- Single Book
129
- 10.1016/c2013-0-09718-6
Cloud Storage Forensics
- Jan 01, 2014
- Darren Quick + 2 more +2
Cloud Storage Forensics
MFP (Multi-Function Peripheral) is an embedded system that serves several functions including printing, copying, scanning, faxing, document storing, and etc. Recently, MFP is becoming a popular option for office workers due to its multi-functionality and economic efficiency. Furthermore, MFP is able to perform several functions such as USB printing, private job printing, stored job printing, and scan-to-server. Due to the rapid growth of MFP market, MFP is widely used in many workspaces. Therefore, if we can extract meaningful information from MFP's storage devices, it may be valuable evidences in digital forensic investigation. However, systematic forensic investigation about MFP has never been studied so far. In this paper, we describe a process for digital forensic examination of MFP and analyze the acquired data and effectively trace the use of MFP in the crime scene.
Cloud Storage Forensics
Cloud Storage Forensics
Forensic analysis for AI speaker with display Echo Show [formula omitted] generation as a case study
Forensic analysis for AI speaker with display Echo Show [formula omitted] generation as a case study
Forensics examination of volatile system data using virtual introspection
While static examination of computer systems is an important part of many digital forensics investigations, there are often important system properties present only in volatile memory that cannot be effectively recovered using static analysis techniques, such as offline hard disk acquisition and analysis. An alternative approach, involving the live analysis of target systems to uncover this volatile data, presents significant risks and challenges to forensic investigators as observation techniques are generally intrusive and can affect the system being observed. This paper provides a discussion of live digital forensics analysis through virtual introspection and presents a suite of virtual introspection tools developed for Xen (VIX tools). The VIX tools suite can be used for unobtrusive digital forensic examination of volatile system data in virtual machines, and addresses a key research area identified in the virtualization in digital forensics research agenda [22].
Read moreA Systematic Review of Digital, Cloud and IoT Forensics
Our world is proliferated with high-end devices that have multiple capabilities. These devices have an array of sensors embedded into them that collect an enormous amount of data. Because of rapid development in technology, these devices are capable of rendering state-of-the-art services that are based on the cloud. Assuredly, the proliferation of ultra-modern devices with high-end services, have modernized and eased our lives. But, some entities or adversaries of our society are exploiting the same technological innovation for their benefits. Such criminal activities have become even easier to be carried out with modern devices and other technologies. Fortunately, we can examine the confiscated digital devices such as android smartphones, laptops, smartwatches, etc., from a crime scene and gain insight into the criminal activities carried out by the adversaries. It is also possible for us to recover the data the adversaries have collected or transmitted. Since modern devices utilize the services provided by cloud computing, it naturally becomes essential for the analysis of the cloud in case of the investigation of a crime scene. IoT forensics is interdisciplinary, as the data to be investigated may be collected from sensors, smart devices, etc., connected to a crime scene and the cloud too. Digital Forensics is an easier task to be performed when compared to Cloud Forensics. The segregation and collection of evidence in a cloud forensic investigation is a mammoth task due to the distributed and multi-tenant nature of cloud computing. But there is no such problem associated with digital forensic investigation. In this chapter, we have reviewed the work on Digital, Cloud and IoT Forensics by the scientific community. We have compared their effort and the outcome of their work, and summarized the state-of-the-art in the field of Digital, Cloud and IoT Forensics. Our aim of this chapter is to create a thorough review that will help fellow researchers in thought association for getting a clearer picture of the current state of research on Digital, Cloud and IoT Forensics and find the research gaps.
Read moreExploring Lack of Due Diligence as a Threat to Forensic Analysis Preparation and Readiness
The usage of digital technology in the digital forensic investigation has grown in tandem with the rising importance of technology today. Too many incidences of digital and physical crime which is the focus of the world nowadays. To gather the finest evidence and investigative outcomes, a digital forensic model must be established. This study included a review of the literature on digital forensics and models established in digital forensics. According to the findings, the majority of research involves broad inquiries and procedures that overlap. Furthermore, no model has been developed to design a systemic inquiry. In this study, we propose a methodology for digital forensic examination to address this issue. This model combines several of the previous models and adds some new variables that are relevant to the study. Keywords: Due Diligence, Threats, Forensic Analysis, Preparation, Readiness, Cyber Security, BOOK Chapter ǀ Research Nexus in IT, Law, Cyber Security & Forensics. Open Access. Distributed Free Citation: Jonas Takyi Asamoah (2022): Exploring Lack of Due Diligence as a Threat to Forensic Analysis Preparation and Readiness Book Chapter Series on Research Nexus in IT, Law, Cyber Security & Forensics. Pp 307-314 www.isteams.net/ITlawbookchapter2022. dx.doi.org/10.22624/AIMS/CRP-BK3-P49
Read moreTowards a framework for enhancing potential digital evidence presentation
In the case of digital forensic investigations, the potential digital evidence captured, the analysis, interpretation, and attribution must ultimately be presented in the form of expert reports, depositions, and testimony in any legal proceedings. If the presentation and interpretation of the potential digital evidence is conducted correctly, it is much easier and useful in apprehending the attacker and stands a much greater chance of being admissible in the event of a prosecution. Wrongly presented and interpreted potential digital evidence data might create loopholes for perpetrators to exploit, thus, making it hard to convict and prosecute them. Existing digital forensic investigation process models have provided guidelines for identifying and preserving potential digital evidence captured from a crime scene. However, the extent to which such potential digital evidence may be admissible in a court of law remains a challenge to investigators. This is backed up by the fact that there are currently no standardised guidelines for even presenting the most common representations of digital forensic evidence. Therefore, in the authors' opinion, methodologies and specifications need to be developed in the field of digital forensics with the ability to effectively enhance the potential digital evidence presentation and interpretation in any legal proceedings. In this paper, therefore, we present a step-by-step framework in an attempt to propose high-level guidelines for enhancing the potential digital evidence presentation in any legal proceedings. Such a framework will be helpful to digital forensic experts, for example, in structuring investigation findings as well as in identifying relevant patterns of events to be incorporated during the presentation of potential digital evidence. The framework will also assist law enforcement agencies, for example, to determine, with less effort, the validity, weight and admissibility of any potential digital evidence presented. However, it should be noted that the purpose of this paper is not to replace any of the extensive and known evidence presentation principles, but serves as a survey of the state of the art of the research area while proposing harmonised and high-level guidelines for enhancing the presentation of potential digital evidence in legal proceedings.
