Assignment 1
RUNNING HEAD: PROJECT 2 1
Project 2 8
CCJS 321 – Digital Forensics
Professor Frank Evans
Project 2
1. What permissions/authorities should you have before you search Mr. Yourprop’s former Company work area, and how would you document that authority?
You should have permission from the organizations senior leadership prior to searching the area. Organization policy should state what can and cannot be searched and seized within the work area (specifying company owned areas and private areas). Documentation of authority could be an Appointment Letter from leadership stating the purpose and scope of the search and the designated individual(s) conducting the search, or authority can be granted if specifically named within the organizational policy. “Civil law recognizes and enforces rights of ownership and control over forms of property in addition to intellectual property.” (Schwerha, 2004). Within the workplace, the organization is more than likely the owner of the physical assets (desks, computers, storage devices) as well as intellectual property. This, coupled with the organization’s policy, will allow appointed authorities (Company IT Specialist) to conduct a search of the company owned workplace.
2. (Looking at the photo of Mr. Yourprop’s work area, provided for Project 2 in the Course Content area) Identify three (3) potential items of digital evidence you see in the photo. For EACH item of digital evidence you identified, explain what potential use that item would be to your investigation (e.g., what type of data that item might hold) AND how you would collect that item as evidence (with emphasis on your care and handling of that item consistent with digital forensic best practices described in your textbook).
1 - HDD x2 – The hard disk drives can contain vast amounts of encrypted and/or unencrypted data pertinent to the investigation. The drives can contain the information even after the user attempted to delete it. Additionally, the HDDs can contain real evidence presentable in the court of law (such as the suspects finger prints on the drive casing) to prove the suspect had some sort of interaction with the device. Drives can also be used as hard evidence if it contains data pertaining to the crime and/or activity. To collect these hard drives (which are already disconnected from a computer), simply photograph and document where they were located, the label information (if available) and bag and tag according to chain of custody and transportation procedures.
2 – Laptop – Since a laptop is a mobile computer, it will contain a lot more information when compared to a disconnected HDD. Along with the raw data found on the primary storage device, the laptop can contain information detailing network connection, user profiles, as well as volatile data so it is important to extract that data prior to shutting the system down. While following the same evidence collection procedures, photograph/document the location and current state of the device prior to interaction. Conduct any active collection measure to collect critical data prior to shutdown, then transport to the lab accordingly for further analysis.
3 - Thumb drive x2 (blue USB item in laptop appears to be a thumb drive) – The type of information found on thumb drives would be very similar compared to HDDs just on a smaller scale. Since most thumb drives contain firmware (software specific to the device pre-loaded on the device), it is possible that hidden information is injected into the pre-existing data. Collection of these as evidence would follow the same procedure as HDDs; photograph, document, bag and tag, transport.
3. (Looking at the photo of Mr. Yourprop’s work area, provided for Project 2 in the Course Content area) Identify three (3) potential items of non-digital evidence you see in the photo. For EACH item of non-digital evidence you identified, explain what potential use that item would be to your investigation AND how you would collect that item as evidence.
1 – Sticky Note x3 – the sticky notes can have usernames and passwords written on them as well as other data pertaining to the investigation. The top left note has Blackberry forward information and directions, informing investigators that the user has/had a personal or company issued cellphone. The middle note on the monitor appears to have hard drive serial numbers labeled “Source” and “target”, a cue that the user copies/transferred data from one drive to another. The last note on the bottom appears to have a password written on it (“Purple793”), which could be useful for investigators when trying to access information. To collect this as evidence, photographs of both where on the desk the notes are would be taken along with closer photographs of what the notes have written on them. From there, the notes should be placed in a zip lock bag (protection from the elements), then labeled, documented, contained and transported in accordance with Chain of Custody procedures.
2 – Notebook – Similar to the sticky notes, the notebook can contain usernames, passwords or other relevant data. The notebooks has a few things written on it – “Ask Maria about ‘Safekeeping’”, which could lead investigators to an additional contact to question; “Check Storage”, which could involve the information contained on the hard drives physically on scene as well as the drives mentioned in one of the sticky notes; “Call Bob at Widgets, Inc.” – this informs investigators of an additional contact, perhaps at a competing organization. Collection of this evidence would be similar to that of the sticky notes; a series of photographs showing the location and writing, and proper bagging, tagging and chain of custody procedures.
