Sampling: Making Electronic Discovery More Cost Effective,
2011
Metropolitan State University, St. Paul, Minnesota
Sampling: Making Electronic Discovery More Cost Effective, Milton Luoma, Vicki Luoma
Annual ADFSL Conference on Digital Forensics, Security and Law
With the huge volumes of electronic data subject to discovery in virtually every instance of litigation, time and costs of conducting discovery have become exceedingly important when litigants plan their discovery strategies. Rather than incurring the costs of having lawyers review every document produced in response to a discovery request in search of relevant evidence, a cost effective strategy for document review planning is to use statistical sampling of the database of documents to determine the likelihood of finding relevant evidence by reviewing additional documents. This paper reviews and discusses how sampling can be used to make document review more …
Digital Forensics And The Law,
2011
Sam Houston State University, Department of Computer Science
Digital Forensics And The Law, Karon N. Murff, Hugh E. Gardenier, Martha L. Gardenier
Annual ADFSL Conference on Digital Forensics, Security and Law
As computers and digital devices become more entrenched in our way of life, they become tools for both good and nefarious purposes. When the digital world collides with the legal world, a vast chasm is created. This paper will reflect how the legal community is failing to meet its obligation to provide adequate representation due to a lack of education about digital (computer) forensics. Whether in a civil litigation setting or a criminal setting, attorneys, prosecutors and judges have inadequate knowledge when it comes to the important questions they need to ask regarding digital evidence. Reliance on expert witnesses is …
Defining Success: Examining What It Means To Be Good In Forensics,
2011
Minnesota State University - Mankato
Defining Success: Examining What It Means To Be Good In Forensics, David J. Brennan
All Graduate Theses, Dissertations, and Other Capstone Projects
For decades college students have been competing in forensic activity (forensics), spending countless hours researching, writing, and performing speeches. Forensic scholars have never created an overarching definition of what it means to be successful in forensics. A survey was created and sent out on the individual events listserv, asking competitors and coaches to define success. Analysis reveals both competitors and coaches believe success in forensics is a combination of competitive achievement, building communication skills, and personal growth.
Kindle Forensics: Acquisition & Analysis,
2011
School of Computer and Security Science
Kindle Forensics: Acquisition & Analysis, Peter Hannay
Journal of Digital Forensics, Security and Law
The Amazon Kindle eBook reader supports a wide range of capabilities beyond reading books. This functionality includes an inbuilt cellular data connection known as Whispernet. The Kindle provides web browsing, an application framework, eBook delivery and other services over this connection. The historic data left by user interaction with this device may be of forensic interest. Analysis of the Amazon Kindle device has resulted in a method to reliably extract and interpret data from these devices in a forensically complete manner.
Column: The Consortium Of Digital Forensics Specialists (Cdfs),
2011
CDFS Board Chair
Column: The Consortium Of Digital Forensics Specialists (Cdfs), Christopher Kelly
Journal of Digital Forensics, Security and Law
Digital forensic practitioners are faced with an extraordinary opportunity. In fact, we may never again be faced with such an opportunity, and this opportunity will challenge us in ways we may never again be challenged. At this point in the history of the Digital Forensics profession, digital forensic specialists have the unique opportunity to help this profession emerge from its infancy. But for this profession to mature -- and to flourish -- individuals and organizations integral to the practice must assemble and shape its future. This is our opportunity. In fact, this is our mandate.
