Computer Forensics

profilehelpneeded2016
20160304225251gbor_emeline_outlineword_1.odt

Outline

  1. Computer Forensics

  1. What is computer forensics?

  1. The preservation, identification, extraction, analysis, and interpretation of digital data, with the expectation that the findings will be introduced in a court of law.

  1. Where to find computer evidence?

  1. Computers, laptops, network equipment(hubs and switches)

  2. External media: CD, floppy disk, USB thumb drive

  3. Paper notes, documentation and manuals, post-it notes.

  1. When is computer forensics used?

  1. Law enforcement investigations

  2. health care systems

  1. What is forensic imaging?

  1. Obtained by a method which does not, in any way, alter any data on the drive being duplicated

  2. Duplicate must contain a copy of every bit, byte, and sector of the source drive

  3. Duplicate will not contain any data except filler characters (for bad areas of the media) other than that which was copied from the source media

  4. Accurate, verifiable, reproducible

  1. Becoming an Computer Forensic Expert

  1. Computer forensic examiner

  1. How do you become an examiner?

  1. schooling

  1. Duration of schooling

  2. Credentials needed

  1. What can the examiner find?

  1. Deleted files

  2. Enhanced metafiles (previously printed files)

  3. Text fragments

  4. Enhanced metadata (embedded information)

  5. Internet usage information (history)

  1. Role of the computer forensic examiner during investigations

  1. Collection of evidence

  2. Processing of evidence

  1. Conclusion

  1. Computer forensics future

  1. Increased numbers of perpetrator arrests and successful cases closed

  2. Progression of technological integration

  3. Case agent must work closely with examiners

  4. Forensic examiners must look beyond the single file

  5. Metadata can be critical to establishing user attribution

  6. Even if evidence itself has been deleted/ destroyed, numerous artifacts

I choose to do my research paper on computer forensic because I thought it was a very interest topic and also I wanted to learn and understand how forensics collect and gather their information when they are investigating a crime scenes etc.

COMPUTER FORENSICS

GBOR_EMELINE_OUTLINEWORD