Module 2
Data Acquisition & Processing Crime
A. Understanding Storage Formats for Digital Evidence
Data acquisition is the process of copying data. For digital forensics, it’s the task
of collecting digital evidence from electronic media. There are two types of data
acquisition: static acquisitions and live acquisitions. In this chapter, you learn how to
perform static acquisitions from magnetic disk media and flash drives. In Chapter!12, you
learn how to forensically acquire digital evidence from solid-state devices, typically
found in smartphones and tablets. Because of the use of whole disk encryption, data
acquisitions are shifting toward live acquisitions with newer operating systems (OSs). In
addition to encryption concerns, collecting any data that’s active in a suspect’s computer
RAM is becoming more important to digital investigations. Techniques for acquiring live
disk and RAM data are covered in Chapter 10. The processes and data integrity
requirements for static and live acquisitions are similar, in that static acquisitions capture
data that’s not accessed by other processes that can change. With live acquisitions, file
metadata,!such!as date and time values, changes when read by an acquisition tool. With
static acquisitions, if you have preserved the original media, making a second static
acquisition should produce the same results. The data on the original disk isn’t altered, no
matter how many times an acquisition is done. Making a second live acquisition while a
computer is running collects new data because of dynamic changes!in the OS.
Your goal when acquiring data for a static acquisition is to preserve the digital
evidence. Many times, you have only one chance to create a reliable copy of disk
evidence with a data acquisition tool. Although these tools are generally dependable, you
should still take steps to make sure you acquire an image that can be verified. In addition,
failures can and do occur, so you should learn how to use several acquisition tools and
methods; you work with a few different tools in this chapter. Other data acquisition tools
that work in Windows, MS-DOS 6.22, and Linux are described briefly in the last section,
but the list of vendors and methods is by no means conclusive. You should always search
for newer and better tools to ensure the integrity of your forensics acquisitions.
The data a forensics acquisition tool collects is stored as an image file, typically in
an open-source or proprietary format. Each vendor has unique features, so
several!different proprietary formats are available. Depending on the proprietary format,
many forensics analysis tools can read other vendors’ formatted acquisitions. Many
acquisition tools create a disk-to-image file in an older open-source format, known as
raw, as well as their own proprietary formats. The new open-source format, Advanced
Forensic Format (AFF), is gaining recognition from some forensics!examiners. Each data
acquisition format has unique features along with advantages and disadvantages. The
following sections summarize each format to help you choose which one to use.
In the past, there was only one practical way of copying data for the purpose of
evidence preservation and examination. Examiners performed a bit-by-bit copy from one
disk to another disk the same size or larger. As a practical way to preserve digital
evidence, vendors (and some OS utilities, such as the Linux/UNIX dd command) made it
possible to write bit-stream data to files. This copy technique creates simple sequential
flat files of a suspect drive or data set. The output of these flat files is referred to as a raw
format. This format has unique advantages and disadvantages to consider when selecting
an acquisition format.
As mentioned, there are two types of acquisitions: static acquisitions and live
acquisitions. Typically, a static acquisition is done on a computer seized during a police
raid, for example. If the computer has an encrypted drive, a live acquisition is done if the
password or passphrase is available—meaning the computer is powered on and has been
logged on to by the suspect. Static acquisitions are always the preferred way to collect
digital evidence. However, they do have limitations in some situations, such as an
encrypted drive that’s readable only when the computer is powered on or a computer
that’s accessible only over a network. Some solutions can help decrypt a drive that has
been encrypted with whole disk encryption, such as Elcomsoft Forensic Disk Decryptor.
Collecting evidence from a large drive can take several hours. If your time is
limited, consider using a logical acquisition or sparse acquisition data copy method.
A!logical acquisition captures only specific files of interest to the case or specific types of
files. A sparse acquisition is similar but also collects fragments of unallocated (deleted)
data; use this method only when you don’t need to examine the entire drive. An example
of a logical acquisition is an e-mail investigation that requires collecting only
Outlook .pst or .ost files. Another example is collecting only specific records from a large
RAID server. If you have to recover data from a RAID or storage area network (SAN)
server with several exabytes (EB) or more of data storage, the logical method might be
the only way you can acquire the evidence. In e-discovery for the purpose of litigation, a
logical acquisition is becoming the preferred method, especially with large data storage
systems.
Most imaging tools have an option to use lossless compression to save disk space,
which means the target drive doesn’t have to be as large as the suspect drive. For
example, if you’re examining a 3 TB SATA drive, you might be able to use lossless
compression to create the disk-to-image file on a 2 TB target drive. Image files can be
reduced by as much as 50% of the original. If the suspect drive already contains several
zip files, however, the imaging tool can’t compress them any further. This is because zip
files have already been compressed, so any additional compression results in very little
size reduction.
An easy way to test lossless compression is to perform an MD5 or SHA-1 hash on
a file before and after it’s compressed. If the compression is done correctly, both versions
have the same hash value. If the hashes don’t match, that means something corrupted the
compressed file, such as a hardware or software error. As an added precaution, perform
two separate hashes with different algorithms, such as MD5 and SHA-1. This step isn’t
mandatory; however, it’s a good way to establish that nothing has changed during data
processing. If you can’t retain the original evidence drive and must return it to the owner,
as in a discovery demand for a civil litigation case, check with the requester (your lawyer
or supervisor, for example), and ask whether a logical acquisition is acceptable. If not,
you have to refer the matter back to the requester. When performing an acquisition under
these conditions, make sure you have a good copy because most discovery demands give
you only one chance to capture data. In addition, make sure you have a reliable forensics
tool that you know how to use.
B. Contingency Planning for Image Acquisitions
Because you’re working with digital evidence, you must take precautions to
protect it from loss. You should also make contingency plans in case software or
hardware doesn’t work or you encounter a failure during an acquisition. The most
common and time-consuming technique for preserving evidence is creating a duplicate of
your disk-to-image file. Many digital investigators don’t make duplicates of their
evidence because they don’t have enough time or resources to make a second image.
However, if the first copy doesn’t work correctly, having a duplicate is worth the effort
and resources. Be sure you take steps to minimize the risk of failure in your investigation.
If you have only one tool, however, consider making two images of the drive with
the same tool, especially for critical investigations. With many tools, you can make one
copy with no compression and compress the other copy. Remember that Murphy’s Law
applies to digital forensics, too: If anything can go wrong, it will. Some acquisition tools
don’t copy data in the host protected area (HPA) of a disk drive. Check the vendor’s
documentation to see whether its tool can copy a drive’s HPA. If not, consider using a
hardware acquisition tool that can access the drive at the BIOS level, such as Belkasoft or
ILookIX IXImager, with a write-blocker, Image MASSter Solo, or X-Ways Replica.
These tools can read a disk’s HPA.