Judges’ Awareness, Understanding, And Application Of Digital Evidence,
2011
Gary Kessler Associates
Judges’ Awareness, Understanding, And Application Of Digital Evidence, Gary C. Kessler
Journal of Digital Forensics, Security and Law
As digital evidence grows in both volume and importance in criminal and civil courts, judges need to fairly and justly evaluate the merits of the offered evidence. To do so, judges need a general understanding of the underlying technologies and applications from which digital evidence is derived. Due to the relative newness of the computer forensics field, there have been few studies on the use of digital forensic evidence and none about judges’ relationship with digital evidence. This paper describes a recent study, using grounded theory methods, into judges’ awareness, knowledge, and perceptions of digital evidence. This study is the …
Technology Corner: Analysing E-Mail Headers For Forensic Investigation,
2011
Banday University of Kashmir India
Technology Corner: Analysing E-Mail Headers For Forensic Investigation, M. T. Banday
Journal of Digital Forensics, Security and Law
Electronic Mail (E-Mail), which is one of the most widely used applications of Internet, has become a global communication infrastructure service. However, security loopholes in it enable cybercriminals to misuse it by forging its headers or by sending it anonymously for illegitimate purposes, leading to e-mail forgeries. E-mail messages include transit handling envelope and trace information in the form of structured fields which are not stripped after messages are delivered, leaving a detailed record of e-mail transactions. A detailed header analysis can be used to map the networks traversed by messages, including information on the messaging software and patching policies …
The Implications Of Virtual Environments In Digital Forensic Investigations,
2011
University of Central Florida
The Implications Of Virtual Environments In Digital Forensic Investigations, Farrah M. Patterson
Electronic Theses and Dissertations
This research paper discusses the role of virtual environments in digital forensic investigations. With virtual environments becoming more prevalent as an analysis tool in digital forensic investigations, it’s becoming more important for digital forensic investigators to understand the limitation and strengths of virtual machines. The study aims to expose limitations within commercial closed source virtual machines and open source virtual machines. The study provides a brief overview of history digital forensic investigations and virtual environments, and concludes with an experiment with four common open and closed source virtual machines; the effects of the virtual machines on the host machine as …
Survey On Cloud Forensics And Critical Criteria For Cloud Forensic Capability: A Preliminary Analysis,
2011
University College Dublin
Survey On Cloud Forensics And Critical Criteria For Cloud Forensic Capability: A Preliminary Analysis, Keyun Ruan, Ibrahim Baggili, Joe Carthy, Tahar Kechadi
Electrical & Computer Engineering and Computer Science Faculty Publications
In this paper we present the current results and analysis of the survey “Cloud forensics and critical criteria for cloud forensic capability” carried out towards digital forensic experts and practitioners. This survey was created in order to gain a better understanding on some of the key questions of the new field - cloud forensics - before further research and development. We aim to understand concepts such as its definition, the most challenging issues, most valuable research directions, and the critical criteria for cloud forensic capability.
Cat Detect (Computer Activity Timeline Detection): A Tool For Detecting Inconsistency In Computer Activity Timelines,
2011
Zayed University
Cat Detect (Computer Activity Timeline Detection): A Tool For Detecting Inconsistency In Computer Activity Timelines, Andrew Marrington, Ibrahim Baggili, George Mohay, Andrew Clark
Electrical & Computer Engineering and Computer Science Faculty Publications
The construction of timelines of computer activity is a part of many digital investigations. These timelines of events are composed of traces of historical activity drawn from system logs and potentially from evidence of events found in the computer file system. A potential problem with the use of such information is that some of it may be inconsistent and contradictory thus compromising its value. This work introduces a software tool (CAT Detect) for the detection of inconsistency within timelines of computer activity. We examine the impact of deliberate tampering through experiments conducted with our prototype software tool. Based on the …
Program And Proceedings: Nebraska Academy Of Sciences 1880–2011, 131st Anniversary Year, One Hundred-Twenty-First Annual Meeting,
2011
University of Nebraska - Lincoln
Program And Proceedings: Nebraska Academy Of Sciences 1880–2011, 131st Anniversary Year, One Hundred-Twenty-First Annual Meeting
Nebraska Academy of Sciences: Programs and Proceedings
Program
Aeronautics and Space Science
Collegiate Academy: Biology
Collegiate Academy: Chemistry and Physics
Chemistry and Physics
Biological and Medical Sciences
Junior Academy, Senior High Competition
Nebraska Wesleyan University Health and Sciences Graduate School Fair, Olin and Smith Curtiss Halls
Teaching of Science and Math
Aeronautics and Space Science, Poster Session
Applied Science and Technology
Maiben Memorial Lecture: Erin Flynn, Omaha Henry Doorly Zoo
Aeronautics
Anthropology
Earth Science
Junior Academy, Junior High Competition
The Application Of Chemometrics To The Detection And Classification Of Ignitable Liquids In Fire Debris Using The Total Ion Spectrum,
2011
University of Central Florida
The Application Of Chemometrics To The Detection And Classification Of Ignitable Liquids In Fire Debris Using The Total Ion Spectrum, Jennifer N. Lewis
Electronic Theses and Dissertations
Current methods in ignitable liquid identification and classification from fire debris rely on pattern recognition of ignitable liquids in total ion chromatograms, extracted ion profiles, and target compound comparisons, as described in American Standards for Testing and Materials E1618-10. The total ion spectra method takes advantage of the reproducibility among sample spectra from the same American Society for Testing and Materials class. It is a method that is independent of the chromatographic conditions that affect retention times of target compounds, thus aiding in the use of computer-based library searching techniques. The total ion spectrum was obtained by summing the ion …
Forensic Analysis Of Plug Computers,
2011
University of Central Florida
Forensic Analysis Of Plug Computers, Scott Conrad, Greg Dorn, Philip Craiger
Publications
A plug computer is essentially a cross between an embedded computer and a traditional computer, and with many of the same capabilities. However, the architecture of a plug computer makes it difficult to apply commonly used digital forensic methods. This paper describes methods for extracting and analyzing digital evidence from plug computers. Two popular plug computer models are examined, the SheevaPlug and the Pogoplug.
