Inferring Previously Uninstalled Applications From Residual Partial Artifacts,
2016
George Mason University, Fairfax, Virginia, United States
Inferring Previously Uninstalled Applications From Residual Partial Artifacts, Jim Jones, Tahir Khan, Kathryn Laskey, Alex Nelson, Mary Laamanen, Douglas White
Annual ADFSL Conference on Digital Forensics, Security and Law
In this paper, we present an approach and experimental results to suggest the past presence of an application after the application has been uninstalled and the system has remained in use. Current techniques rely on the recovery of intact artifacts and traces, e.g., whole files, Windows Registry entries, or log file entries, while our approach requires no intact artifact recovery and leverages trace evidence in the form of residual partial files. In the case of recently uninstalled applications or an instrumented infrastructure, artifacts and traces may be intact and complete. In most cases, however, digital artifacts and traces are al- …
One-Time Pad Encryption Steganography System,
2016
Embry-Riddle Aeronautical University, Daytona Beach, FL
One-Time Pad Encryption Steganography System, Michael J. Pelosi, Gary Kessler, Michael Scott S. Brown
Annual ADFSL Conference on Digital Forensics, Security and Law
In this paper we introduce and describe a novel approach to adaptive image steganography which is combined with One-Time Pad encryption, and demonstrate the software which implements this methodology. Testing using the state-of-the-art steganalysis software tool StegExpose concludes the image hiding is reliably secure and undetectable using reasonably-sized message payloads (≤25% message bits per image pixel; bpp). Payload image file format outputs from the software include PNG, BMP, JP2, JXR, J2K, TIFF, and WEBP. A variety of file output formats is empirically important as most steganalysis programs will only accept PNG, BMP, and possibly JPG, as the file inputs.
Keywords: …
Domestic Violence Risk Assessments: Considerations For Selection And Use,
2016
Portland State University
Domestic Violence Risk Assessments: Considerations For Selection And Use, Ryan M. Labrecque
Criminology and Criminal Justice Faculty Publications and Presentations
Focuses on Senate Bill 789 (Increases penalty for crime of strangulation) and what to consider when mandating law enforcement officers to perform domestic violence risk assessments.
Crime In Developing Countries: The Contribution Of Crime Science,
2016
CUNY John Jay College
Crime In Developing Countries: The Contribution Of Crime Science, Mangai Natarajan
Publications and Research
No abstract provided.
Applying Grounded Theory Methods To Digital Forensics Research,
2016
Faculty of Technology, De Montfort University
Applying Grounded Theory Methods To Digital Forensics Research, Ahmed Almarzooqi, Andrew Jones, Richard Howley
Annual ADFSL Conference on Digital Forensics, Security and Law
Deciding on a suitable research methodology is challenging for researchers. In this paper, grounded theory is presented as a systematic and comprehensive qualitative methodology in the emergent field of digital forensics research. This paper applies grounded theory in a digital forensics research project undertaken to study how organisations build and manage digital forensics capabilities. This paper gives a step-by-step guideline to explain the procedures and techniques of using grounded theory in digital forensics research. The paper gives a detailed explanation of how the three grounded theory coding methods (open, axial, and selective coding) can be used in digital forensics research. …
Covert6: A Tool To Corroborate The Existence Of Ipv6 Covert Channels,
2016
Department of Computer and Information Technology, Purdue University
Covert6: A Tool To Corroborate The Existence Of Ipv6 Covert Channels, Raymond A. Hansen, Lourdes Gino, Dominic Savio
Annual ADFSL Conference on Digital Forensics, Security and Law
Covert channels are any communication channel that can be exploited to transfer information in a manner that violates the system’s security policy. Research in the field has shown that, like many communication channels, IPv4 and the TCP/IP protocol suite have been susceptible to covert channels, which could be exploited to leak data or be used for anonymous communications. With the introduction of IPv6, researchers are acutely aware that many vulnerabilities of IPv4 have been remediated in IPv6. However, a proof of concept covert channel system was demonstrated in 2006. A decade later, IPv6 and its related protocols have undergone major …
Acceleration Of Statistical Detection Of Zero-Day Malware In The Memory Dump Using Cuda-Enabled Gpu Hardware,
