CJUS 363
Module 2_Computer and Digital Communications Overview
Charles Dickens
Hello. I’d like to welcome you back. This second session that we're going to have together is
going to be focused on a little bit about the networking and computers and technology. So
I'm going to transition for a little bit into the technical aspects of what goes on with
computers because it's so important for you to understand how computers work. I'm not
going to be able to do that in a few minutes with you here this morning, but I want to get you
kind of started. I want to give some important concepts.
As you can see, we're standing in the capital. It’s the center of the United States, in an essence,
of where governance and legislative actions are happening. It is a centerpiece for where our
laws are driven from and run, the whole electoral process is built around. And just up the street
to your left is what we call Union Station and it's still the hub for all the infrastructure that
comes into Washington DC, bringing trains and Metro and buses and taxis and thousands upon
thousands of folks, people, transition through that facility on a daily basis. Both morning and
evening, getting to and from work and coming right down here to Washington DC and this
capital area. That infrastructure is very similar to the same infrastructure that exists within
computer systems.
The course we’re in is in computer and cyber forensics so I want to make sure that we don't get
myopically focused down into looking at computers only because computers are only part of
the concern. When you as an investigator are asked to step in and look at what's going on with
one system to another against the suspect, you have to have an appreciation of all the different
things that come into play with that particular digital capability. Just think back about your
dorm room right now or your home. You probably have a computer that's got a floppy drive,
well maybe not floppy anymore, but CDs, DVDs, thumb drives. You probably have stacks of
DVDs and CDs sitting in different places. You probably have recorded media inside of your
house for a number of different things. You have probably a phone of some form, whether
digital or the old analog, but they have smart chips inside of them. The smart chips are also
used inside of cameras. So a home or room is filled with all kinds of electronic media. Every one
of those are part of the digital evidence and package that we as investigators have to step in
and look and try to analyze. But in order to get there, we have to have an appreciation for what
a computer is built upon.
Computers have been around for, you know if you go back to the Abacus, thousands upon
thousands of years, right? But when we're talking about the electronic computer, roughly
about 75 years. We've had different types of computers, starting with what were really tube
driven. A computer is built off of a very simple concept of a yes/no answer, you know.
Something is on or it's off. So from that very simple concept, you can then start putting
combinations of on/off to then create code that then is used to represent words or functions
or applications or capabilities that are used within a computer system.
Today when we look at our computer systems, we just see a box. Most of us are wireless and so
you walk into Starbucks with your laptop and you make the connection. But those connections
that are being made are being made by different ports and protocols. Those ports and protocols
are built off standards that were established underneath several different venues, some of
them international, some of them are American, North American. The international standards
organization based out of here in DC as well is involved intimately in establishing these types of
standards to be used with the computer systems. What became very important though,
particularly when the internet started being realized, the ability to communicate from
computer to computer, is we had to establish standards of communication. So multiple means
and businesses of course moved out into designing different ways of configuring systems and
networks to be able to enable communications.
So your basic computer today when you connect to a wireless device that is sitting inside of
Starbucks is still touching a lot of different systems along the way. It is piping information to
that wireless router. It is piping information through bridges and routers back and forth
between resident addresses. The URL is what we see when we type into a browser, but it
actually is working off of something underlying that which is an IP address. That IP address is
part of those standards. So if you ever heard somebody talk about resetting a router or putting
an IP address on a computer or when you’ve talked to a help desk technician who wants to
know your IP address, these are all things that help them to identify specifically which
computer and which device is communicating between one to the other.
Now, this is built off of something called the open systems interconnect model, OSI model. It’s
a 7 layer model and most of our communications platforms internationally have been designed
around this. I wanted to spend a few minutes talking about that because I know you should be
reading more about the technical capabilities that reside with specific computers and operating
systems. So the OSI model was built off of really trying to identify layers at which
communication takes place. The most basic layer is called the physical layer, so everything
that’s physical. Your laptop, your phone, those are physical devices that have to have stuff
installed on
them, software, to be able to make them operate and communicate. But that is the starting
point by which communications will be initiated.
It then moves up into the network and the network layer then allows basically establishing the
connection between the computer to the network. In every case, you're going to end up getting
additional information added onto what is trying to be communicated, help establish the path
so that information transits away from your computer to desired computer or server and then
returns back along a similar path. It doesn’t always come back on the same path, but it's a
similar path because it’s only focused at identifying and finding the address. It looks for the
path of least resistance to get there.
Ultimately, when the OSI model is put in place, the top layers of things that you see most
frequently are what are called the presentation and applications layer. The presentation layer
is basically where the information is being presented to you and it's everything that you see
within your screen. The application is what’s residing in the background that is running on the
computer itself or through the internet to your phone, to your laptop, that is basically giving
you new information. It’s much like a ticker-tape. If you’ve seen a ticker-tape or you see the
comment strips on the bottom of one of the news channels as it rolls by and information
continues to pass, there's an application in the background running that's making that show at
the presentation layer.
When we start talking about the investigation that needs to take place, you need to look and
consider from these different activities within the OSI 7 layer model that give us the ability to
lay out where different components will reside from the investigative perspective. Is it physical
evidence? Is it network evidence? Is it application or software evidence? All these elements
become important in helping you to catalog and document the process. Later on through the
course of reading, you’ll start getting and picking up hints of one of the most important things
an investigator can do, which is document, document, document. Why is that? It's because
we've got so many different details that have to be identified. You’ve seen crime shows. People
come in and they document where things are, what position and how was it laid. Pictures tell a
thousand words. Well, that same type of documentation has to take place with the digital
evidence.
The challenge is the computer is harder to define. Through your course of reading you're going
to discover that there's a challenge from the perspective of presentation to a jury or to
somebody else of what's real and what's not real within the computer world. If you bring
evidence forward saying that this was resident within somebody's computer, they're going to
challenge the chain-of-custody. They're going to challenge the validity of that information and
they're going to challenge almost every stead of your presentation, your investigation, unless
you have the documentation showing here's a copy of the original file, I never touched it. I now
have the copy by which I have now parsed the codes out. Here is what the evidence is that’s
being presented based off of my research, my reviews, my applications as I run through each
and every one of the scenarios to help determine whether or not this evidence is relevant to
the case and whether it is supportive to the defendant or supportive towards a prosecutor or
prosecution approach.
I encourage you to spend some time understanding the technical components. I just touched on
four of the basic areas out of the seven-layer OSI model, just with respect of time. But as you
continue to pursue this digital forensics career, as we look and continue through this course, I
need you to understand that the fundamental technical components, your understanding and
your appreciation of those, are really an important element in helping you to put together a
relevant case for either the prosecution or the defense.