Open Access. Powered by Scholars. Published by Universities.®

Forensic Science and Technology Commons

Open Access. Powered by Scholars. Published by Universities.®

1,248 Full-Text Articles 1,640 Authors 1,867,946 Downloads 82 Institutions

All Articles in Forensic Science and Technology

Faceted Search

1,248 full-text articles. Page 48 of 55.

Toward Alignment Between Communities Of Practice And Knowledge-Based Decision Support, Jason Nichols, David Biros, Mark Weiser 2012 Management Science and Information Systems, Spears School of Business, Oklahoma State University

Toward Alignment Between Communities Of Practice And Knowledge-Based Decision Support, Jason Nichols, David Biros, Mark Weiser

Annual ADFSL Conference on Digital Forensics, Security and Law

The National Repository of Digital Forensics Information (NRDFI) is a knowledge repository for law enforcement digital forensics investigators (LEDFI). Over six years, the NRDFI has undertaken significant design revisions in order to more closely align the architecture of the system with theory addressing motivation to share knowledge and communication within ego-centric groups and communities of practice. These revisions have been met with minimal change in usage patterns by LEDFI community members, calling into question the applicability of relevant theory when the domain for knowledge sharing activities expands beyond the confines of an individual organization to a community of practice. When …


A Proposal For Incorporating Programming Blunder As Important Evidence In Abstraction-Filtration-Comparison Test, P. Vinod Bhattathiripad 2012 Cyber Forensic Consultant, Polpaya Mana, Thiruthiyad

A Proposal For Incorporating Programming Blunder As Important Evidence In Abstraction-Filtration-Comparison Test, P. Vinod Bhattathiripad

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper investigates an unexplored concept in Cyber Forensics, namely, a Programming Blunder. Programming Blunder is identified as a variable or a code segment or a field in a database table, which is hardly used or executed in the context of the application or the user’s functionality. Blunder genes can be found in many parts of any program. It is the contention of this paper that this phenomenon of blunders needs to be studied systematically from its very genetic origins to their surface realizations in contrast to bugs and flaws, especially in view of their importance in software copyright infringement …


Update On The State Of The Science Of Digital Evidence Examination, Fred Cohen 2012 CEO, Fred Cohen & Associates President, California Sciences Institute

Update On The State Of The Science Of Digital Evidence Examination, Fred Cohen

Annual ADFSL Conference on Digital Forensics, Security and Law

This paper updates previous work on the level of consensus in foundational elements of digital evidence examination. Significant consensus is found present only after definitions are made explicit, suggesting that, while there is a scientific agreement around some of the basic notions identified, the use of a common language is lacking.

Keywords: Digital forensics examination, terminology, scientific methodology, testability, validation, classification, scientific consensus


Capecitabine Induced Hand And Foot Syndrome And The Reproducibility Of Friction Skin, Rodney Allen Schenk 2012 University of Southern Mississippi

Capecitabine Induced Hand And Foot Syndrome And The Reproducibility Of Friction Skin, Rodney Allen Schenk

Master's Theses

In 2008, a 62 year old male was detained by United States Customs and Immigration officials when attempting to enter the United States because his fingerprints were not detectable. It was later reported by his medical doctor in Singapore that the individual suffered from Hand and Foot Syndrome (palmar-plantar erythrodysaesthesia) as a result of his cancer treatment of capecitabine (N4-pentyloxycarbonyl-5-deoxy-5- fluorocytidine) which causes interruptions to the normal growth of keratinocytes in the friction skin. Capecitabine is a recently developed, orally administered fluoropyrimidine prodrug designed to generate 5-fluorouracil through a three-step enzymatic process giving it antineoplastic properties to combat cancerous tumor …


Efficiency Of Using Commercial Dna Extraction Kits And The Organic Extraction Method In Removal Of Polymerase Chain Reaction Inhibitors, Brandi Jo Payne 2012 University of Southern Mississippi

