CJUS 363
Module 6_ Forensics Lab
Charles Dickens
Welcome back. Today I want to take a little bit of time and talk through basic case
studies and give you an idea what the sum of the sum of forensic cases sort of
amount to. There’s two ideas today that I'm going to address. One, I'm going to talk
a little bit about the emergence of some of the new digital devices that are coming
out and some of the activities associated with and then I want to take a few minutes
and then talk with you about the specifics of case studies and what those things
would look like in terms of a running through the actual documentation that would
have to be created the support a different type of case.
There is as we standing here today emergence of all kinds of technologies in the
changes every day. Within the last 2 months the next version of the iPhone actually
popped out onto the market and we have really a new capability, new level
transaction, that's occurring within the internet.
The things that we call the iCloud is basically moving a lot of the data that we have
off of our devices and moving it into a space that is readily available to I'm basically
a trusted public area. and over the course of the last several years and as many of
you been growing up and having realized some of the first computers I worked with
actually worried that driven by little basically 3 by 8 cards that were basically a full
of punched holes and would run through a computer in series to basically he get it
to be able to do certain things had a tape devices that were very small micro
cassette tapes it basically had computer languages that were communicating.
Analog on audibly basically between each other loud basic computer to get a
program loaded into it. And then we've come a long ways now into its digits just
fly across the network through the air waves through every means by which is
available to be used.
The challenges is as you were running to an investigation that the simplicity of just
go grabbing the computer isn't all that there is about in terms of capturing the
essence of the digital environment but the people working in. And as you walk into a
crime scene investigation scene you're going to find yourself having a house where
is all the potential that digital media that exist within a particular scene and as you
think about that in today's environment we have digital applications running on
several of our digital recording devices, DVRs. You've got a TiVo is an example of
War you've got the other applications that allow you basically to set and forget walk
away and allow the recordings to occur in those recordings can contain different
types of information which would include timing, when things were actually done and
include the content that could be part of a suspect investigation.
So as you look through this you know part of why I need to talk it is the small scale
digital devices. We’ve got to start thinking about that all the different things that
can exist inside of a particular environment and starts with the devices and you
really need checklist to walk into the start these types of process but the devices
that exists inside of it a telephone. The devices that stood inside of a cell phone.
The devices that sit inside of cameras. small memory chips that basically are
purchased and acquired and in many cases can be stored in numerous places all
reflect basically some of the digital history that round particular case and as you
start developing the warrants to go in and be able to seize these specific digital
information these are types of things that you would want to make sure you
reference.
Beyond just the typical things that we think of the number to digital devices are
emerging as well that are represented with the gaming industry. and so in in
today's environment you've got the number different systems that are basically
connected directly into the internet and entire profiles in personal histories are built
inside of those things as long and in many cases can offer storage and or ability to
retrieve or contain specific information that may be relevant to an investigation and
these types of transactions that even in some cases can form mail messages, text
messages, all become part of this vast volume of collection.
The challenge of the investigators realizing it and there is so much information as
how do you say how do you how do you get it down to something that's
manageable. and really that comes from an initial analysis and identification of
what are the keywords that you're going to have a search and find segmenting the
types of information are all that are contained when they each one of the devices
identifying whether it's been encrypted or not been encrypted and then being able
to start working towards extraction. So there aren't any set rules yet and dealing
with all the different small-scale devices that are out there. it's recognized it as a
problem because rather than just having what we knew is physical bookcases and
like that to sort through now we have virtual book cases which are and vastly bigger
volume wise in terms of the amount of data the amount of information that has to
be processed but we do have automated tools that help us to get to them. So I just
want to emphasize that the small-scale devices is a particular problem that's
emerging in the midst of all the activities for investigators as a look at conducting
these investigations.
I need to take a couple of minutes and talk about a case study. and I think this is
important that kind of helps set the context of how things are conducted throughout
Brits book there's an emphasis on documentation, documentation, documentation
and one of your key roles is that document or building processes that help you
basically: one, establish standards and procedures that are repeatable. you got to
be able to extract information out of a qualified set of information, a extracted copy,
exact copy of the target files and be able then to manipulated a number different
ways to do you have to repeat it have the same results come out or else it becomes
suspect.
As you read through a Brits book, there's always the problem that gets into the
trust of the understanding of what is really digital. How can you prove that this
particular person did this particular activity? and it becomes with that the context of
multiple layers of content 1 attributes of the individual attributes to the Internet
Protocol IP address of the computer, attributes to the person’s email address, use
and frequency, type of use all these become very important part of building that
investigation.