Microsoft has added whole disk encryption with BitLocker to its newer operating
systems, such as Windows Vista, 7, 8, and 10, which makes performing static
acquisitions more difficult. (Several other third-party whole disk encryption tools are
available, and you should be familiar with as many as possible.) As part of contingency
planning, you must be prepared to deal with encrypted drives. A static acquisition on
most whole disk—encrypted drives currently involves decrypting the drives, which
requires the user’s cooperation in providing the decryption key. Most whole disk
encryption tools at least have a manual process for decrypting data, which is converting
the encrypted disk to an unencrypted disk. This process can take several hours, depending
on the disk size. One good thing about encryption is that data isn’t altered, in that free
and slack space aren’t changed. The biggest concern with whole disk encryption is
getting the decryption key—that is, the password or code used to access encrypted data.
If you can recover the whole disk key with tools such as Elcomsoft Forensic Disk
Decryptor, mentioned previously, you need to learn how to use it to decrypt the drive. In
criminal investigations, this might be impossible because if a disk contains evidence
supporting the crime, a suspect has a strong motivation not to supply the decryption key.
Many forensics software vendors have developed acquisition tools that run in
Windows. These tools make acquiring evidence from a suspect drive more convenient,
especially when you use them with hot-swappable devices, such as USB-3, FireWire
1394A and 1394B, or SATA, to connect disks to your workstation. Using acquisition
tools with current OSs, such as Windows and Linux, has some drawbacks, however.
Because Windows and Linux can easily contaminate an evidence drive when it’s
mounted, you must protect it with a well-tested write-blocking hardware device. The
automatic mounting process updates boot files by changing metadata, such as the most
recent access time. (Chapter 6 discusses write-blocking devices in more detail.) In
addition, some countries haven’t yet accepted the use of write-blocking devices for data
acquisitions. Check with your legal counsel for evidence standards in your community or
country.
Accessing a disk drive directly might not be practical for a forensics acquisition.
For example, a laptop’s design could make removing the disk drive to mount it on a
write-blocker difficult, or you might not have the right connector for a drive. In these
situations, a forensic boot CD/DVD or USB drive gives you a way to acquire data from a
suspect computer and write-protect the disk drive. These forensic boot discs or drives can
be Windows or Linux. One forensically sound Windows boot utility is Mini-WinFE. It
enables you to build a Windows forensic boot CD/DVD or USB drive with a
modification in its Windows Registry file so that connected drives are mounted as read-
only. Before booting a suspect’s computer with Mini-WinFE, you need to connect your
target drive, such as a USB drive. After Mini-WinFE is booted, you can list all connected
drives and alter your target USB drive to read-write mode so that you can run an
acquisition program.
The Linux OS has many features that are applicable to digital forensics, especially
data acquisitions. One unique feature of older Linux versions is that it can access a drive
that isn’t mounted. Physical access for the purpose of reading data can be done on a
connected media device, such as a disk drive, a USB drive, or other storage devices.
In!Windows OSs and newer Linux kernels, when you connect a drive via USB, FireWire,
external SATA, or even internal PATA or SATA controllers, both OSs automatically
mount and access the drive. On Windows drives, an acquisition workstation can access
and alter data in the Recycle Bin; on Linux drives, the workstation most likely alters
metadata, such as mount point configurations for an Ext3 or later drive. If you need to
acquire a USB drive that doesn’t have a write-lock switch, use one of the forensic Linux
Live CDs (discussed in the next section) to access the device.
As powerful as this command is, it does have some shortcomings. One major
problem is that it requires more advanced skills than the average computer user might
have. Also, because it doesn’t compress data, the target drive needs to be equal to or
larger than the suspect drive. It’s possible to divide the output to other drives if a large
enough target drive isn’t available, but this process can be cumbersome and prone to
mistakes when you’re trying to keep track of which data blocks to copy to which
target!drive.
The dd command is intended as a data management tool; it’s not designed for
forensics acquisitions. Because of these shortcomings, Nicholas Harbour of the Defense
Computer Forensics Laboratory (DCFL) developed a tool that can be added to most
UNIX/Linux OSs. This tool, the dcfldd command, works similarly to the dd command
but has many features designed for forensics acquisitions. FTK Imager can make disk-to-
image copies of evidence drives and enables you to acquire an evidence drive from a
logical partition level or a physical drive level. You can also define the size of each disk-
to-image file volume, allowing you to segment the!image into one or many split volumes.
For example, you can specify 650 MB volume segments if you plan to store volumes on
650 MB CD-Rs or 2.0 GB volume segments so that you can record volumes on
DVD-/+Rs. An additional feature of FTK Imager is that it can image RAM on a live
computer. The evidence drive you’re acquiring data from must have a hardware write-
blocking device or run from a Live CD, such as Mini-WinFE.
C. Validating Data Acquisitions
Probably the most critical aspect of computer forensics is validating digital
evidence. The weakest point of any digital investigation is the integrity of the data you
collect, so validation is essential. In this section, you learn how to use several tools to
validate data acquisitions. Validating digital evidence requires using a hashing algorithm
utility, which is designed to create a binary or hexadecimal number that represents the
uniqueness of a data set, such as a file or disk drive. This unique number is referred to as
a “digital fingerprint.” With a few exceptions, making any alteration in one of the files—
even changing one letter from uppercase to lowercase—produces a completely different
hash value.
Linux is rich in commands and functions. The two Linux shell commands shown
earlier in this chapter, dd and dcfldd, have several options that can be combined with
other commands to validate data. The dcfldd command has other options that validate
data collected from an acquisition. Validating acquired data with the dd command
requires using other shell commands. Current distributions of Linux include two hashing
algorithm utilities: md5sum and sha1sum. Both utilities can compute hashes of a single
file, multiple files, individual or multiple disk partitions, or an entire disk drive.
Unlike Linux, Windows has no built-in hashing algorithm tools for digital
forensics. However, many Windows third-party programs do have a variety of built-in
tools. These third-party programs range from hexadecimal editors, such as X-Ways
WinHex or Breakpoint Software Hex Workshop, to forensics programs, such as
OSForensics, Autopsy, EnCase, and FTK. In Chapter 9, you learn how to hash specific
data by using a hexadecimal editor to locate and verify groups of data that have no file
association or are sections within a file. Commercial forensics programs also have built-
in validation features. Each program has its own validation technique used with
acquisition data in its proprietary format. For example, Autopsy uses MD5 to validate an
image. It reads the metadata in Expert Witness Compression or AFF image files to get the
original hash. If the hashes don’t match, Autopsy notifies you that the acquisition is
corrupt and can’t be considered reliable evidence.
Acquisitions of RAID drives can be challenging and frustrating for digital
forensics examiners because of how RAID systems are designed, configured, and sized.
Size is the biggest concern because many RAID systems are now pushing into exabytes
or more of data. The following sections review common RAID configurations and
discuss ways to acquire data on these large storage devices. Redundant array of
independent disks (RAID) is a computer configuration involving two or more physical
disks. Originally, RAID was developed as a data-redundancy measure to minimize data
loss caused by a disk failure. As technology improved, RAID also provided increased
storage capabilities. Several levels of RAID can be implemented through software
(known as “software RAID”) or special hardware controllers (known as “hardware
RAID”). Software RAID is typically implemented from the host computer’s OS.