2016
Independent Researchers, Moscow, Russia
Acceleration Of Statistical Detection Of Zero-Day Malware In The Memory Dump Using Cuda-Enabled Gpu Hardware, Igor Korkin, Iwan Nesterow
Annual ADFSL Conference on Digital Forensics, Security and Law
This paper focuses on the anticipatory enhancement of methods of detecting stealth software. Cyber security detection tools are insufficiently powerful to reveal the most recent cyber-attacks which use malware. In this paper, we will present first an idea of the highest stealth malware, as this is the most complicated scenario for detection because it combines both existing anti-forensic techniques together with their potential improvements. Second, we will present new detection methods which are resilient to this hidden prototype. To help solve this detection challenge, we have analyzed Windows’ memory content using a new method of Shannon Entropy calculation; methods of …
Using Computer Behavior Profiles To Differentiate Between Users In A Digital Investigation,
2016
Indiana University Purdue University Indianapolis
Using Computer Behavior Profiles To Differentiate Between Users In A Digital Investigation, Shruti Gupta, Marcus Rogers
Annual ADFSL Conference on Digital Forensics, Security and Law
Most digital crimes involve finding evidence on the computer and then linking it to a suspect using login information, such as a username and a password. However, login information is often shared or compromised. In such a situation, there needs to be a way to identify the user without relying exclusively on login credentials. This paper introduces the concept that users may show behavioral traits which might provide more information about the user on the computer. This hypothesis was tested by conducting an experiment in which subjects were required to perform common tasks on a computer, over multiple sessions. The …
Current Challenges And Future Research Areas For Digital Forensic Investigation,
2016
School of Computer Science, University College Dublin, Ireland
Current Challenges And Future Research Areas For Digital Forensic Investigation, David Lillis, Brett A. Becker, Tadhg O’Sullivan, Mark Scanlon
Annual ADFSL Conference on Digital Forensics, Security and Law
Given the ever-increasing prevalence of technology in modern life, there is a corresponding increase in the likelihood of digital devices being pertinent to a criminal investigation or civil litigation. As a direct consequence, the number of investigations requiring digital forensic expertise is resulting in huge digital evidence backlogs being encountered by law enforcement agencies throughout the world. It can be anticipated that the number of cases requiring digital forensic analysis will greatly increase in the future. It is also likely that each case will require the analysis of an increasing number of devices including computers, smartphones, tablets, cloud-based services, Internet …
Forensic Analysis Of Ares Galaxy Peer-To-Peer Network,
2016
Politieacademie, The Netherlands
Forensic Analysis Of Ares Galaxy Peer-To-Peer Network, Frank Kolenbrander, Nhien-An Le-Khac, Tahar Kechadi
Annual ADFSL Conference on Digital Forensics, Security and Law
Child Abuse Material (CAM) is widely available on P2P networks. Over the last decade several tools were made for 24/7 monitoring of peer-to-peer (P2P) networks to discover suspects that use these networks for downloading and distribution of CAM. For some countries the amount of cases generated by these tools is so great that Law Enforcement (LE) just cannot handle them all. This is not only leading to backlogs and prioritizing of cases but also leading to discussions about the possibility of disrupting these networks and sending warning messages to potential CAM offenders. Recently, investigators are reporting that they are creating …
Keynote Speaker,
2016
Computer Security and Forensics Expert
Keynote Speaker, Chuck Easttom
Annual ADFSL Conference on Digital Forensics, Security and Law
Conference Keynote Speaker, Chuck Easttom
Restorative Resources: A New Theory In Juvenile Offender Control ~ Examining The Successes Of Restorative Resources In Sonoma County And The Impact It Had On One Police Sergeant’S Journey,
2016
St. Mary's College of California, and University of San Francisco
Restorative Resources: A New Theory In Juvenile Offender Control ~ Examining The Successes Of Restorative Resources In Sonoma County And The Impact It Had On One Police Sergeant’S Journey, Stephen Wayne Cramer
The International Undergraduate Journal For Service-Learning, Leadership, and Social Change
No abstract provided.