So if you were asked to conduct an investigation I'm going to give you a couple
things here just to kind of run-down is sort of a checklist that. You know it starts the
process of looking at sequentially how you go through in and conduct these
investigations and every one of our automated capabilities there's typically a
system clock and so the first things that we always want to do is basically annotate
the time hack and determine if there's any discrepancy in the time that is
registered within the computer or the operating system or the network to that
which it is being looked at a real-time. The Second Step, the second thing that you
must do is just write protect basically the disorder the computer to prevent any
additional information from being written on it that would either corrupt the files
and or change the conditions and make the file attributes suspect.
A physical examination of all of the devices of which you're concerned with whether
it’s a disc to a computer system is make making sure that his head contains all the
parts and components is
not missing anything readily, really that's apparent on terms of maybe the drive has
been removed or there's a portion of the cases is missing these were all out for
Naturals and whether there are scratches or some form of other type of damage that
has been done on that could disrupt the type of information and be able to strike
down.
There the very next thing that you you're going to do when you have to retain this
is start the chain of custody. so is as you pick up the particular item you want
identify where it came from, who else has been involved with who else has touched
it in between that and the time for the time of the target of the investigation had
had some form of access.
There's a process we call basically a hash or check sum within the process of
conducting an assessment of Digital Data and in this this hash sequence is basically
a procedure you run checks on but basically runs a total number count of all the
different pieces of data digitally there within a particular file. And there is no way
that actually have that be repeated unless you have exactly the same information
within another file. So the checksum become sort of in authority to say that this
information here's exactly is this information is it is here. And it doesn't matter
where this encrypted or otherwise because the balance of all the doll the date of
this being represented will be exactly the same in file one to file two. It is part of the
process of computers built in and providing pure and clean copies. So that you
would want to basically establish what that checksum value is on all the digital
media that you have access to and basically then use that and register those
numbers so that it becomes the hash mark that you're looking for and every other
transaction.
Now you're going to need to create copies and so in order to create copies and
many times we used to say a means by which most effectively we can use because
of the size of most of the disk drives and hard disc space it's ever so on we have to
basically do a clean swipe of the previous device. On any computer devices there is
an ability to have some resident information from previous transactions still reside
even though you said you said delete everything that's how investigators actually
do retrieve information on computers and so to get a clean swipe call the disc
basically there's a at an application use and it basically run writes zeros to every
single sector within a disk and then writes ones over and zeros and then ones and
basically flushes everything in that out of that disc that could have ever been there
in the past and so you'll do me no residual information and allow basically a clean
copy to be resident within from one to the other.
So as you move through this then the process of conducting all the various types of
an analysis against the those files and there's several tools that we've and I'll talk
about them in next week's session some of the tools that are associated with digital
forensics but the schools that would be using you'd procedurally and sequentially
walkthrough each one of those files using these tools looking for specific
characteristics. part of your process is documenting what is it you're looking for
what are the conditions that would show that it would show itself as a as a signature
on that particular file and then as you step through each one of those instances of
reviewing the file annotating when and where those particular items have been
registered in allowing basically they get back and put some more deliberate time
into it.
You've got to be disciplined and sequencing yourself through this process what can
happen is you can't get drawn-in or distracted as something pops up much like an
advertisement saying oh there's something there you should just registered
continue to the remainder of your process of review and Analysis and then come
back and procedurally step into that next level view.
Again, I want to emphasize that the documentation throughout the process is
absolutely
essential and the record and transaction by transaction record is imperative to
ensuring that you get to the point that you are able to them to develop the case.
As you basically work through the remainder of these activities you're going to find
that you have come to a point in you have to start making some assumptions and
some analysis and basically coming to a point of making recommendations that
you compile the data you're going to be able to demonstrate how many type files
of one certain characteristic are represented or if they're not and be able to provide
the evidence and extraction out of the specific files that are oriented to the specific
subject of the investigation. Remember that as you move through this and must
stay focused and within the scope of the warrant you cannot just your freelance go
through the particular files if you find something suspect in another direction again
you'll have to go back patient if it would be allowed by the courts stay focused on
the scope of your current investigation work through the issues be disciplined and
ensure you document your process.
Procedurally work through each one of the ends instances make sure you write it
out before you start don't generate it as you go because it will not be consistent
and again I'm sure that it's repeatable and every single sense as you move through
it. So this is just a quick an introduction to do a case study and gives you kind of a
broad overview of some of the things that you would be involved in did the
application that will come for you is as you step forward it as a computer or cyber
forensics expert or investigator that disciplining yourself through process and
documentation and a staying true to the to the scope of the effort will result a
quality and a qualified examination on your part that will support a prosecutor,
investigator or defense. If you're part of a court proceeding and thank you
appreciate your time look forward to seeing you next week.