Research paper
COMPUTER FORENSICS 1
COMPUTER FORENSICS 4
COMPUTER FORENSICS
Student’s Name
Date of Submission
1.
What permissions / authorities should you have before you search Mr. Yourprop’s former Company X work area and how would you document that authority
Before carrying the search I have options of doing a warrantless search or getting either a warrant or subpoena if Mr.Yourprop does not voluntarily surrender the requirements. A court order compels an individual or organization to surrender evidence. A subpoena would be appropriate if Mr. Your prop is not in a position to delete or interfere with information/evidence. If I am working on behalf of the organization not as an agent to the Police then I will not be bound by the Fourth Amendments which states that government officials and police officers are required by law to get a warrant of search if not done this way the evidence gotten will be inadmissible before a court of law. A forensic computer analyst needs to know where he falls, it is taken that he is an agent of police if he is doing a search on their behalf. However a warrantless search does not is justifiable if it does not violate the Fourth Amendment on two conditions; if it does not violate a reasonable expectation of privacy. This subjectively means that a court will decide if the item of search is within reasonable expectation of privacy. Courts have taken purses and cases to be personal property even if an employee comes with them to work, flash disks are enclosed therefore it is generally taken by courts to mean there is a reasonable expectation of privacy therefore evidence gotten by this warrantless search will not be admissible in court.
It is therefore important before a search one to seek a subpoena from courts to compel an individual or organization to surrender evidence. If you are a forensic detective working with police or as an agent sent to collect information then you will need a court order before starting a search. Our case study is an investigatory search for evidence which together with non investigatory work related search to employee misfeasance (non investigatory search is only permissible if does not violate a person’s reasonable expectation of privacy) according to Supreme court qualifies it as a warrantless search that is constitutional.
2. Looking at photo of Mr. Yourprop work area in Project 2 Corse Content area. Identify 3 potential items of digital evidence you see in photo. Explain potential use of each item, how you would collect that item as evidence (digital forensics best practices)
A lot of digital evidence can be obtained from data to be recovered from the flash drive, desktop and external hard disk. In this investigation the hard disk and the flash drive will provide information in digital form and may have images or files that can be used as evidence. The desktop is also very important in collection of evidences however the collection has to be very systematic. An ARP will aide in knowing which other computer it the suspect’s computer has been in contact with.
It is advised to start with the most volatile pieces of information as we move our way down to the more stable ones, this is because volatile information are temporary and may not last especially after a machine is shut down for example an application that was running in the background. Pictures have to be taken prior to doing anything this will help in evidence analysis and ensure admissibility in court if you document all your steps and precautions taken to preserve integrity of any evidence. In our case I would start by noting the systems date, time and applications. More volatile evidences such as information is register’s cache, routing table and ARP cache, process table, kernel statistics, memory temporary files. Once I am done with the very volatile evidence, I would concentrate on getting an image of the external disk, internal disk. This stores an exact replica of the drives as they are at the time. It is important to image before one attempts to analyze anything. Information concerning remote logging, physical configuration and network topology is advised to be done after getting an image of the drive.
3. Photo of Mr. Youpop work area identify 3 potential non digital evidence explain potential use that each item would be to your incidence and collection of that item as evidence.
Non digital evidence include handwritten notes eg notebook pieces of paper. Written evidence eg printed reports, data in log file
Looking at his work area non digital evidence that should be of concern are sticky notes, note book and file stashed above the desktop in a partition directly above the desktop. These types of evidence may give information directly related to the case/investigation or give information which will help the investigator to get an insight into the subject’s objective. In other words they may help you as an investigator to understand the subject more and we know empathy is a critical part of figuring out any case.
Before doing anything I would take pictures of all these non digital evidences, generally one picture must be taken in a way that what is written is clearly seen while the other is taken in relation to its position in the work area. After taking pictures I would then take my notebook and note everything down for later use during investigation. It is also important to document every step I take to minimize change of evidence this prevents any evidence being deemed inadmissible before court. For example before analyzing a piece of paper closely I would take a picture, while wearing gloves I would the put the piece of paper into an airtight plastic bag then I closely analyze it. If this is documented and at a later time a fingerprint of a suspected point man for the competition is found together with Mr. Yourpop’s then my evidence will stand before a court of law.
4. Looking at evidence custody document and item photograph provided in Project 2 read the evidence custody document prepared by one of your coworkers. Did your coworker adequately describe each item? What could you add to the description?
He did not adequately describe the items. It is important to try and write everything you can see so as to capture all evidence even those you don’t know yet. His was like a summary stating what was found. In description writing you write everything noticeable
The voice recorder obtained was small size 5cm by 3 cm by 1 cm dimension, it is silver in color. Has a USB mini-b (5-Pin) male port on the side for connection to a computer. Uses direct current from a battery located in the back and the storage mechanism is a removable SD Micro storage card. The hard disk obtained was size 8cm by 6 cm by 3cm and had no cover. On one side it is covered with a metal while the other side is partially covered almost three quarters with a green plastic casing the other quarter is not covered and open circuits can be seen. It is a 1 TB Western Digital drive using SATA filing system serial number WMAZ0202091 model WDI0EARS-00MVWBO. This drive had a sticker on its side which is covered by metal; the sticker has been torn so no information can be obtained from it. Flash drive obtained has a retractable black top and the bottom part is greenish in color. It is 64 GD
5. How should the items you collect as evidence be stored in your evidence room. Describe any environmental condition/ concerns for your evidence room as well as any security procedures
Evidence should maintain the same integrity once in. this can be attained by ensuring the evidence cannot modified in any way during its storage. For example read only image using a software write block ensures no write impacts a mounted volume. Hardware write blocker to block physical connections for path to the disk, this is the most secure way of ensuring data integrity. Security of this room has to be without compromise, ideally evidence rooms are to be specific entry only with only one person at a time entering, this creates accountability in case of any damage or corruption of evidence. It is also advised that guard must be stationed at the door and manner of entry should be using fingerprints or key card this limits a situation where the guard can be compromised to open the door or open the door himself and claim someone else who is innocent did it.
Generally method or procedure of ensuring safety and integrity of an evidence will be determined by the type of evidence itself. For example an evidence in form of a tape recording, in the storage room it is advised the room to be dry as water may spoil it, dust free, free from extremes such as too much heat or cold and most importantly be kept away from any magnetic material. However when storing a note written by the suspect then magnets will no longer be an issue however humidity is now a new issue which could lead to this evidence being inadmissible in court. It is therefore important before storage to do a research and understand the workings of a piece of evidence if it’s a machine what can make it spoil for example water may short circuit it. After knowing and thinking of all possible threats then you create a localized area in the evidence room where you ensure the right environmental condition is achieved.