Hardware RAID uses its own controller as well as a processor and memory connected to
the host computer.
RAID 0 provides rapid access and increased data storage (see Figure 3-8). In
RAID 0, two or more disk drives become one large volume, so the computer views the
disks as a single disk. The tracks of data on this mode of storage cross over to each disk.
The logical addressing scheme makes it seem as though each track of data is continuous
throughout all disks. If you have two disks configured as RAID 0, track one starts on the
first physical disk and continues to the second physical disk. When viewed from a booted
OS, such as Windows XP or later, the two disks appear as one large disk. The advantage
of RAID 0 is increased speed and data storage capability spread over two or more disks
that can be one large disk partition. Its biggest disadvantage is lack of redundancy; if a
disk fails, data isn’t continuously available.
RAID 3 uses data striping and dedicated parity and requires at least three disks.
Similar to RAID 0, RAID 3 stripes tracks across all disks that make up one volume.
RAID!3 also implements dedicated parity of data to ensure recovery if data is corrupted.
Dedicated parity is stored on one disk in the RAID 3 array. Like RAID 3, RAID 4 uses
data striping and dedicated parity (block writing), except data is written in blocks rather
than bytes. RAID 5 (see Figure 3-11) is similar to RAID 0 and RAID 3 in that it uses
distributed data and distributed parity and stripes data tracks across all disks in the RAID
array. Unlike RAID 3, however, RAID 5 places parity data on each disk. If a disk in a
RAID array has a data failure, the parity on other disks rebuilds the corrupt data
automatically when the failed drive is replaced.
The Runtime RAID Reconstructor tool copies the original RAID to a raw format
file, which must then be restored on another RAID-configured system where repairs can
be performed. It also scans and corrects errors on the newly copied RAID. R-Tools R-
Studio creates a virtual volume of the RAID image file. All repairs are made on the
virtual volume, which can then be restored to the original RAID. Occasionally, a RAID
system is too large for a static acquisition. Under ideal circumstances, your goal is to
collect a complete image of evidence drives. Because RAID systems can have dozens or
more terabytes of data storage, copying all data isn’t always practical. For these
occasions, retrieving only the data relevant to the investigation with the sparse or logical
acquisition method is the only practical solution. When dealing with very large RAID
servers, consult with the forensics vendor to determine how to best capture RAID data.
Another possible solution is renting a portable RAIDBank for your acquisition.
D. Using Remote Network Acquisition Tools
Recent improvements in forensics tools include the capability to acquire disk data
or data fragments (sparse or logical) remotely. With this feature, you can connect to a
suspect computer remotely via a network connection and copy data from it. Remote
acquisition tools vary in configurations and capabilities. Some require manual
intervention on remote suspect computers to initiate the data copy. Others can acquire
data surreptitiously through an encrypted link by pushing a remote access program to the
suspect’s computer. From an investigation perspective, being able to connect to a
suspect’s computer remotely to perform an acquisition has tremendous appeal. It saves
time because you don’t have to go to a suspect’s computer, and it minimizes the chances
of a suspect discovering that an investigation is taking place. Most remote acquisitions
have to be done as live acquisitions, not static acquisitions. When performing remote
acquisitions, advanced privileges are required to push agent applications to the remote
system.
ProDiscover Incident Response is designed to be integrated as a network intrusion
analysis tool and is useful for performing remote acquisitions. When connected to a
remote computer, it uses the same ProDiscover acquisition method described previously.
After the connection is established, the remote computer is displayed in the Capture
Image dialog box. Guidance Software was the first forensics vendor to develop a remote
acquisition and analysis tool based on its desktop tool EnCase.
The R-Tools suite of software is designed for data recovery. As part of this
recovery capability, the R-Studio network edition can remotely access networked
computer systems. Data acquired with R-Studio network edition creates raw format
acquisitions, and it’s capable of recovering many different file systems, including ReFS.
F-Response is a vendor-neutral specialty remote access utility designed to work with any
digital forensics program. When installed on a remote computer, it sets up a security
read-only connection that allows forensics examiners to access it. With F-Response,
examiners can access remote drives at the physical level and view raw data. After the F-
Response connection has been set up, any forensics acquisition tool can be used to collect
digital evidence.
In addition to the tools you’ve learned about already, you can use other
commercial acquisition tools, described in the following sections. Prices for some tools
are discounted for law enforcement officers working in digital forensics. PassMark
Software has an acquisition tool called ImageUSB for its OSForensics analysis product.
To create a bootable flash drive, you need Windows XP or later and ImageUSB
downloaded from the OSForensics Web site. ASR Data SMART is a Linux forensics
analysis tool that can make image files of a suspect drive.
In addition to RAID Reconstructor, Runtime Software offers several compact
shareware programs for data acquisition and recovery, including DiskExplorer for FAT
and DiskExplorer for NTFS. Runtime has designed its tools to be file system specific, so
DiskExplorer versions for both FAT and NTFS are available. IXImager runs from a
bootable thumb drive or CD/DVD. It’s a stand-alone proprietary format acquisition tool
designed to work only with ILookIX. It can acquire single drives and RAID drives. It
supports IDE (PATA), SCSI, USB, and FireWire devices. The IXImager proprietary
format can be converted to a raw format if other analysis tools are used. For more
information on IXImager, see www.perlustro.com/solutions/e-forensics/ iximager.
E. Identifying Digital Evidence
Evidence rules are critical, whether you’re on a civil or a criminal case. As you’ll
see, a civil case can quickly become a criminal case, and a criminal case can have civil
implications larger than the criminal case. This chapter examines rules of evidence in the
United States, but similar procedures apply in most courts worldwide. This chapter also
describes differences between a business (private entity) and a law enforcement
organization (public entity) in needs and concerns and discusses incident-scene
processing for both types of investigations. Private-sector security officers often begin
investigating private-sector digital crimes and then coordinate with law enforcement as
they complete the investigation. Law enforcement investigators should, therefore, know
how to process and manage incident scenes. Because public agencies usually don’t have
the funding to train officers continuously in technology advances, they must learn to
work with private-sector investigators, whose employers can often afford to maintain
their investigators’ computing skills.
To address these issues, this chapter explains how to apply standard crime scene
practices and rules for handling evidence to private-sector and law enforcement digital
investigations. You must handle digital evidence systematically so that you don’t
inadvertently alter or lose data. In addition, you should apply the same security controls
to evidence for a civil lawsuit as evidence for a major crime. Federal and state rules of
evidence govern both civil and criminal cases. However, the restrictions on how the
government can proceed, as opposed to a private company, are much stricter. For
example, as long as a policy exists, a company doesn’t need a search warrant to examine
a machine it owns; however, the government does. These rules are similar in English-
speaking countries because they have a common ancestor in English common law (judge-
made law), dating back to the late Middle Ages. However, laws in only 40% of the world
are based on English or Dutch common law.