Read moreIntegrated digital forensic process model
Integrated digital forensic process model
RAM data significance in digital forensics
In present modern times when operating systems require larger amounts of RAM or Random Access Memory, we usually come across computers with 4 GB RAM, but given the price drops, it is quite usual to come across computers with 64 GB of RAM as well. By imaging this part of computer memory and by performing forensics analysis of the data located in RAM, it can be easily concluded that performing RAM imagining and analysis should be one of the essential steps in any forensic investigation. This paper will give a short introduction to digital forensics and the role of live data forensics. Furthermore, the mail goal will be to show and explain the importance of forensics of live machines and artefacts which can be found as well as methods and tools which are used for extracting and analyzing data from RAM. In addition, it will be shown that sometimes in forensic investigations, data contained in RAM can contain enough evidence to solve the whole case and actually be everything a digital forensics investigator really need.
Read moreDigital Forensic Tools
Digital forensics investigators have access to a wide variety of tools, both commercial and open source, which assist in the preservation and analysis of digital evidence. Unfortunately, most current digital forensics tools fall short in several ways. First, they are unable to cope with the ever-increasing storage capacity of target devices. As capacities grow into hundreds of gigabytes or terabytes, the traditional approach of utilizing a single workstation to perform a digital forensics investigation against a single evidence source, such as a hard drive, will become completely intractable. Further, huge targets will require more sophisticated analysis techniques, such as automated categorization of images. We believe that the next generation of digital forensics tools will employ high-performance computing, more sophisticated evidence discovery and analysis techniques, and better collaborative functions to allow digital forensics investigators to perform investigations much more efficiently than they do today. This chapter examines the next generation of digital forensics tools.
Read moreAwareness of Problems and Defies with Big Data Involved in Network Security Management with Revised Data Fusion-Based Digital Investigation Model
The budding progress and relevance of digital information technology in quite a few areas of business, engineering, medical, agricultural and scientific studies are resulting in data explosion coined by the term “big data”. The dependency on digital media drives and devices has enlarged the dimensions of data formation and storage exponentially around the world, with a need of keeping a record of what data is accumulated and how the data is exercised. So it has raised an alarm of security for the data asset. To discover the pattern of interest leading to a decision from these voluminous data has put forth a challenge for the law enforcement and investigative agencies. Also, tracing such type of misutilization of digital technology in a big data age from the perspective of digital forensics requires minute bit-level examination and observations to locate the digital evidence that explains how maliciously nefarious activities have been done and by whom with the possible extent of the damage. The forensic examination and analysis in such a big data era requires appropriate digital investigation model with the application of tools, techniques and methodologies to boost decision-making and diagnostic process for advanced outfitted competence in digital forensic investigation with the intent of assembling valuable evidence from it. So, the need of the hour is to have a holistic outlook of the big data challenges and opportunities for its application in the digital forensic domain with the goal of making full-bodied investigation pronouncements. Much work has been done to model digital investigation as well as digital evidence but a comprehensive correlated and aggregated merging of voluminous data coming from different heterogeneous sources along with timely and accurate detection and analysis is the need of the hour. This chapter depicts the trends of digital forensics served for big data and the challenges of evidence acquisition, and further suggests the revision of the existing fusion-based digital investigation model by highlighting the formalization, quick detection and timely accurate analysis of digital evidence from multiple sources simultaneously. The modification adopted the inclusion of look-up table into the architecture with the application of data fusion to practice voluminous data effectually.