Efficiency Of Using Commercial Dna Extraction Kits And The Organic Extraction Method In Removal Of Polymerase Chain Reaction Inhibitors, Brandi Jo Payne

Master's Theses

The first step in the determination of a perpetrator of a crime using DNA profiling is obtaining good quality DNA. The substrate on which the body fluid is located may contain substances that can co-extract with DNA and may inhibit subsequent PCR analysis. In this study, the efficiency of the removal of such contaminants were tested using three different methods, namely the PrepFiler DNA extraction kit, DNA IQ DNA extraction system, and the organic DNA extraction protocol. One, two, five, and ten μl of whole blood were deposited on soil, wood chips, and cotton swatches treated with bleach. DNA was …


Table Of Contents, 2012 Embry-Riddle Aeronautical University

Table Of Contents

Journal of Digital Forensics, Security and Law

No abstract provided.


Research Toward A Partially-Automated, And Crime Specific Digital Triage Process Model, Gary Cantrell, David Dampier, Yoginder S. Dandass, Nan Niu, Chris Bogen 2012 Marshall University

Research Toward A Partially-Automated, And Crime Specific Digital Triage Process Model, Gary Cantrell, David Dampier, Yoginder S. Dandass, Nan Niu, Chris Bogen

Computer Sciences and Electrical Engineering Faculty Research

The digital forensic process as traditionally laid out begins with the collection, duplication, and authentication of every piece of digital media prior to examination. These first three phases of the digital forensic process are by far the most costly. However, complete forensic duplication is standard practice among digital forensic laboratories.

The time it takes to complete these stages is quickly becoming a serious problem. Digital forensic laboratories do not have the resources and time to keep up with the growing demand for digital forensic examinations with the current methodologies. One solution to this problem is the use of pre-examination techniques …


Forensic Analysis Of Social Networking Applications On Mobile Devices, Noora Al Mutawa, Ibrahim Baggili, Andrew Marrington 2012 Zayed University

Forensic Analysis Of Social Networking Applications On Mobile Devices, Noora Al Mutawa, Ibrahim Baggili, Andrew Marrington

Electrical & Computer Engineering and Computer Science Faculty Publications

The increased use of social networking applications on smartphones makes these devices a goldmine for forensic investigators. Potential evidence can be held on these devices and recovered with the right tools and examination methods. This paper focuses on conducting forensic analyses on three widely used social networking applications on smartphones: Facebook, Twitter, and MySpace. The tests were conducted on three popular smartphones: BlackBerrys, iPhones, and Android phones. The tests consisted of installing the social networking applications on each device, conducting common user activities through each application, acquiring a forensically sound logical image of each device, and performing manual forensic analysis …


Hfs Plus File System Exposition And Forensics, Scott Ware 2012 University of Central Florida

Hfs Plus File System Exposition And Forensics, Scott Ware

Electronic Theses and Dissertations

The Macintosh Hierarchical File System Plus, HFS +, or as it is commonly referred to as the Mac Operating System, OS, Extended, was introduced in 1998 with Mac OS X 8.1. HFS+ is an update to HFS, Mac OS Standard format that offers more efficient use of disk space, implements international friendly file names, future support for named forks, and facilitates booting on non-Mac OS operating systems through different partition schemes. The HFS+ file system is efficient, yet, complex. It makes use of B-trees to implement key data structures for maintaining meta-data about folders, files, and data. The implementation of …


Comparing Android Applications To Find Copying, Larry Melling, Bob Zeidman 2012 Virtual System Platform Cadence Design Systems

Comparing Android Applications To Find Copying, Larry Melling, Bob Zeidman

Journal of Digital Forensics, Security and Law

The Android smartphone operating system includes a Java virtual machine that enables rapid development and deployment of a wide variety of applications. The open nature of the platform means that reverse engineering of applications is relatively easy, and many developers are concerned as applications similar to their own show up in the Android marketplace and want to know if these applications are pirated. Fortunately, the same characteristics that make an Android application easy to reverse engineer and copy also provide opportunities for Android developers to compare downloaded applications to their own. This paper describes the process for comparing a developer’s …