Digital evidence can be any information stored or transmitted in digital form.
Because you can’t see or touch digital data directly, it’s difficult to explain and describe.
Is digital evidence real or virtual? Does data on a disk or other storage medium physically
exist, or does it merely represent real information? U.S. courts accept digital evidence as
physical evidence, which means digital data is treated as a tangible object, such as a
weapon, paper document, or visible injury, that’s related to a criminal or civil incident. In
addition, ISO standard 27037 gives guidance on what procedures countries should have
in place for digital evidence. However, each country has its own interpretation of what
can or can’t be presented in court or accepted as evidence. Some countries used to require
that all digital evidence be printed to be presented in court, and this requirement, at one
time, was true for many U.S. states.
Collecting digital devices while processing a crime or incident scene must be
done systematically. To minimize confusion, reduce the risk of losing evidence, and
avoid damaging evidence, only one team should collect and catalog digital evidence at a
crime scene or lab, if practical. If there’s too much evidence or too many systems to make
it practical for one team to perform these tasks, all examiners must follow the same
established operating procedures, and a lead or managing examiner should control
collecting and cataloging evidence. You should also use standardized forms (discussed
later in “Documenting Evidence”) for tracking evidence to ensure that you consistently
handle evidence in a safe, secure manner.
Consistent practices help verify your work and enhance your credibility, so you
must handle all evidence consistently. Apply the same security and accountability
controls for evidence in a civil lawsuit as in a major crime to comply with your state’s
rules of evidence or with the Federal Rules of Evidence (FRE). Also, keep in mind that
evidence admitted in a criminal case might also be used in a civil suit, and vice versa. As
part of your professional growth, keep current on the latest rulings and directives on
collecting, processing, storing, and admitting digital evidence. The following sections
discuss some key concepts of digital evidence. You can find additional information at the
U.S. Department of Justice Web site (www.usdoj.gov) and by searching the Internet for
“digital evidence,” “best evidence rule,” “hearsay,” and other relevant keywords. Consult
with your prosecuting attorney, Crown attorney, corporate general counsel, or the
attorney who retained you to learn more about managing evidence for your investigation.
In other common law countries, a distinction is made between “real computer
evidence” and “hearsay computer evidence.” A simplified explanation of this distinction
states that you can, for example, prove an e-mail was sent and perhaps opened by a
logged-in user. However, you can’t necessarily verify the e-mail’s contents.!Generally,
digital records are considered admissible if they qualify as a business record. Another
way of categorizing digital records is by dividing them into computergenerated records
and computer-stored records. Computer-generated records are data!the system maintains,
such as system log files and proxy server logs. They are output generated from a
computer process or algorithm, not usually data a person!creates. Computer-stored
records, however, are electronic data that a person creates!and saves on a computer or
digital device, such as a spreadsheet or word processing document. Some records
combine computer-generated and computer-stored evidence, such as a spreadsheet
containing mathematical operations!(computer-generated records) generated from a
person’s input (computer-stored records).
Computer-generated and computer-stored records must also be shown to be
authentic and trustworthy to be admitted into evidence. Computer-generated records are
considered authentic if the program that created the output is functioning correctly. These
records are usually considered exceptions to the hearsay rule. For computerstored records
to be admitted into court, they must also satisfy an exception to the hearsay rule, usually
the business-record exception, so they must be authentic records of regularly conducted
business activity. To show that computer-stored records are authentic, the person offering
the records must demonstrate that a person created the data and the data is reliable and
trustworthy—in other words, it wasn’t altered when it was acquired or afterward.
When attorneys challenge digital evidence, often they raise the issue of whether
computer-generated records were altered or damaged after they were created. In the case
of American Express v. Vinhnee (9th Cir. Bk. App. Panel, 2005), the judge determined
that American Express hadn’t established that the records presented in court were
authentic and the same as the original bill sent to Mr. Vinhnee. The company lost on
appeal, too. Attorneys might also question the authenticity of computer-generated records
by challenging the program that created them. FRE 902, for example, refers to
selfauthenticating evidence, which includes public documents that are sealed and signed
or certified. It also includes publications such as newspapers. Proposed changes to FRE
902 (b) are attempting to put an end to challenges based on computer-generated records
being unreliable or having been tampered with.
As mentioned, one test to prove that computer-stored records are authentic is to
demonstrate that a specific person created the records. Establishing who created digital
evidence can be difficult, however, because records recovered from slack space or
unallocated disk space usually don’t identify the author. The same is true
for!other!records, such as anonymous e-mails or text messages. To establish authorship of
digital evidence in these cases, attorneys can use circumstantial evidence, which requires
finding other clues associated with the suspect’s computer or location. The!circumstantial
evidence might be that the computer has a password consistent with the password the
suspect used on other systems, a witness saw the suspect at the!computer at the time the
offense occurred, or additional trace evidence!associates the suspect with the computer at
the time of the incident. In a recent case, the attorney!chose not to use the digital evidence
because although it could be proved that!a particular camera was used to create the
suspect’s movies, CDs, and DVDs, there!was no way to prove that the suspect was the
person using the camera. Therefore, there was no circumstantial or corroborating
evidence to prove that!the suspect was guilty.
In addition to revealing the author, computer-stored records must be proved
authentic, which is the most difficult requirement when you’re trying to qualify evidence
as an exception to the hearsay rule. The process of establishing digital evidence’s
trustworthiness originated with written documents and the “best evidence rule,” which
states that to prove the content of a written document, a recording, or a photograph,
ordinarily the original file is required (as stated in Article X, Rule 1001, of the FRE). In
addition, the original of a document is preferred to a duplicate. The best evidence,
therefore, is the document created and saved on a computer’s hard disk. However, Rule
1001, section (e), defines a duplicate done in a manner, including electronic, that
“accurately reproduces the original.” Moreover, Rule 1003 states that the duplicate can be
used unless the original’s authenticity is challenged.
Agents and prosecutors occasionally express concern that a printout of a
computer-stored electronic file might not qualify as an original document, according to
the best evidence rule. In its most fundamental form, the original file is a collection of 0s
and 1s; in contrast, the printout is the result of manipulating the file through a
complicated series of electronic and mechanical processes (FRE, 803(6); see “Searching
and Seizing from Computers and Obtaining Electronic Evidence in Criminal
Investigations,” 2009). To address this concern about original evidence, the FRE states:
“[I]f data are stored in a computer or similar device, any printout or other output readable
by sight, shown to reflect the data accurately, is an ‘original.’” Instead of producing hard
disks in court, attorneys can submit printed copies of files as evidence. In contrast, some
countries and even some U.S. states used to allow only the printed version to be
presented in court, not hard disks.
