Lecture 9 - Digital Forensics Basics Flashcards

1
Q

What is digital forensics?

A

A digital investingation that focuses on digital devices e.g. laptops , mobile phones. It is a process where hypothesis are developed and tested to answer questions about digital events. Within the process we acquire and go through (analyse) data found in digital devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the goals of digital forensics?

A
  • prevention of further intrusion on digital device (s) - make sure the event doesn’t happen again
  • assess the damage on the system - can it be used safely again
  • recontruct the timeline of incident (s) , typically to prosecute criminals and for interal organizational proceedings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What kind of events are analysed with digital forensics?

A
  • computer intrusion
  • generic criminal activity (e.g. using the device to look up information used in later crime -> crime doesn’t have to be digital, but related to information used)
  • device as a direct instrument of crime e.g. using phone to set off a bomb, email scam , fraud , intrusion on other systems
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Our hypothesis for digital forensics has to be backed up with …

A

evidence found from the process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When doing digital forensics what to do we need to follow?

A

The procedural (how we come up with evidence) and legal notion (defined by rules of evidence , differs by legislation)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can hear say be used as evidence?

A

No, it is procedurally evidence, but cannot be used as legal evidence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the 4 types of digital forensics?

A
  • computer forensics
  • network forensics
  • mobile forensics
  • forensic data analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is computer forensics?

A

is the procedure of acquiring
a snapshot of the internal state of a computer system (cloning the hard drive/memory) and moving on in analysing the acquired copy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

When are forensics procedures normally applied?

A

Most of the time these practices are used in digital crime investigations and the goal is to lead into successful prosecution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is network forensics?

A

is focusing on the communication aspect of the device and it
captures the traffic as data for further analysis -> helps in intrusion detection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is mobile forensics?

A

Mobile Forensics is representing practices employed for recovering data from a mobile device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is forensic data analysis?

A

another branch which
focuses on structured data analysis relevant to financial crimes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who should be aware of digital forensics (practices , evidence , notions etc. )?

A
  • Those involved in the legal proceedings that might use the digital evidence -> judges , prosecutors etc.
  • those involved in system administration e.g. system admins , network admins , security officers
  • those writing system procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why is digital forensics important?

A
  • to be able to recover data
  • to be able to discover malicious activies and hence prosecute criminals
How well did you know this?
1
Not at all
2
3
4
5
Perfectly