Review and reflect on the knowledge you have gained from this course. Based on your review and reflection, write at least 3 paragraphs on the following:
Running head: DIGITAL FORENSICS 1
DIGITAL FORENSICS 5
Digital Forensics Theory
Name
Course
Tutor
Date
Digital Forensics Theory
What is the meaning of digital forensics theory and its intended application during the digital forensics investigation?
Digital forensics is that branch or aspect of forensic science whose concern is the recovery of materials I digital materials to aid investigations. In many cases where investigators are handling a case where they would have to look at digital materials, and they would have to obtain some data from the materials, it is more likely than not that they would have to invite the assistance of specialists of digital forensics. Thus, digital forensics theory refers to the processes, procedures, and laws that are used in digital forensic investigations (Holt et al., 2015). It is important to note that digital forensics is not a simple undertaking. Because the findings of digital forensics are supposed to be used in legal proceedings, it is incumbent upon the leaders in this field to make sure that they act in accordance with all the laws regarding the practice. Thus, the primary role of digital forensics theory is to make sure that the digital forensics investigators work within the law in practice.
As indicated above, the theory of digital forensics plays an important role in making sure that the practice not only adheres to the law but also maintain a specific order and adherence to the law. Before gaining access to digital material and seeking to retrieve data or evidence from it, there are legal provisions that must be satisfied. There are many instances where courts of law have rejected evidence because it was obtained irregularly. The theory of digital forensics covers these legal provisions, and that means it will be immensely useful to digital forensic experts.
What are the processes used by digital forensics investigators to identify threats and root causes of attacks against networks and systems?
When there are attacks on networks and computer systems, it is the responsibility of digital forensic experts to investigate the attacks and come up with mechanisms and approaches that they may use to prevent future attacks. When investigators are investigating such attacks, there are approaches and protocols that they follow. The following is an analysis of the steps that these professionals follow in the process according to Davidoff and Ham (2012);
Identification
This involves identifying and classifying the attack based on the indicators that are generated from the network indicators.
Preservation
Obtain physicals and digital evidence and keep them safe so that they may not be lost, tampered with, or altered in any manner.
Collection
Appling standard tools and methods to gain access to and create duplicates of the digital data on preparation for analysis
Examination
Carry out an in-depth search for any piece of evidence that may be related to the attack from the pieces of materials that were collected
Analysis
Analyze the evidence collected and obtain as much information as possible with regard to the attack, and make conclusions about the nature of the attack and any other relevant information.
Presentation
Present the findings of the investigations to the relevant authorities for appropriate action.
How can digital forensics produce evidence to determine what resources have been affected by the threat?
Digital forensics is capable of giving information on the resources that have been affected by a threat to networks and systems. It is important to note that digital forensics is capable of making it possible for investigators to understand the nature of attacks and the sources, in addition to the resources that have been affected. Even without going into the details concerning the parts of the computer systems, to understand the potential areas of interest of the attackers. Additionally, from the vulnerability test, it is possible to understand the resources that might have been vulnerable.
References
Davidoff, S., & Ham, J. (2012). Network forensics: tracking hackers through cyberspace (Vol. 2014). Upper Saddle River: Prentice Hall.
Holt, T. J., Bossler, A. M., & Seigfried-Spellar, K. C. (2015). Cybercrime and digital forensics: An introduction. Routledge.