Read moreAn Enhanced Blockchain-Based IoT Digital Forensics Architecture Using Fuzzy Hash
Due to businesses’ growing use of IoT services in their day-to-day operations and the increased use of smart devices, digital forensic investigations involving such systems will need increasingly sophisticated digital evidence collection and processing. The majority of IoT systems are composed of disparate software and hardware components, which may pose security and privacy concerns. Recently, blockchain technology was presented as one of the options for achieving IoT security via the use of an immutable ledger, a decentralized architecture, and strong cryptographic primitives. Integrating blockchain platforms with IoT-based applications, on the other hand, poses a number of difficulties owing to the trustworthiness, integrity, and real-time responsiveness of IoT data. However, certain IoT devices may be incompatible with existing blockchain-based IoT forensic methods for additional digital evidence processing owing to their usage of conventional hash. A critical feature of cryptographic hash functions is that even if just one bit of the input is altered, the output acts pseudo-randomly, making it impossible to identify identical files. However, in the field of computer forensics, it is essential to locate comparable files (e.g., various versions of a file); therefore, we need a hash function that preserves similarity. It is getting more difficult to establish how forensic investigators might utilize traces from such devices. To effectively deal with IoT digital forensics applications, this article presents an improved blockchain-based IoT digital forensics architecture that uses the fuzzy hash to construct the Blockchain’s Merkle tree in addition to the conventional hash for authentication. Fuzzy hashing enables the identification of potentially damning documents that might otherwise remain undiscovered using conventional hashing techniques. By comparing blocks/files to all nodes in the blockchain network using fuzzy hash similarity, the digital forensics investigator will be able to verify their authenticity. To support the proof of concept, we simulated the suggested model.
Read moreDesign of expert system for tool selection in digital forensics investigation
Along with the diverse types of electronic goods and digital evidence, techniques have also developed in conducting digital forensic investigations. Another effect is the increase in types and types of tools for conducting digital forensic investigations. The problem is the increasing number of digital forensic tools is not always developed in conjunction with the manual book. So this is what makes the investigator to check the tool to make it suitable for investigations. Choosing the right tool is very important in the investigation process, because each stage of the forensic investigation process has a different treatment for each of its staging. Seeing these conditions, then in this paper we make a system design to facilitate investigators in choosing the right digital forensic tool and in accordance with using an expert system. The design system shows that it’s still needed to confirm to an expert to get a match output if there is a new rule. Later this system will be implemented with website technology.
Read moreA Framework to Guide the Implementation of Proactive Digital Forensics in Organisations
Most organizations underestimate the demand for digital evidence [1]. Often, when evidence is required to prove fraudulent transactions, not enough or trustworthy evidence is available to link the attacker to the incident. It is essential for organizations to prepare themselves for digital Forensic (DF) investigations and ensure that entire organizational operating environment is prepared for example for an investigation (criminal or internal) or acompliance tests. The accepted literature on DF readiness concentrates mainly on evidence identification, handling and storage, first line incident response and training requirements [2]. It does not consider the proactive application of DF tools to enhance the corporate governance structures (specifically Information Technology (IT) governance). Pro-active DF (ProDF) as defined in this paper will enable an organization to take the initiative by implementing adequate measures to become DF ready,demonstrate due diligence for good corporate Governance, specifically IT Governance and provide a mechanism to assess and improve IT Governance frameworks. The purpose of this paper is to define, identify goals, steps, and deliverables of ProDF, identify dimensions of DF, and propose a theoretical DF management framework to guidethe implementation of ProDF in an organization.
Read moreExt4
The Ext4 file system is often used by Android cell phones and by Linux distributions. As a mobile forensic expert, it is necessary to understand the structures of this file system to recover data, verify tool results, and detect anti-forensics techniques that may be present in the file system. In this chapter, we will have a deep dive into topics important for an investigation. Many digital forensic tools do not recover much from the Ext4 file system [52], and therefore we show some of the most useful Ext4 recovery techniques proposed by current research.The Ext4 file system is often used by Android1 operating systems, and also by Linux desktop distributions [14], and this file system is open source. The Ext4 file system replaces the Ext2 and Ext3, but it is mostly backwards compatible. Carrier described Ext2 and Ext3 in his File System forensic analysis book [10], which includes information also relevant for Ext4. Fairbanks describes the Ext4 file system at a low level and from a Digital Forensics perspective. This chapter will describe file system information important for mobile forensic investigators and other digital forensic experts.
Read moreArtificial Intelligence from the perspective of Digital Forensics
Abstract: With the evolution of man, technology has also evolved day by day, man has started relying upon the technologies, thus easing his burdens up. According to reports, it is expected that by 2020, 80% of adults on earth will have a smart phone on an average there has been a growth of 936%from 2000-2017 in the total population connected to internet. These figures are quite good on the part of technological progress, but at the same time pose a great threat to security issues for data on internet. The increasing rate of cyber crimes in past years is a threat to the data preserved via internet. This is the need of the hour to put a check on the rate with which cyber crimes have been increasing. A check point in this regard is the lack of highly automated tools and equally less number of forensic investigators. Thus the need of time is the possibility of such an intelligent frame work, which can share the burden of forensic cyber crime or digital forensics investigators.
Read more