John M. Hagedorn, The Insane Chicago Way: The Daring Plan By Chicago Gangs To Create A Spanish Mafia,
2016
Eastern Kentucky University
John M. Hagedorn, The Insane Chicago Way: The Daring Plan By Chicago Gangs To Create A Spanish Mafia, Thomas Barker
Qualitative Criminology (QC)
"In The Insane Chicago Way, Professor Hagedorn opines that the super street gangs in Chicago have fundamentally changed since the 1990s. He provides an “institutionalized history” of the rise and fall of the Spanish Growth and Development (SGD) alliance to document the fundamental changes in Chicago. He rightly concludes that the SGD is “almost completely unknown to the public, the police, the professors and even most gang members” (p. 1). This powerful SGD case study is supported by the author’s long history of gang study and his interviews with gang leaders and street gang members, and with organized crime—Chicago …
Editorial,
2016
Michigan State University
Editorial, Tom Holt
Qualitative Criminology (QC)
"Welcome to the first issue of the fourth volume of the Journal of Qualitative Criminal Justice & Criminology. This is my first issue as editor, and I am pleased to continue along the path established by Will Oliver. It has been both exciting and challenging to take the reins and transition into this role. Thankfully Will already had a great crop of articles prepared for this issue. In a way, you could argue this issue is a result of both of our efforts. To that end, this issue highlights the journal’s continued emphasis on high-quality qualitative scholarship. The first …
Mass Murder And The Mass Media: Understanding The Construction Of The Social Problem Of Mass Shootings In The Us,
2016
State University of New York at Oswego
Mass Murder And The Mass Media: Understanding The Construction Of The Social Problem Of Mass Shootings In The Us, Jaclyn Schildkraut
Qualitative Criminology (QC)
"Nearly as soon as the first shot is fired in a mass shooting, the news media already are rushing to break coverage, the likes of which typically last days or, in the more extreme cases, weeks. Though mass shootings are rare in occurrence, the disproportionate amount of coverage they receive in the media leads the public to believe that they occur at a much more regular frequency than they do. In order to understand how the public comes to understand mass shooting events, however, one first must understand how the stories are constructed by the media. The present study takes …
Old Message In A New Bottle: Taking Gang Rivalries Online Through Rap Battle Music Videos On Youtube,
2016
Rowan University
Old Message In A New Bottle: Taking Gang Rivalries Online Through Rap Battle Music Videos On Youtube, Joseph D. Johnson, Natalie Schell-Busey
Qualitative Criminology (QC)
"The Internet is changing society, including criminal behavior. It has been shown that gangs are active online, but it is unclear how gangs are using the Internet. Most studies seem to conclude that gang members are not using the Internet instrumentally to commit or promote criminal behavior, but these same studies show that gang members use social media for flame wars— to insult and threaten one another. We argue that using social media in this way is actually an instrumental use of the Internet because it promotes violence. According to the code of the street, a diss requires a response, …
Jody Miller And Wilson R. Palacios, Editors, Qualitative Research In Criminology,
2016
Eastern Kentucky University
Jody Miller And Wilson R. Palacios, Editors, Qualitative Research In Criminology, Carl Root
Qualitative Criminology (QC)
"Qualitative Research in Criminology is Volume 20 in the series titled Advances in Criminological Theory edited by William S. Laufer and Freda Adler. The title of Miller and Palacios’ contribution brings to mind the saying “one of these things is not like the others.” In fact, they acknowledge as much on page three of the introduction, as they state, “For some readers, our strategy may beg the question, why does a volume oriented around methodology belong in a theoretical series?” Miller and Palacios give a brief answer to this question, but allow the seventeen chapters that comprise their volume …
Homeland Security In The Post-9/11 Era: Forced Compliance Along The Northern Border,
2016
University of Akron
Homeland Security In The Post-9/11 Era: Forced Compliance Along The Northern Border, Nancy E. Marion, Ronald Gelleny
Qualitative Criminology (QC)
"The border relationship between the U.S. and Canada has traditionally been very trusting, allowing for an ease of trade and travel. However, the terrorist attacks of 9/11 altered this comfortable association. Now, U.S. policy is geared toward protecting the homeland from illegal immigration and potential terrorist actions. In other words, for Americans, security concerns trump trade. At the same time, Canada remains concerned with maintaining an ease of trade and travel with the U.S. To do this, Canada has been forced to establish and implement increased security measures as outlined by U.S. officials, even though there is strong opposition from …
When The Watchers Are Watched: An Interpretive Phenomenological Analysis Of Body-Worn Cameras,
2016
Washington State University
When The Watchers Are Watched: An Interpretive Phenomenological Analysis Of Body-Worn Cameras, David A. Makin
Qualitative Criminology (QC)
"This research explores the individual construction of the bodyworn camera (BWC) within what would be labeled as an average size police agency. Using a pre- and post-implementation qualitative design and leveraging interpretive phenomenological analysis as the analytical strategy, this research explores the nuanced reaction to this technological diffusion within the agency. Results reveal global themes spanning a continuum of negative and positive reactions to the diffusion, with an overwhelming acceptance of the device and individual construction of how best to use the device. While providing an initial lens of analysis for future researchers, the research includes considerable unanswered questions concerning …
The Csi Effect: Fact Or Fiction?,
2016
San Jose State University
The Csi Effect: Fact Or Fiction?, Kavita Alejo
Themis: Research Journal of Justice Studies and Forensic Science
The CSI effect has been a subject undergoing intense scrutiny in recent years. With the ever-increasing number of television shows, such as CSI and all of its spinoffs, that poorly represent the field of forensic science, there has also been a growing concern over the effects that media has on the legal system. Prosecutors argue that the CSI effect raises their burden of proof and makes jurors more likely to acquit in cases involving little or no forensic evidence, while defense lawyers claim that jurors are more inclined to wrongfully convict based on their unrealistic perceptions of forensic evidence. This …