Private-sector organizations include small to medium businesses, large
corporations, and non-government organizations (NGOs), which might get funding from
the government or other agencies. In the United States, NGOs and similar agencies must
comply with state public disclosure and federal Freedom of Information Act (FOIA) laws
and make certain documents available as public records. State public disclosure laws
define state public records as open and available for inspection. For example, divorces
recorded in a public office, such as a courthouse, become matters of public record unless
a judge orders the documents sealed. Anyone can request a copy of a public divorce
decree. Figure 4-3 shows an excerpt of a public disclosure law for the state of Idaho.
State public disclosure laws apply to state records, but the FOIA allows citizens to
request copies of public documents created by federal agencies. The FOIA was originally
enacted in the 1960s, and several subsequent amendments have broadened its laws. Some
Web sites now provide copies of publicly accessible records for a fee. ISPs and other
communication companies make up a special category of privatesector businesses. ISPs
can investigate computer abuse committed by their employees but not by customers.
They must preserve customer privacy, especially when dealing with e-mail. However,
federal regulations related to the Homeland Security Act and the PATRIOT Act of 2001
have redefined how ISPs and large organizations operate and maintain their records. ISPs
and other communication companies can be called on to investigate customers’ activities
that are deemed to create an emergency situation. An emergency situation under the
PATRIOT Act is defined as the immediate risk of death or personal injury, such as
finding a bomb threat in an e-mail.
Investigating and controlling computer incident scenes in private-sector
environments is much easier than in crime scenes. In the private sector, the incident scene
is often a workplace, such as a contained office or manufacturing area, where a policy
violation is being investigated. Everything from the computers used to violate a company
policy to the surrounding facility is under a controlled authority— that is, company
management. Typically, businesses have inventory databases of computer hardware and
software. Having access to these databases and knowing what applications are on
suspected computers help identify the forensics tools needed to analyze a policy violation
and the best way to conduct the analysis. For example, companies might have a preferred
Web browser, such as Microsoft Internet Explorer, Microsoft Edge, Mozilla Firefox, or
Google Chrome. Knowing which browser a suspect used helps you develop standard
examination procedures to identify data downloaded to the suspect’s workstation.
However, if a company doesn’t display a warning banner or publish a policy
stating that it reserves the right to inspect digital assets at will, employees have an
expectation of privacy (as explained in Chapter 1). When an employee is being
investigated, this expected privacy prevents the employer from legally conducting an
intrusive investigation. A well-defined company policy, therefore, should state that an
employer has the right to examine, inspect, or access any company-owned digital assets.
If a company issues a policy statement to all employees, the employer can investigate
digital assets at will without any privacy right restrictions; this practice might violate the
privacy laws of countries in the EU, for example. As a standard practice, companies
should use both warning banners and policy statements. For example, if an incident is
escalated to a criminal complaint, prosecutors prefer showing juries warning
banners!instead of policy manuals. A warning banner leaves a much stronger impression
on a jury.
If a private-sector investigator finds that an employee is committing or has
committed a crime, the employer can file a criminal complaint with the police. Some
businesses, such as banks, have a regulatory requirement to report crimes. In the United
States, the employer must turn over all evidence to the police for prosecution. If this
evidence had been collected by a law enforcement officer, it would require a warrant,
which would be difficult to get without sufficient probable cause. In “Processing Law
Enforcement Crime Scenes” later in this chapter, you learn more about probable cause
and how it applies to a criminal investigation.
If you discover evidence of a crime during a company policy investigation, first
determine whether the incident meets the elements of criminal law. You might have to
consult with your organization’s attorney to determine whether the situation is a potential
crime. Next, inform management of the incident; they might have other concerns, such as
protecting confidential business data that could be included with the criminal evidence
(called “commingled data”). In this case, coordinate with management and the
organization’s attorney to determine the best way to protect commingled data. After you
submit evidence containing sensitive information to the police, it becomes public record.
Public record laws do include exceptions for protecting!sensitive company information;
ultimately, however, a judge decides what!to protect.
After you discover illegal activity and document and report the crime, stop your
investigation to make sure you don’t violate Fourth Amendment restrictions on obtaining
evidence. If the information you supply is specific enough to meet the criteria for a search
warrant, the police are responsible for obtaining a warrant that requests any new
evidence. If you follow police instructions to gather additional evidence without a search
warrant after you have reported the crime, you run the risk of becoming an agent of law
enforcement. Instead, consult with your organization’s attorney on how to respond to a
police request for information. The police and prosecutor should issue a subpoena for any
additional new evidence, which minimizes your exposure to potential civil liability. In
addition, you should keep all documentation of evidence collected to investigate an
internal company policy violation. Later in this section, you learn more about using
affidavits in an internal investigation.
You survey the remaining content of the subject’s drive and find that he’s a lead
engineer for the team developing your company’s latest high-tech bicycle. He placed the
child pornography images in a subfolder where the bicycle plans are stored. By doing so,
he has commingled contraband with the company’s confidential design plans for the
bicycle. Your discovery poses two problems in dealing with this contraband evidence.
First, you must report the crime to the police; all U.S. states and most countries have
legal and moral codes when evidence of sexual exploitation of children is found. Second,
you must also protect sensitive company information. Letting the high-tech bicycle plans
become part of the criminal evidence might make it public record, and the design work
will then be available to competitors. Your first step is to ask your organization’s attorney
how to deal with the commingled contraband data and sensitive design plans.
Your next step is to work with the attorney to write an affidavit confirming your
findings. The attorney should indicate in the affidavit that the evidence is commingled
with company secrets, and releasing the information will be detrimental to the company’s
financial health. When the affidavit is completed, you sign it before a notary, and then
deliver the affidavit and the recovered evidence with log files to the police, where you
make a criminal complaint. At the same time, the attorney goes to court and requests that
all evidence recovered from the hard disk that’s not related to the complaint and is a
company trade secret be protected from public viewing. You and the attorney have
reported the crime and taken steps to protect the sensitive data.
F. Processing Law Enforcement Crime Scenes
To process a crime scene correctly, you must be familiar with criminal rules of
search and seizure. You should also understand how a search warrant works and what to
do when you process one. For all criminal investigations in the United States, the Fourth
Amendment limits how governments search and seize evidence. A law enforcement
officer can search for and seize criminal evidence only with probable cause. Probable
cause is the standard specifying whether a police officer has the right to make an arrest,
conduct a personal or property search, or obtain a warrant for arrest. With probable cause,
a police officer can obtain a search warrant from a judge to authorize a search and the
seizure of specific evidence related to the criminal complaint.
The Fourth Amendment states that only warrants “particularly describing the
place to be searched and the persons or things to be seized” can be issued. Note that this
excerpt uses the word “particularly.” The courts have determined that it means a warrant
can authorize a search only of a specific place for a specific thing. Without specific
evidence and the description of a particular location, a warrant might be weak and create
problems later during prosecution. For example, stating that the evidence is in a house on
Elm Avenue between Broadway and Main Street is too general, unless only one house
fits that description, because several houses might be located in this area. Instead, provide
specific information, such as “123 Elm Avenue.”