Column: File Cabinet Forensics,
2011
Naval Postgraduate School, California
Column: File Cabinet Forensics, Simson Garfinkel
Journal of Digital Forensics, Security and Law
Researchers can spend their time reverse engineering, performing reverse analysis, or making substantive contributions to digital forensics science. Although work in all of these areas is important, it is the scientific breakthroughs that are the most critical for addressing the challenges that we face. Reverse Engineering is the traditional bread-and-butter of digital forensics research. Companies like Microsoft and Apple deliver computational artifacts (operating systems, applications and phones) to the commercial market. These artifacts are bought and used by billions. Some have evil intent, and (if society is lucky), the computers end up in the hands of law enforcement. Unfortunately the …
Column: Putting The Science In Digital Forensics,
2011
California Sciences Institute, Fred Cohen & Associates
Column: Putting The Science In Digital Forensics, Fred Cohen
Journal of Digital Forensics, Security and Law
In a recent study, digital forensics was found to lack a consensus around even the most basis notions and terminology of the field. To quote: “These two preliminary studies individually suggest that (1) scientific consensus in the area of digital forensic evidence examination is lacking in the broad sense, but that different groups within that overall community may have limited consensus around areas in which they have special expertise, and (2) that the current peerreviewed publication process is not acting to bring about the sorts of elements typically found in the advancement of a science toward such a consensus. ... …
Technology Corner: Internet Packet Sniffers,
2011
University of New Mexico
Technology Corner: Internet Packet Sniffers, Nick V. Flor, Kenneth Guillory
Journal of Digital Forensics, Security and Law
The best way to understand an internet packet sniffer, hereafter “packet sniffer”, is by analogy with a wiretap. A wiretap is a piece of hardware that allows a person to eavesdrop on phone conversations over a telephone network. Similarly, a packet sniffer is a piece of software that allows a person to eavesdrop on computer communications over the internet. A packet sniffer can be used as a diagnostic tool by network administrators or as a spying tool by hackers who can use it to steal passwords and other private information from computer users. Whether you are a network administrator or …
Sampling: Making Electronic Discovery More Cost Effective,
2011
Metropolitan State University
Sampling: Making Electronic Discovery More Cost Effective, Milton Luoma, Vicki Luoma
Journal of Digital Forensics, Security and Law
With the huge volumes of electronic data subject to discovery in virtually every instance of litigation, time and costs of conducting discovery have become exceedingly important when litigants plan their discovery strategies. Rather than incurring the costs of having lawyers review every document produced in response to a discovery request in search of relevant evidence, a cost effective strategy for document review planning is to use statistical sampling of the database of documents to determine the likelihood of finding relevant evidence by reviewing additional documents. This paper reviews and discusses how sampling can be used to make document review more …
Column: The Physics Of Digital Information,
2011
CEO, Fred Cohen & Associates President, California Sciences Institute
Column: The Physics Of Digital Information, Fred Cohen
Journal of Digital Forensics, Security and Law
No abstract provided.
Developing A Forensic Continuous Audit Model,
2011
University of South Florida, St. Petersburg
Developing A Forensic Continuous Audit Model, Grover S. Kearns, Katherine J. Barker, Stephen P. Danese
Journal of Digital Forensics, Security and Law
Despite increased attention to internal controls and risk assessment, traditional audit approaches do not seem to be highly effective in uncovering the majority of frauds. Less than 20 percent of all occupational frauds are uncovered by auditors. Forensic accounting has recognized the need for automated approaches to fraud analysis yet research has not examined the benefits of forensic continuous auditing as a method to detect and deter corporate fraud. The purpose of this paper is to show how such an approach is possible. A model is presented that supports the acceptance of forensic continuous auditing by auditors and management as …
Analysis Of Data Remaining On Second Hand Adsl Routers,
2011
Edith Cowan University; Perth, Western Australia
Analysis Of Data Remaining On Second Hand Adsl Routers, Patryk Szewczyk
Journal of Digital Forensics, Security and Law
In theory, an ADSL router can provide an additional layer of security to a wired and wireless network through; access control, wireless encryption, firewall rule sets, and network event logging. An ADSL router may also contain the users’ usage habits and broadband account credentials. However, end-users may be unaware of the intricacies of the security measures available and the potentially confidential information stored on their device. As a result a second hand ADSL router may contain a wealth of user-specific information if not wiped and disposed of in a secure manner. This paper shows the data that was acquired from …
