Chpt 19 Flashcards
3 Requirements for evidence to be admissible
Must be 1) relevant, 2) material (related) to the case, and 3) competent (obtained legally)
SP 800-86
NIST guide to integrating forensic techniques into incident response
4 major categories of evidence
Real, documentary, testimonial, and demonstrative
Rules applied to documentary evidence
Best evidence - original copies are needed
Parol evidence - written agreements are assumed to contain all the terms of the agreement and no verbal agreements may modify the written agreement
write blocker
hardware adapter used to prevent alteration to storage devices during media analysis
memory dump
a file of memory of live systems used for in-memory analysis
ways to collect network traffic for an investigation
SPAN port on a switch, network tap hardware device, or software protocol analyzer on one of the communicating systems (less reliable)
an FBI-led consortium of forensic analysts who produce detailed guidance on gathering digital evidence
The Scientific Working Group on Digital Evidence
RFC 1087
“Ethics and the Internet,” created by the Internet Architecture Board (IAB), describes unacceptable and unethics activity:
- seeks to gain unauthorized access
- disrupts the intended use of the internet
- wasted resources
- destroys the integrity of computer-based info
- compromised the privacy of users
6 types of computer crimes
military and intelligence, business, financial, terrorist, grudge, thrill