You should be familiar with warrant terminology governing the type of evidence
that can be seized. Many digital investigations involve large amounts of data you must
sort through to find evidence; the Enron case, for example, involved terabytes of
information. Unrelated information (referred to as innocent information) is often included
with the evidence you’re trying to recover. It might be personal records of innocent
people or confidential business information, for example. When you find commingled
evidence, judges often issue a limiting phrase to the warrant, which allows the police to
separate innocent information from evidence. The warrant must list which items can be
seized.
However, the plain view doctrine’s applicability in the digital forensics world is
being rejected. The U.S. Court of Appeals for the Ninth Circuit has directly addressed
this doctrine and used it to give wide latitude to law enforcement (United States v. Wong,
334 F.3d 831, 9th Cir., 2003). Other circuit courts have been less willing to address
applying the doctrine to computer searches. For example, police investigating a case have
a search warrant authorizing the search of a computer for evidence related to illegal drug
trafficking; during the search, the examiner observes an .avi file, opens it, and sees that
it’s child pornography. At that point, she must get an additional warrant or an expansion
of the existing warrant to continue the search for child pornography. This approach is
consistent with rulings in United States v. Carey (172 F.3d 1268, 10th Cir., 1999) and
United States v. Walser (275 F.3d 981, 10th Cir., 2001). In a more recent case that went
to the Ninth Circuit Court of Appeals, the original search warrant was for 10 major
league baseball players suspected of steroid use (United States v. Comprehensive Drug
Testing, 2010). During the examination of files and e-mails, 200 more players were
implicated. Forensics investigators see many files when they’re searching for evidence,
so in this case, their opinion was that the data was in plain view. However, the court
disagreed. As with the example of discovering child pornography, a separate warrant for
all other players should have been issued.
Preparing for search and seizure of computers or digital devices is probably the
most important step in digital investigations. The better you prepare, the smoother your
investigation will be. The following sections discuss the tasks you should perform before
you search for evidence. For these tasks, you might need to get answers from the victim
(the complainant) and an informant, who could be a police detective assigned to the case,
a law enforcement witness, or a manager or co-worker of the person of interest to the
investigation.
Next, determine the type of OSs involved in the investigation. For law
enforcement, this step might be difficult because the crime scene isn’t controlled. You
might not know what kinds of digital devices were used to commit a crime or how or
where they were used. In this case, you must draw on your skills, creativity, and sources
of knowledge, such as the Uniform Crime Report discussed in Chapter 2, to deal with the
unknown. If you can identify the OS or device, estimate the size of the storage device on
suspect computers and determine how many digital devices you have to process at the
scene. Also, determine what hardware might be involved, such as PCs or mobile devices,
including smartphones, tablets, Fitbits, and laptops. Then you need to determine the OS:
Microsoft, Linux, macOS, Apple iOS, Android, and so forth. For private-sector
investigators, configuration management databases make this step easier.
Generally, the ideal situation for incident or crime scenes is seizing computers
and digital devices and taking them to your lab for further processing. However, the type
of case and location of the evidence determine whether you can remove digital equipment
from the scene. Law enforcement investigators need a warrant to remove computers from
a crime scene and transport them to a lab. If removing the computers will irreparably
harm a business, the computers shouldn’t be taken offsite, unless you have disclosed the
effect of the seizure to the judge. An additional complication is files stored offsite that are
accessed remotely. You must decide whether the drives containing these files need to be
examined. Another consideration is the availability of cloud storage, which essentially
can’t be located physically. The data is stored on drives where data from many other
subscribers might be stored.
The more information you have about the location of a digital crime, the more
efficiently you can gather evidence from the crime scene. Environmental and safety
issues are the main concerns during this process. Before arriving at incident or crime
scenes, identify potential hazards to your safety as well as that of other examiners. Some
cases involve dangerous settings, such as a drug bust of a methamphetamine lab or a
terrorist attack using biological, chemical, or nuclear contaminants. For these types of
investigations, you must rely on the skills of hazardous materials (HAZMAT) teams to
recover evidence from the scene. The recovery process might include decontaminating
digital components needed for the investigation, if possible. If the decontamination
procedure might destroy electronic evidence, a HAZMAT specialist or an investigator in
HAZMAT gear should make an image of a suspect’s drive. If you have to rely on a
HAZMAT specialist to acquire data, coach the specialist on how to connect cables and
how to run the software. You must be exact and articulate in your instructions.
Ambiguous or incorrect instructions could destroy evidence. Ideally, a digital forensics
investigator trained in dealing with HAZMAT environments should acquire drive images.
However, not all organizations have funds available for this!training.
As discussed in Chapter 1, a company needs an established line of authority to
specify who can instigate or authorize an investigation. Private-sector investigations
usually require only one person to respond to an incident or crime scene. Processing
evidence usually involves acquiring an image of a suspect’s drive. In law enforcement,
however, many investigations need additional staff to collect all evidence quickly. For
large-scale investigations, a crime or incident scene leader should be designated. Anyone
assigned to a large-scale investigation scene should cooperate with the designated leader
to ensure that the team addresses all details when collecting evidence.
After you collect evidence data, determine whether you need specialized help to
process the incident or crime scene. For example, suppose you’re assigned to process a
crime scene at a data center running Windows servers with several RAID drives
and!high-end Linux servers. If you’re the lead on this investigation, you must identify!the
additional skills needed to process the crime scene, such as enlisting help with a high-end
server OS. Other concerns are how to acquire data from RAID drives!and how!much data
you can acquire. RAID servers typically process several terabytes of data, and standard
imaging tools might not be able to handle such large!data sets.
After you have gathered as much information as possible about the incident or
crime scene, you can start listing what you need at the scene. Being overprepared is better
than being underprepared, especially when you determine that you can’t transfer the
computer to your lab for processing. To manage your tools, consider creating an initial-
response field kit and an extensive-response field kit. Using the right kit makes
processing an incident or crime scene much easier and minimizes how much you have to
carry from your vehicle to the scene. Your initial-response field kit should be lightweight
and easy to transport. With this kit, you can arrive at a scene, acquire the data you need,
and return to the lab as quickly as possible. Figure 4-4 shows some items you might need,
and Table 4-1 lists the tools you might need in an initial-response field kit.
Before you initiate the search and seizure of digital evidence at incident or crime
scenes, you must review all the available facts, plans, and objectives with the
investigation team you have assembled. The goal of scene processing is to collect and
secure digital evidence successfully. The better prepared you are, the fewer problems you
encounter when you carry out the plan to collect data. Keep in mind that digital evidence
is volatile. Develop the skills to assess the facts quickly, make your plan, gather the
needed resources, and collect data from the incident or crime scene. In some digital
investigations, responding slowly might result in the loss of important evidence for the
case.