Forensic Evidence Identification And Modeling For Attacks Against A Simulated Online Business Information System, Manghui Tu, Dianxiang Xu, Eugene Butler, Amanda Schwartz 2012 Purdue University

Forensic Evidence Identification And Modeling For Attacks Against A Simulated Online Business Information System, Manghui Tu, Dianxiang Xu, Eugene Butler, Amanda Schwartz

Journal of Digital Forensics, Security and Law

Forensic readiness of business information systems can support future forensics investigation or auditing on external/internal attacks, internal sabotage and espionage, and business fraud. To establish forensics readiness, it is essential for an organization to identify which fingerprints are relevant and where they can be located, to determine whether they are logged in a forensically sound way and whether all the needed fingerprints are available to reconstruct the events successfully. Also, a fingerprint identification and locating mechanism should be provided to guide potential forensics investigation in the future. Furthermore, mechanisms should be established to automate the security incident tracking and reconstruction …


To License Or Not To License Updated: An Examination Of State Statutes Regarding Private Investigators And Digital Examiners, Thomas Lonardo, Doug White, Alan Rea 2012 Roger Williams University

To License Or Not To License Updated: An Examination Of State Statutes Regarding Private Investigators And Digital Examiners, Thomas Lonardo, Doug White, Alan Rea

Journal of Digital Forensics, Security and Law

In this update to the 2009 year's study, the authors examine statutes that regulate, license, and enforce investigative functions in each US state. After identification and review of Private Investigator licensing requirements, the authors find that very few state statutes explicitly differentiate between Private Investigators and Digital Examiners, but do see a trend of more states making some distinction. The authors contacted all state regulatory agencies where statutory language was not explicit, and as a result, set forth the various state approaches to professional Digital Examiner licensing. As was the case in the previous two iterations of this research, the …


Dns In Computer Forensics, Neil F. Wright 2012 University of Westminster

Dns In Computer Forensics, Neil F. Wright

Journal of Digital Forensics, Security and Law

The Domain Name Service (DNS) is a critical core component of the global Internet and integral to the majority of corporate intranets. It provides resolution services between the human-readable name-based system addresses and the machine operable Internet Protocol (IP) based addresses required for creating network level connections. Whilst structured as a globally dispersed resilient tree data structure, from the Global and Country Code Top Level Domains (gTLD/ccTLD) down to the individual site and system leaf nodes, it is highly resilient although vulnerable to various attacks, exploits and systematic failures.


Ipad2 Logical Acquisition: Automated Or Manual Examination?, Somaya Ali, Sumaya AlHosani, Farah AlZarooni, Ibrahim Baggili 2012 Zayed University

Ipad2 Logical Acquisition: Automated Or Manual Examination?, Somaya Ali, Sumaya Alhosani, Farah Alzarooni, Ibrahim Baggili

Electrical & Computer Engineering and Computer Science Faculty Publications

Due to their usage increase worldwide, iPads are on the path of becoming key sources of digital evidence in criminal investigations. This research investigated the logical backup acquisition and examination of the iPad2 device using the Apple iTunes backup utility while manually examining the backup data (manual examination) and automatically parsing the backup data (Lantern software-automated examination).The results indicate that a manual examination of the logical backup structure from iTunes reveals more digital evidence, especially if installed application data is required for an investigation. However, the researchers note that if a quick triage is needed of an iOS device, then …


Older, Wiser, Novice: An Autoethnographic Study Of Nontraditional Students' Participation In Collegiate Forensics, Laura Kathleen Pelletier 2012 Minnesota State University - Mankato

Older, Wiser, Novice: An Autoethnographic Study Of Nontraditional Students' Participation In Collegiate Forensics, Laura Kathleen Pelletier

