspects that are potentially dangerous. Therefore, criminal …
The "Csi Effect" And Its Potential Impact On Juror Decisions,
2015
San Jose State University
The "Csi Effect" And Its Potential Impact On Juror Decisions, John Alldredge
Themis: Research Journal of Justice Studies and Forensic Science
The “CSI Effect” was first described in the media as a phenomenon resulting from viewing forensic and crime based television shows. This effect influences jurors to have unrealistic expectations of forensic science during a criminal trial and affect jurors’ decisions in the conviction or acquittal process. Research has shown the “CSI Effect” has a possible pro-defense bias, in that jurors are less likely to convict without the presence of some sort of forensic evidence. Some studies show actors in the criminal justice system are changing their tactics, as if this effect has a significant influence, causing them to request unnecessary …
Reducing Contamination In Forensic Science,
2015
San Jose State University
Reducing Contamination In Forensic Science, Carly Balk
Themis: Research Journal of Justice Studies and Forensic Science
The sensitivity of modern forensic techniques has drastically increased, with sensitive technology detecting even the smallest traces of DNA evidence left behind. This has made it possible to detect DNA profiles deposited through contamination. When DNA contamination occurs in forensic science, it has the potential to change the outcome of a criminal investigation and may have significant social and financial repercussions. A compilation of global research shows that DNA evidence transfer can occur during forensic product manufacturing, the fingerprinting process, or even autopsy and crime lab examinations. These vital areas of the forensic investigation are vulnerable to contamination, and national …
Mathematics In Forensic Firearm Examination,
2015
State University of New York, Upstate Medical University, Pediatric Residency Program, Syracuse, New York
Mathematics In Forensic Firearm Examination, Erin N. Zalewski
Renée Crown University Honors Thesis Projects - All
Forensic Science encompasses many disciplines that employ the scientific method to examine, analyze, and interpret physical evidence in the courtroom. The discipline of Forensic Firearm Examination involves the examination and comparison of ballistic evidence components to determine if they came from the same source. In other words, firearm examiners are tasked with determining whether spent cartridge cases or bullets were fired through the same gun. Examination of ballistic evidence can involve the employment of automated matching systems, comparison microscopy, and mathematical analysis. The comparison microscope is the tool of the firearm examiner and allows for the simultaneous view of ballistic …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2015, 135th Anniversary Year, One Hundred-Twenty-Fifth Annual Meeting,
2015
University of Nebraska - Lincoln
Program And Proceedings: Nebraska Academy Of Sciences 1880–2015, 135th Anniversary Year, One Hundred-Twenty-Fifth Annual Meeting
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Chemistry and Physics
Collegiate Academy: Biology
Collegiate Academy: Chemistry and Physics
Anthropology
Biological and Medical Sciences
Junior Academy, Senior High Competition
Aeronautics and Space Science, Poster Session
Maiben Memorial Lecture: “Nebraska Biocontainment Unit Planning and Response to Ebola,” Ebola team, University of nebraska medical Center
Applied Science and Technology
Earth Science
Teaching of Science and Math
Junior Academy, Junior High Competition
Brief For Professor Albert E. Scherr As Amicus Curiae In Support Of Petitioner,
2015
University of New Hampshire School of Law
Brief For Professor Albert E. Scherr As Amicus Curiae In Support Of Petitioner, Albert E. Scherr
Law Faculty Scholarship
INTRODUCTION AND SUMMARY OF ARGUMENT Professor Scherr agrees with petitioner that review is warranted because the Maryland Court of Appeals decision is erroneous. The Fourth Amendment does not sanction police harvesting of DNA without probable cause and a warrant and without the subject’s knowledge or consent, to be used however the authorities deem appropriate and without restriction. The Maryland Court of Appeals’ decision is contrary to the Supreme Court’s jurisprudence as articulated in the Riley v. California – Maryland v. King – United States v. Jones trilogy. This case fits squarely in the center of the triangle formed by that …
Science 208 Forensic Science Ii: Death Analysis Spring 2015,
2015
Parkland College
Science 208 Forensic Science Ii: Death Analysis Spring 2015, John Moore
General Science
No abstract provided.
Science 208 Forensic Science Ii: Death Analysis Fall 2015,
2015
Parkland College
Science 208 Forensic Science Ii: Death Analysis Fall 2015, John Moore
General Science
No abstract provided.
Science 108-001 Essentials Of Forensic Science Fall 2015,
2015
Parkland College
Science 108-001 Essentials Of Forensic Science Fall 2015, Christina Beatty
General Science
No abstract provided.
Quantitative Assessment Of The Effects Of Microbial Degradation Of A Simple Hydrocarbon Mixture,
2015
University of Central Florida
Quantitative Assessment Of The Effects Of Microbial Degradation Of A Simple Hydrocarbon Mixture, Jessica Kindell
Electronic Theses and Dissertations
Ignitable liquids consist of either a single organic compound or a complex organic mixture. In regards to fire debris analysis, the analyst is responsible for determining if an ignitable liquid residue is present. However, when extracted from soil-containing fire debris evidence, chemical degradation from microorganisms is observed to result in the loss of compounds based on chemical structure. It can also happen when the evidence container is stored at room temperature before analysis. This can present a challenge to the fire debris analyst when identifying and classifying the ignitable liquid residue based on the criteria established by standard test methods. …
The Challenges Of Seizing And Searching The Contents Of Wi-Fi Devices For The Modern Investigator,
2015
Edith Cowan University
The Challenges Of Seizing And Searching The Contents Of Wi-Fi Devices For The Modern Investigator, Dan Blackman, Patryk Szewczyk
Australian Digital Forensics Conference
To the modern law enforcement investigator, the potential for an offender to have a mobile device on his or her person, who connects to a Wi-Fi network, may afford evidence to place them at a scene, at a particular time. Whilst tools to interrogate mobile devices and Wi-Fi networks, have undergone significant development, little research has been conducted with regards to interrogating Wi-Fi routers and the evidence they may contain. This paper demonstrates that multiple inhibiting factors exist for forensic investigators when attempting to extract data from Wi-Fi routers at the scene. Data volatility means the Wi-Fi router cannot be …
Table Of Contents,
2015
Embry-Riddle Aeronautical University
Table Of Contents
Journal of Digital Forensics, Security and Law
No abstract provided.