G. Securing a Digital Incident or Crime Scene
Investigators secure an incident or crime scene to preserve the evidence and to
keep information about the incident or crime confidential. Information made public could
jeopardize the investigation. If you’re in charge of securing a digital incident or crime
scene, use barrier tape to prevent bystanders from entering the scene accidentally, and ask
police officers or security guards to prevent others from entering the scene or taking
photos and videos with smartphones and other digital devices. Legal authority for an
incident scene includes trespassing violations; for a crime scene, it includes
obstructing!justice or failing to comply with a police officer. Access to the scene should
be restricted to only those people who have a specific reason to be there. The reason for
the standard practice of securing an incident or a crime scene is to expand the area of
control beyond the scene’s immediate location. In this way, you avoid overlooking an
area that might be part of the scene. Shrinking the scene’s perimeter is easier than
expanding it.
For major crime scenes, digital investigators aren’t usually responsible for
defining!a scene’s security perimeter. These cases involve other specialists and detectives
who are collecting physical evidence and recording the scene. For incidents involving
mostly computers, the computers can be a crime scene within a crime scene!or a
secondary crime scene, containing evidence to be processed. The evidence is in the
computer, but the courts consider it physical evidence. Computers and other!digital
devices can also contain actual physical evidence, such as DNA evidence!or fingerprints
on keyboards. Crime labs can use special vacuums to extract!DNA residue from a
keyboard to compare with other DNA samples. In a major!crime scene,!law enforcement
usually retains the keyboard and other!peripherals.
Evidence is commonly lost or corrupted because of professional curiosity, which
involves the presence of police officers and other professionals who aren’t part of the
crime scene–processing team. They just have a compelling interest in seeing what
happened, but their presence could contaminate the scene directly or indirectly. Keep in
mind that even those authorized and trained to search crime scenes can alter the scene or
evidence inadvertently. For example, during one homicide investigation, the lead
detective collected a good latent fingerprint from the crime scene. He compared it with
the victim’s fingerprints and those of others who knew the victim, but he couldn’t find a
matching fingerprint. The detective suspected he had the murderer’s fingerprint and kept
it on file for several years until his police department purchased an Automated
Fingerprint Identification System (AFIS) computer. During acceptance testing, the
software vendor processed sample fingerprints to see how quickly and accurately the
system could match fingerprints in the database. The detective asked the testing team to
run the fingerprint he found at the homicide scene. He believed the suspect’s fingerprints
were in the AFIS database. The testing team complied and within minutes, AFIS found a
near-perfect match of the latent fingerprint: It belonged to the detective.
With proper search warrants, law enforcement can seize all digital systems and
peripherals. In private-sector investigations, you might have similar authority; however,
you might have the authority only to make an image of the suspect’s drive. Depending on
company policies, private-sector investigators rarely have the authority to seize all
computers and peripherals. The evidence you acquire at the scene depends on the nature
of the case and the alleged crime or violation. For a criminal case involving a drug
dealer’s computer, for example, you need to take the entire computer along with any
peripherals and media in the area, including smartphones, USB devices, CDs/DVDs,
printers, cameras, and scanners. You might also need to seize smart TVs, gaming
systems, and other devices attached to the network. Seizing peripherals and other media
ensures that you leave no necessary system components behind, but predicting what
components might be critical to the system’s operation is often difficult. On the other
hand, if you’re investigating employee misconduct, you might need only a few specific
items.
The following guidelines offer suggestions on how to process incident or crime
scenes. As you gain experience in performing searches and seizures, you can add to or
modify these guidelines to meet the needs of specific cases. Use your judgment to
determine what steps to take when processing a civil or criminal investigation. For any
difficult issues, seek out legal counsel or other technical experts. Keep a journal to
document your activities. Include the date and time you arrive on the scene, the people
you encounter, and notes on every important task you perform. Update the journal as you
process the scene. With mobile devices, you can easily record a log of what you’re doing;
just be sure to check who has access to your mobile device.
Take video and still recordings of the area around the computer or digital device.
Start by recording the overall scene, and then record details with close-up shots,
including the back of all computers. Before recording the back of each computer, place
numbered or lettered labels on each cable to help identify which cable is connected to
which plug, in case you need to reassemble components at the lab. Make sure you take
close-ups of all cable connections, including keyloggers (devices used to record
keystrokes) and dongle devices used with software as part of the licensing agreement.
Record the area around the computer, including the floor and ceiling, and all access
points to the computer, such as doors and windows. Be sure to look under any tables or
desks for anything taped to the underside of a table or desk drawer or on the floor out of
view. If the area has ceiling panels—false ceiling tiles—remove them and record that
area, too. Slowly pan or zoom the camera to prevent blurring in the video image, and
maintain a camera log for all shots you take.
As a general rule, don’t cut electrical power to a running system unless it’s an
older Windows or MS-DOS!system. However, it’s a judgment call because of recent
trends in digital crimes. More digital investigations now revolve around network and
Internetrelated cases, which rely heavily on log file data. Certain files, such as the Event
log and Security log in Windows, might lose essential network activity records if power
is terminated without a proper shutdown. Some government agencies, however, still teach
investigators to “pull the plug”; it’s the Digital Evidence First Responder’s (DEFR’s)
judgment call. If you’re working on a network or Internet investigation and the computer
is on, save data in any current applications as safely as possible and record all active
windows or shell sessions. Don’t examine folders or network connections or press any
keys unless it’s necessary. For systems that are powered on and running, photograph the
screens. If windows are open but minimized, expanding them so that you can photograph
them is safe. As a precaution, write down each window’s contents.
As you’re copying data on a live suspect computer, make notes in your journal
about everything you do so that you can explain your actions in your formal report to
prosecutors and other attorneys. When you’ve finished recording screen contents, save
them to external media. For example, if one screen shows a Word file, save it to an
external drive. Keep in mind that the suspect might have changed the file since last!using
the Save command. If another screen is a Web browser, take a screenshot or save!the
Web page to a USB drive or an external hard drive. If the suspect computer has!an active
connection to a network server with enough storage, you can save large files to a folder
on the server. To do so, you need the network administrator’s!cooperation to direct you to
the correct server and folder for storing!the!file.
Digital investigators sometimes perform forensics analysis on RAID systems or
server!farms, which are rooms filled with extremely large disk systems and are typical of
large!business data centers, such as banks, insurance companies, and ISPs. As
you!learned in Chapter 3, one technique for extracting evidence from large systems
is!sparse acquisition. This technique extracts only data related to evidence for your case
from allocated files and minimizes how much data you need to analyze. A drawback of
this technique is that it doesn’t recover data in free or slack space. If you!have a digital
forensics tool that accesses unallocated space on a RAID system,!work!with the tool on a
test system first to make sure it doesn’t corrupt the RAID system.
When working with advanced technologies, recruit a technical advisor who can
help you list the tools you need to process the incident or crime scene. At large data
centers, the technical advisor is the person guiding you about where to locate data and
helping you extract log records or other evidence from large RAID servers. In law
enforcement cases,!the technical advisor can help create the search warrant by itemizing
what you need for the warrant. If you use a technical advisor for this purpose, you should
list his or her name in the warrant. At the scene, a technical advisor can help direct other
investigators to collect evidence correctly.