All Graduate Theses, Dissertations, and Other Capstone Projects

There is a growing trend in nontraditional college student enrollments in the United States. Older, nontraditional students are currently the majority on many college campuses. Due to the constraints on nontraditional students' time, they are often unable to spend as much time on campus as traditional students and are unable to fully partake in campus life and socialization. Cocurricular activities, such as collegiate forensics, can be time consuming activities which for nontraditional students, especially those who have children, may seem like an impossible fit for their already busy schedules. Because college demographics continue to change and there are a growing …


Forensics And The Basic Communication Course: A New Path To Satisfying Learning Outcomes, Benjamin Walker 2012 Minnesota State University - Mankato

Forensics And The Basic Communication Course: A New Path To Satisfying Learning Outcomes, Benjamin Walker

All Graduate Theses, Dissertations, and Other Capstone Projects

Forensic scholars have long written about the educational benefits of forensics, but very few have attempted to tie the activity to learning objectives from the curriculum. This thesis seeks to determine if collegiate forensics can offer the same learning opportunities as one of the most common and fundamental communication classes in the discipline: the basic communication course. This research uses experiential learning as a pedagogical framework for forensics in attempting to answer if forensics can offer the same learning opportunities of the basic communication course, and if so, how the activity does this and what the students actually learn. Likert …


Column: The Physics Of Digital Information-Part 2, Fred Cohen 2012 CEO, Fred Cohen & Associates President, California Sciences Institute

Column: The Physics Of Digital Information-Part 2, Fred Cohen

Journal of Digital Forensics, Security and Law

In part 1 of this series (Cohen, 2011a), we discussed some of the basics of building a physics of digital information. Assuming, as we have, that science is about causality and that a scientific theory should require that cause(C) produces effect (E) via mechanism M (written C→ME), we explore that general theory of digital systems from the perspective of attributing effects (i.e., traces of activities in digital systems) to their causes. Full details of the current version of this physics are available online2 , and in this article, we explore a few more of them.


Technology Corner: Dating Of Electronic Hardware For Prior Art Investigations, Sellam Ismail 2012 VintageTech

Technology Corner: Dating Of Electronic Hardware For Prior Art Investigations, Sellam Ismail

Journal of Digital Forensics, Security and Law

In many legal matters, specifically patent litigation, determining and authenticating the date of computer hardware or other electronic products or components is often key to establishing the item as legitimate evidence of prior art. Such evidence can be used to buttress claims of technologies available or of events transpiring by or at a particular date.


Applying The Acpo Principles In Public Cloud Forensic Investigations, Harjinder S. Lallie, Lee Pimlott 2012 University of Warwick, Coventry

Applying The Acpo Principles In Public Cloud Forensic Investigations, Harjinder S. Lallie, Lee Pimlott

Journal of Digital Forensics, Security and Law

The numerous advantages offered by cloud computing has fuelled its growth and has made it one of the most significant of current computing trends. The same advantages have created complex issues for those conducting digital forensic investigations. Digital forensic investigators rely on the ACPO (Association of Chief Police Officers) or similar guidelines when conducting an investigation, however the guidelines make no reference to some of the issues presented by cloud investigations. This study investigates the impact of cloud computing on ACPO’s core principles and asks whether these principles can still be applied in a cloud investigation and the challenges presented …


An Overview Of The Jumplist Configuration File In Windows 7, Harjinder S. Lallie, Parmjit S. Bains 2012 University of Warwick, Coventry

An Overview Of The Jumplist Configuration File In Windows 7, Harjinder S. Lallie, Parmjit S. Bains

Journal of Digital Forensics, Security and Law

The introduction of Jumplists in Windows 7 was an important feature from a forensic examiners viewpoint. Jumplist configuration files can provide the examiner with a wealth of information relating to file access and in particular: dates/times, Volume GUIDs and unique file object IDs relating to those files. Some of the information in the Jumplist could be used to build a more precise timeline relating to system and file usage. In this article, we analyse the structure of a Jumplist configuration file and in particular a record from a Jumplist configuration file and highlight some of the important entries therein.


Digital Commons powered by bepress