From The Editor-In-Chief,
2015
JDFSL
From The Editor-In-Chief, Ibrahim Baggili
Journal of Digital Forensics, Security and Law
Welcome to JDFSL’s second issue for 2015! First, I would like to thank our editorial board, reviewers, and the JDFSL team for bringing this issue to life. In this issue, we continue our multidisciplinary tradition. The first paper, Two challenges of stealthy hypervisors detection: time cheating and data fluctuations, showcases an important contribution to the computing discipline. The use of virtualization has dramatically increased given our strong reliance on cloud services both private and public. Even though hypervisors enhance security, they can also be exploited by malware. Therefore, this paper is of importance given that it introduces a novel method …
From The Editor-In-Chief,
2015
JDFSL
From The Editor-In-Chief, Ibrahim Baggili
Journal of Digital Forensics, Security and Law
Welcome to JDFSL’s first issue for 2015! First, I would like to thank our editorial board, reviewers, and the JDFSL team for bringing this issue to life. It has been a big year for JDFSL as the journal continues to progress. We are continuing our indexing efforts for the journal and we are getting closer with some of the major databases.
Police Opinions Of Digital Evidence Response Handling In The State Of Georgia: An Examination From The Viewpoint Of Local Agencies’ Patrol Officers,
2015
Nova Southeastern University
Police Opinions Of Digital Evidence Response Handling In The State Of Georgia: An Examination From The Viewpoint Of Local Agencies’ Patrol Officers, Tanya Macneil
CCAC Theses and Dissertations
This research examined opinions of local law enforcement agencies’ patrol officers in the State of Georgia regarding preparedness and expectations for handling of digital evidence. The increased criminal use of technology requires that patrol officers be prepared to handle digital evidence in many different situations. The researcher’s goal was to gain insight into how patrol officers view their preparedness to handle digital evidence as well as their opinions on management expectations regarding patrol officers’ abilities to handle digital evidence. The research focused on identifying whether a gap existed between patrol officers’ opinions of digital evidence and the patrol officers’ views …
Network And Device Forensic Analysis Of Android Social-Messaging Applications,
2015
University of New Haven
Network And Device Forensic Analysis Of Android Social-Messaging Applications, Daniel Walnycky, Ibrahim Baggili, Andrew Marrington, Jason Moore, Frank Breitinger
Electrical & Computer Engineering and Computer Science Faculty Publications
In this research we forensically acquire and analyze the device-stored data and network traffic of 20 popular instant messaging applications for Android. We were able to reconstruct some or the entire message content from 16 of the 20 applications tested, which reflects poorly on the security and privacy measures employed by these applications but may be construed positively for evidence collection purposes by digital forensic practitioners. This work shows which features of these instant messaging applications leave evidentiary traces allowing for suspect data to be reconstructed or partially reconstructed, and whether network forensics or device forensics permits the reconstruction of …
An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?,
2015
University of New Haven
An Empirical Comparison Of Widely Adopted Hash Functions In Digital Forensics: Does The Programming Language And Operating System Make A Difference?, Satyendra Gurjar, Ibrahim Baggili, Frank Breitinger, Alice E. Fischer
Electrical & Computer Engineering and Computer Science Faculty Publications
Hash functions are widespread in computer sciences and have a wide range of applications such as ensuring integrity in cryptographic protocols, structuring database entries (hash tables) or identifying known files in forensic investigations. Besides their cryptographic requirements, a fundamental property of hash functions is efficient and easy computation which is especially important in digital forensics due to the large amount of data that needs to be processed when working on cases. In this paper, we correlate the runtime efficiency of common hashing algorithms (MD5, SHA-family) and their implementation. Our empirical comparison focuses on C-OpenSSL, Python, Ruby, Java on Windows and …
Science 108-002h Essentials Of Forensic Science Hybrid Fall 2015,
2015
Parkland College
Science 108-002h Essentials Of Forensic Science Hybrid Fall 2015, Sybil Anderson
General Science
No abstract provided.
Strategies For Enhanced Genetic Analysis Of Trace Dna From Touch Dna Evidence And Household Dust,
2015
University of Central Florida
Strategies For Enhanced Genetic Analysis Of Trace Dna From Touch Dna Evidence And Household Dust, Katherine Farash
Electronic Theses and Dissertations
In forensic casework it is often necessary to obtain genetic profiles from crime scene samples that contain increasingly smaller amounts of genetic material, called Low Template DNA (LTDNA). Two examples of LTDNA sources are touch DNA evidence and dust bunnies. Touch DNA refers to DNA that is left behind through casual contact of a donor with an object or another person. Touch DNA can be used to prove a suspect was present at a crime scene. Dust bunnies, or dust conglomerates, typically contain trapped shed skin cells of anyone in the vicinity along with fibers, dirt, hair, and other trace …
