Identify two current challenges for Digital Forensic investigators dealing with the
Cloud. How is the field of DF currently tackling these challenges? As a forensics
investigator, what plan of action would you recommend to a bank considering cloud
storage?
Answer
Digital forensics investigators rely majorly on two types of evidence which are digital and physical
evidence. Physical evidence is that evidence that can be brought to court as evidence while digital
evidence involves data that is collected from physical evidence. However digital forensic investigators
have found challenges in collecting the two types of evidence as a result of Police and Justice act 2006
that prohibits unauthorized access t computer material. This means that an investigator too could be taken
to court for trespass when seeking evidence. The field of DF has continued to champion for the use of
chain of custody by investigators while giving evidence on their investigations since it authenticates
available evidence. I would suggest that a bank planning to use cloud for storage to consider a private
cloud. A private cloud provides an infrastructure that can be operated by solely by the bank meaning that
it will be within its administrative control and only include data related to the organization.
What is the Frye standard? How does this standard effect Digital Forensic
investigations? Discuss one alternative technique.
Frye Standard also referred to as general acceptance test is applied in digital forensics to determine the
admissibility of scientific evidence that is gathered. It enables an expert to offer an opinion that is based
on a particular scientific technique that is considered reliable in computer forensics. Frye Standards work
to ensure that the evidence that is offered by investigators can easily be quantified. This is based on the
facts that zeroes and ones do not lie. The particular standard ensures that digital and physical evidence
relies more on evidence that can be articulated. An alternative technique to Frye standards is the Daubert
standard that judges use to give a ruling on available evidence regarding digital forensics.It gives guides
on admissibility of scientific evidence. This particular standard is favored in most jurisdictions over the
Frye Standard since it offers clear guideline for quantifying expert witness.
How can digital images be validated and preserved? Compare and contrast 3
examples.
Forensic investigators can use drive imaging, hash values and chain of custody to validate and digital
images. Drive imaging involves an analyst creating a bit for bit duplicate of a drive in order to retain
evidence. Hash values are gotten after a machine is imaged creating cryptography hash values. Its main is
to quantify the authenticity and integrity of the image and whether it is a duplicate of the original image.
Chain of custody applies paperwork to acknowledge that available image has been under a recognized
possession since its creation. Drive imaging is quite involving as it involves digging ino available drives
and those files that may have been wiped. Unlike Hash values it involves the original generation of
evidence. The three methods are necessary in the event of ensuring that images offered as evidence are
admissible.
What is meant by ‘authentication of evidence’ and why is this important? How can a
Digital Forensics investigator authenticate evidence presented in a court of law?
Authentication of evidence is a rule attached to evidence that requires evidence to be sufficient to back up
a finding that the matter of concern is what its proponents claim. Authenticity calls for ensuring that
evidence is genuine before it is considered admissible. Authenticity important since it ensure that only
genuine information is admissible in court. Secondly it calls for an expert in computer forensics to admit
that the information before court is true through a testimony. A digital forensic investigator can be called
by a court of law to offer an expert opinion on digital evidence before court. After investigation then an
investigator will give a reason why the information before court is either genuine or not genuine hence
authenticating it.
Identify an dependencies among the steps, as in which steps must be started and/or
completed prior to the next step.
Summarize the TJX/Heartland and Iceman cases. What lessons were learned and what
importance do each of these cases play on the field of Digital Forensics?
TJX case summary
It was not until November 2005 that Fidelity Homestead noted suspicious charges in their customer’s
credit cards mainly those based in California and Mexico. After audit a year later it was found that those
charges were associated with credit card data held by computer systems belonging to TJX companies.
After investigation it was found that hackers had penetrated in TJX systems in Mid 2005 accessing
information .TJX had failed to update its in store wireless network thus breaching security standards .In
2007 the company admitted that its system had be compromised by hackers with more than 46 million
debit cards affected something that came to be the largest data breach in the United States.
Iceman cases summary
What is a time stamping aid, and how can it be used to establish integrity to an
investigation? Provide one example from literature of where time stamping was used
in court to validate evidence.
A time stamping aid is time printed on a file to track when data is removed, added, received and send.
Time stamping aids in providing real time log files and shows how they were executed by someone trying
to compromise a system. It offers the actual timelines through which a crime under investigation was
carried out and the purported time that it was discovered. In the TJX case time stamping was used in court
to provide evidence. Through reviewing the hackers log files it was possible for forensic investigator to
appropriately apply timestamps to record the moment that hackers gain information to the companies
system and gained access to customer’s credit card information.
Describe the AccessData FTK Imager tool. In addition to creating an image, how can
this tool be used to retrieve, disseminate, and validate data as potential evidence in an
investigation?
Access Data FTK imager is a forensic tool that is applied to preview recoverable information from disks.
It creates forensic images which are perfect copies of the data under investigations.Despite being used by
investigators as a preview tool and imager the tool has several capabilities that can assist investigators in
examining digital devices. Access Data FTK can be used to retrieve, disseminate and validate data as
potential evidence in an investigation in the first step of forensic digital examinations. The tool facilitates
the creation of precise duplicate duplicates of storage disks that hold evidence. Thus it reduces the risks of
an investigator altering with the information being collected and makes it as complete as possible.
What are the challenges when conducting data acquisition from a network? Give 3
examples and at least one common tool used to combat the challenge.
The fact that investigators cannot operate device drivers from networks is a challenge in acquiring data
from the networks. Trying to operate communication networks from device drivers would mess up the
system and make it hard to recover. When utilizing manual acquisition of data for instance only the data
that is visible in the operating system can be recovered. On top of that the process is time consuming and
can delay investigations. At sometimes investigators may be forced to use logical extraction which does
produce any information that was deleted unless the network houses a database. Xplico is one of the tools
that can be used to combat the above mentioned challenges being an open network forensic analysis tool
that extracts vital data from application that use network and internet protocols.
What are the legal and ethical issues associated with a Digital Forensic investigation?
Give at least 2 examples of each, and explain the difference between legal and ethical
issues from a forensic viewpoint.
Legal issues
The two legal issues of interest in computer forensics are preservation of evidence and evidence
admissibility. Forensic evidence should be reserved in a duplicate form to reduce the risk of change. On
the other hand information that is presented to the court should have been acknowledged by an expert
through an opinion.
Ethical issues
The major ethical issues in digital forensics investigations are honesty and prudence. pert in the field
come across vital information that they are entrusted with and need not to leak it. Prudence on the other
hand is essential in ensuring that investigation are in line of law.
Difference
Legal issues in digital forensic investigation seek to ensure that evidence that is brought to court is
genuine and admissible. This is in line with the law of evidence. On the other hand ethical issues seek to
foster discipline across the computer forensic community in regard to confidentiality of the information
that they come across.