After you collect digital evidence at the scene, you transport it to a forensics lab,
which should be a controlled environment that ensures the security and integrity of digital
evidence. In any investigative work, be sure to record your activities and findings as you
work. To do so, you can maintain a journal to record the steps you take as you process
evidence. Your goal is to be able to reproduce the same results when you or another
investigator repeat the steps you took to collect evidence. If you get different results
when you repeat the steps, the credibility of your evidence becomes questionable. At
best, the evidence’s value is compromised; at worst, the evidence will be disqualified.
Because of the nature of electronic components, failures do occur. For example, you
might not be able to repeat a data recovery because of a hardware failure, such as a disk
drive head crash. Be sure to report all facts and events as they occur.
You must maintain the integrity of digital evidence in the lab as you do when
collecting it in the field. Your first task is to preserve the disk data. If you have a suspect
computer that hasn’t been copied with an imaging tool, you must create a copy. When
you do, be sure to make the suspect drive read-only (typically by using a write-blocking
device), and document this step. If the disk has been copied with an imaging tool, you
must preserve the image files. With most imaging tools, you can create smaller,
compressed volume sets to make archiving your data easier.
H. Storing Digital Evidence
With digital evidence, you need to consider how and on what type of media to
save it and what type of storage device is recommended to secure it. The choice of media
for storing digital evidence usually depends on how long you need to keep it. If you
investigate criminal matters, store the evidence as long as you can. The ideal storage
media for digital data used to be CDs and DVDs. (CDs from the 1980s could last up to
5!years. The expected lifespan of CDs and DVDs is now 2 to 5 years.) The optimum
choice now is solid-state USB drives. Although they’re more expensive than CDs and
DVDs, they’re more durable.
Evidence is routinely kept for long periods. In the United States, for example, tens
of thousands of rape kits kept in storage have never been processed, and as you’ve
probably heard, cold cases from 20, 30, or even 50 years ago are now being solved
because of advances in technology. You never know when a case might be solved or go
to trial, so you need to make sure evidence is preserved for the long term. If a 30-year
lifespan for data storage is acceptable for your digital evidence, older DLT magnetic tape
cartridge systems are a good choice. Keep in mind that you never know how long it will
take for a case to go to trial. DLT systems have been used with mainframe computers for
several decades and are reliable data-archiving systems. Depending on the size of the
DLT cartridge, one cartridge can store up to 80 GB of data in compressed mode. Speed of
data transfer from a hard drive to a DLT tape is also faster than transferring data to a CD
or DVD. The only major drawback of a DLT drive and tapes is cost. A drive can cost
from $400 to $800, and each tape is about $40. However, with the current large disk
drives, the DLT system does offer substantial labor savings over other!systems.
To help maintain the chain of custody for digital evidence so that it’s accepted in
court or by arbitration, restrict access to your lab and evidence storage area. When your
lab is open for operations, authorized personnel must keep these areas under constant
supervision. When your lab is closed, at least two security workers should guard evidence
storage cabinets and lab facilities. As a good security practice, your lab should have a
sign-in roster for all visitors. Most labs use a manual log system that an authorized
technician maintains when an evidence storage container is opened and closed. Some
facilities have upgraded to electronic systems that meet statutes, but many prefer the
tried-and-true manual logs. These logs should be maintained for a period based on legal
requirements, including the statute of limitations, the maximum sentence, and expiration
of appeal periods. Make the logs available for management to inspect.
To verify data integrity, different methods of obtaining a unique identity for file
data have been developed. One of the first methods was the Cyclic Redundancy Check
(CRC), a mathematical algorithm that determines whether a file’s contents have changed.
The most recent version is CRC-32. CRC, however, is not considered a forensic hashing
algorithm. The first algorithm used for digital forensics was Message Digest 5 (MD5).
Like CRC, MD5 is a mathematical formula that generates a hexadecimal code, or hash
value, based on the contents of a file, a folder, or an entire drive. If a bit or byte in the file
changes, it alters the hash value, a unique hexadecimal value that can be used to verify
that a file or drive hasn’t changed or been tampered with. Before you process or analyze a
file, you can use a software tool to calculate its hash value. After you process the file, you
produce another digital hash. If it’s the same as the original one, you can verify the
integrity of your digital evidence with mathematical proof that the file didn’t change.
Most digital forensics hashing needs can be satisfied with a nonkeyed hash set,
which is a unique hash number generated by a software tool, such as the Linux md5sum
command. The advantage of this type of hash is that it can identify known files, such as
executable programs or viruses, that hide themselves by changing their names. For
example, many people who view or transmit pornographic material change filenames and
extensions to obscure the nature of the contents. However, even if a file’s name and
extension change, the hash value doesn’t. The alternative to a nonkeyed hash is a keyed
hash set, which is created by an encryption utility’s secret key. You can use the secret key
to create a unique hash value for a file. Although a keyed hash set can’t identify files as
nonkeyed hash methods can, it can produce a unique hash set for digital evidence.
Most cases in the private sector are considered low-level investigations, or
noncriminal cases. This doesn’t mean private-sector investigations are less important; it
means they require less effort than a major criminal case. The example of a low-level
civil investigation in this section is an e-mail investigation that resulted in a lawsuit
between two businesses. An investigation of this nature requires examining only e-mail
messages, not a complete disk forensics analysis. Mr. Jones at Company A claims to have
received an order for $200,000 in widgets!from the purchasing manager, Mr. Smith, at
Company B. Company A manufactures the widgets and notifies Company B that they’re
ready for shipment. Mr.!Smith at Company B replies that they didn’t order any widgets
and won’t pay for them. Company A locates an e-mail requesting the widgets that
appears to be from Mr.!Smith and informs Company B about the e-mail. Company B tells
Company A!that!the e-mail didn’t originate from its e-mail server, and it won’t pay for
the!widgets.
Another activity common in the private sector is covert surveillance of employees
who are abusing their computing and network privileges. The use of
covert!surveillance!of employees must be well defined in company policy before it can!be
carried out. If a company doesn’t have a policy that informs employees they have no
privacy rights when using company computers and digital devices, no surveillance can be
conducted!without exposing the company to civil or even criminal liability. If no policy
exists, the company must create a policy and notify all employees about the new rules.
The Legal Department should create policy language appropriate for your state or country
and define the rights and authority the company has in conducting surveillance of
employees according to provincial, state, or country privacy!laws.
For covert surveillance, you set up monitoring tools that record a suspect’s
activity!in real time. Real-time surveillance requires sniffing data transmissions between
a suspect’s computer and a network server. Network sniffer tools, such as Wireshark,
allow network administrators and others to determine what data is being transmitted over
the network. Other data-collecting tools (called keylogger programs—Spector and
TrueActive Software, for example) are screen capture programs that collect!most or all
screens and keystrokes on a suspect’s computer. Most of these tools run on!Windows and
usually collect data through remote network connections. The tools are hidden or
disguised as other programs in Windows Task Manager and process!logs.