Chapter 1
Foundations of Digital Forensics
Objectives
On completion of this chapter, the student will
– Recognize that there will be a digital component in nearly every crime.
– Be able to list some of the ways criminals use technology.
– Recognize that increased use of technology increases evidence.
–
–Be aware of who is concerned with proper processing of digital evidence.
–Recognize how digital forensics has changed over time.
–
–
–ciple applies to digital forensics.
– Recognize the difference between class characteristics and individual characteristics.
– Recognize that evidence preservation is not an absolute.
Digital evidence has come to play some part in virtually every crime. It would, in fact, be
difficult to describe a crime scene that does not have a digital element. Criminals have always
found ways to use technology to their own ends, and digital technology is no different. There is
ital technology is used, the more likely that there will be resulting
digital evidence.
Digital evidence is the target of the forensic examiner, who pursues those digital elements that
support (or refute) a particular scenario. However, if the evidence is to be used in court, the
collection and processing must adhere to strict rules of evidence. Therefore, it is important that
everyone who is involved in the
understands the concepts of digital forensics and adheres to best practices and standard
procedures.
and then to verify or authenticate the data collected so that the examiner can state the copied data
is identical to the original. The accepted method
be covered in a later chapter.
Another issue is tracking the movement of the evidentiary data through the collection, storage,
and analyzing processes. It is
records when evidence changes hands, with whom, and why.
Challenges to the forensic process and digital evidence include:
1. The idea that the true data (magnetic patterns) is never observed, but rather, it is observed
through some level of abstraction (the hexadecimal view of a file).
2.
accident or error, that change the data.
Multiple Choice Questions
1. A valid definition of digital evidence is:
2. What are the three general categories of computer systems that can contain digital
evidence?
3. In terms of digital evidence, a hard drive is an example of:
4. In terms of digital evidence, a mobile telephone is an example of:
5. In terms of digital evidence, a Smart Card is an example of:
6. In terms of digital evidence, the Internet is an example of:
7. Computers can be involved in which of the following types of crime?
8. A logon record tells us that, at a specific time:
9. Cybertrails are advantageous because:
10. Private networks can be a richer source of evidence than the Internet because:
11. Due to caseload and budget constraints, often computer security professionals
attempt to limit the damage and close each investigation as quickly as possible.
Which of the following is NOT a significant drawback to this approach?
12. The criminological principle which states that, when anyone, or anything, enters a
crime scene he/she takes something of the scene with him/her, and leaves
something of himself/herself behind, is:
13. The author of a series of threatening e-mails c
is an example of:
14. Personal computers and networks are often a valuable source of evidence. Those
involved with _______ should be comfortable with this technology.
15. An argument for including computer forensic training computer security specialists is:
True or False Questions
1. Digital evidence is only useful in a court of law.
2. Attorneys and police are encountering progressively more digital evidence in their
work.
3. Video surveillance can be a form of digital evidence.
4. All forensic examinations should be performed on the original digital evidence.
6. Computers were involved in the investigations into both World Trade Center attacks.
7. Computer professionals who take inappropriate actions when they encounter child
lose their jobs or break the law.
8. Digital evidence is always circumstantial.
9. Digital evidence alone can be used to build a solid case.
10. Automobiles have computers that record data such as vehicle speed, brake status, and throttle
position when an accident occurs.
11. Computers can be used by terrorists to detonate bombs.
12. The aim of a forensic examination is to prove with certainty what occurred.
13. Even digital investigations that do not result in legal action can benefit from principles of
forensic science.
14. Forensic science is the application of science to investigation and prosecution of crime or to
the just resolution of conflict.
15. When a file is deleted from a hard drive, it can often be recovered.
Essay Questions
1. When criminals use computers, what advantages does this have from an investigative
standpoint?
2. What are the three general categories of computer systems that can contain digital evidence?
In each category, give a specific source of digital evidence that interests you and describe the
type of evidence that you might find.
3. Why is it important for computer security professionals to become familiar with digital
evidence?
4. At what point should computer security professionals stop handling digital evidence and
contact law enforcement?
5. What are the main challenges of investigating computer-related crime?
6. What is the difference between digital evidence, electronic evidence, and computer evidence?
7. Describe a case reported in the media or from personal experience that demonstrates how
digital evidence can be useful in the investigation of a violent crime or civil dispute.