1 / 3100%
CJUS 363-D01
December 13, 2020
Hashing Files Project
A hash value is “an algorithm that turns a variable-sized amount of text into a fixed-sized
output” (Kumar, Sofat, Jain, & Aggarwal, 2012, p. 65). In simpler terms, a hash value is “a
unique hexadecimal value that identifies a file or drive” (Nelson, Phillips, & Steuart, 2016,
section 4-8). Hash values are used to create digital signatures of text for the purpose of
analyzation. The two most common hash algorithms are MD5 (Message Digest 5) and SHA-1
(Secure Hash Algorithm version 1). Salgado (2005) states that hash algorithms can confirm when
a copy of data is made, when the original is altered, and when the copy is identical. Forensic
examiners can also use hash values to ignore files and data that are irrelevant to an investigation,
while also identifying the files and data that are pertinent (Salgado, 2005).
The hashing program I used was MD5 (https:// www.md5hashgenerator.com/ ). It seemed
like the most “user friendly” hashing program. It was easy to use and pretty self-explanatory. I
also used it because it was the first hashing program mentioned in the textbook. According to
Nelson, Phillips, & Steuart (2016), forensic hashing has three rules: (1) the hash value of a file
or device cannot be predicted, (2) no two hash values are the same, and (3) a hash value changes
when there is the slightest change to a file or device (section 4-8). My original document read:
“I’m really excited to finish my undergrad degree next week. I hope we’re able to walk in May. I
have applied to several colleges for an online Master’s degree in Crime Scene Investigation.”
The resulting hash value was 6b078d3a06545e7c81289a7e3349ea59. I altered my original
document, which read: “I’m really excited to finish my undergrad degree next week. I hope
we’re able to walk in May. I have already been accepted to one university for an online Master’s
degree in Crime Scene Investigation.” The resulting hash value for the changed document was
11e1e7ed3e834ebba197f79fb4a8e0fc.
Hash algorithms are used in digital forensics to preserve digital evidence and to ensure
the integrity of that evidence (Schmitt & Jordan, 2013). Changing any part of digital evidence
results in a change in the hash value. This change causes a “cascade effect during the calculation
process which would produce a different hash value” (Schmitt & Jordan, 2013, p. 42). The
change in hash value shows that the file or data has changed from its original state. A hashing
algorithm results in two properties. The first property is that the hash value will be uniquely tied
to the input, and the second property is that a hash value works in one direction (Salgado, 2006,
pp. 39-40).
One of the most important pieces of a forensic investigation is data acquisition, which is
“the task of collecting digital evidence from electronic media” (Kumar et al., 2012, p. 64).
Forensically, an investigator should make multiple copies of the digital evidence that is collected.
This allows for the preservation of the original evidence and keeps the original evidence from
accidental destruction or alteration. In court, an investigator must explain and prove that the hash
values produced are an exact match to those found on the original files and data.
As a future investigator, it is my duty to uphold the law and to focus on my morals and
integrity. Much like hidden evidence is found by investigators, anything immoral I would be
tempted to participate in would be found out. Second Peter 1:5 (NLT) states, “In view of all this,
make every effort to respond to God’s promises. Supplement your faith with a generous
provision of moral excellence, and moral excellence with knowledge.” Above all, my job is to
honor God and walk in truth and integrity.
References
Kumar, K., Sofat, S., Jain, S. K., & Aggarwal, N. (2012). Significance of hash value generation
in digital forensics: A case study. International Journal of Engineering Research and
Development, 2(5), 64-70. Retrieved from http://citeseerx.ist.psu.edu/viewdoc/download?
doi=10.1.1.299.7223&rep=rep1&type=pdf
Nelson, B., Phillips, A., & Steuart, C. (2016). Guide to computer forensics and investigations:
Processing digital evidence. Boston: Cengage Learning.
New Living Translation Bible. (2015). BibleHub. https://biblehub.com/nlt/2_peter/1.htm
Salgado, R. P. (2005). Fourth Amendment and the power of the hash. Harvard Law Review
Forum, 119(38), 38-46. Retrieved from https://heinonline-
org.ezproxy.liberty.edu/HOL/Page?
collection=journals&handle=hein.journals/forharoc119&id=45&men_tab=srchresults
Schmitt, V., & Jordan, J. (2013). Establishing the validity of MD5 and Sha-1 hashing in digital
Forensic practice in light of recent research demonstrating cryptographic weaknesses
in these algorithms. International Journal of Computer Applications, 68(2), 40-43.
Retrieved from https://research.ijcaonline.org/volume68/number23/pxc3887433.pdf
Students also viewed