3 – Business Cards – The business cards could contain the contact information for both “Maria” and “Bob at Widgets, Inc.”, allowing the investigators to circumvent digging and searching to contact these individuals. To collect this evidence, the location will need to be photographed as well as each individual card (more than likely all will be different). Once photographed, collect using the same procedures as the sticky notes and notepad.
“The first control could be to take pictures of the evidence's original state. This, of course, is only applicable for real evidence. Once you photograph and/or document the initial state of the entire scene, you can begin to collect evidence.” (Solomon, Rudolph, Tittel, Broom & Barrett, 2011) To stress the importance of controlling evidence and the collection of evidence, the authors stress photographing the scene prior to evidence collection. This is used to prove the location and state in which evidence was found, prior to closer inspection and collection.
4. (Looking at the Evidence Custody Document and item photographs, provided for Project 2 in the Course Content area) Read the Evidence Custody Document prepared by one of your co-workers, in which he is attempting to seize the three items pictured in the accompanying photos. Did your co-worker adequately describe each item? What could you add to the descriptions, and for which items (based on what you see in the photos), to make them more complete and serve as an example to your co-worker of what they SHOULD look like?
The co-worker could have provided additional details about the three items contained within the evidence/property custody document. First, the voice recorder details are lacking key aspects, such as the fact that the recorder is digital. There are large differences between digital recorders when compared to older tape recorders. Other details should include the model and serial numbers, storage medium (specify Micro SD), ports (USB, 3.5mm jack) and dimensions of the device. The Western Digital hard drive is lacking key details as well. Information such as model and serial numbers, type of drive (SSD, HDD, etc.), dimensions/form factor and indicators such as SATA and cache sizes would be relevant and useful information to have on the document. Lastly, the thumb drive’s description on the custody document is quite sufficient, but a few more details could prove useful. If it can be determined, the USB interface could be included (2.0, 3.0) as well as what the slide’s function (on the back) is. Is this a write lock or slider for the USB dongle? Unable to determine from the photograph.
Digital Voice Recorder, Olympus, unknown storage, Model Number: dm-620, Serial Number: Unknown, Grey, Plastic Construction, 6” x 3” x 0.75”, Micro SD Card Slot, Mini USB Port, Lanyard.
SATA Hard Disc Drive, Western Digital, 1 TB, 64 MB Cache, Model Number: WD10EARS-00MVWB0, Serial Number: WMAZA0202091, Silver and Black, Plastic and Metal Construction, Form Factor 3.5”, SATA and Power Supply Connections
Thumb Drive, PNY, 64 GB, Model Number: Unknown, Serial Number: Unknown, Grey and Black, Plastic and Metal Construction, Approximately 1” x 2.5” x. 0.5”, USB 3.0 (blue)
5. How should the items you collected as evidence be stored in your evidence room. Describe any environmental conditions or concerns for your evidence room (digital evidence can require some unique considerations!), as well any security procedures that should be in place.
Seized evidence should be kept in a locked, secure area with limited access at all times. While in storage, all evidence pertaining to a specific case should be kept together to avoid mixing up items, as well as kept away from interference devices or items that could damage the evidence (magnets, extreme temperature sources, humidity, etc.). As for digital evidence storage, investigators need to adopt Digital Evidence Bags (DEBs), which was developed to treat digital evidence in the same manner as physical evidence. “The concept was to develop a digital evidence container that would metaphorically mimic the familiar plastic evidence bag used by crime scene investigators to collect fibers, hair, blood, and other physical crime scene artifacts. Physical evidence containers are trusted because of a well-understood and practiced process called “chain-of-custody.” Simply put, this is a process used to maintain and document the chronological history of the evidence once in possession and secured.” (Hosmer, 2006).
References
Solomon, Michael G. & Rudolph, K. & Tittel, Ed & Broom, Neil& Barrett, Diane. ( © 2011). Computer forensics jumpstart, second edition. [Books24x7 version] Available from http://common.books24x7.com.ezproxy.umuc.edu/toc.aspx?bookid=41065
Schwerha IV, J. J. (2004). Cybercrime: Legal Standards Governing the Collection of Digital Evidence. Information Systems Frontiers, 6(2), 133-151.
Hosmer, C. (2006). DIGITAL EVIDENCE BAG. Communications Of The ACM, 49(2), 69-70. doi:10.1145/1113034.1113072