3 - Digital Investigation Process Flashcards
Kruse & Heiser
Assessment
Acquisition
Analysis
Reporting
Assessment
Short: prepare plan of action and find potential sources of evidence
Define the scope and likely venue of examination
Collect legal documentation needed
Determine sources of evidence
Acquisition
All issues of legal search & seizure are followed, integrity was preserved, evidence is authentic and as complete as possible
Issues with chain of custody
incomplete
inconsistent dates
custodian is not competent or authorized
Checksum/One-way hash/Digital signature
Checksum and hash easy to compute
Checksum fast but low assurance
Hash does not bind but is more secure
Digital binds and secures more but more slow and must protect key
Analysis
Extract all material evidence, inculpatory and exculpatory
Types of evidence
Overt
Hidden
Deleted
Anti-forensic
Forms of offense reconstitution
Temporal
Relational
Functional
Reporting
General Case documentation Procedural documentation Process documentation Case timeline Evidence chain of custody
Casey 2001
Identification/assessment Collection/Acquisition Preservation Examination Analysis Reporting
Limitations of models
Complexity
Rigidness
Incompleteness
Scientific method
Simple, flexible, methodological
Steps: observation, hypothesis, testing, conclusions