Chapter 22
Applying Forensic Science to Networks
On completion of this chapter, the student will:
– Be aware of the need to gather intelligence about the target systems prior to the actual search.
– Recognize the similarity between the intelligence gathering in preparation for seizing and
conducting vulnerability assessments.
– Be aware of proper methods for preserving evidence on networked devices.
Chapter Summary
As discussed in earlier chapters, when handling digital evidence it is necessary to establish chain
of custody, document the state of items in situ, and take other steps to preserve the evidence so
that it can be authenticated at a later date. This chapter presents a methodology for processing
digital evidence and describes key concepts and their importance, including copying all data
Note: The practice of obtaining two separate copies of storage media using two different tools
may be prohibitively expensive in investigations involving hundreds of computers. In such
situations, to save time and resources, it may be necessary to make one copy and then a backup
Additionally, this chapter provides an overview of examination and analysis of digital evidence.
Some digital investigators begin a forensic examination by looking for items in places where
they are commonly found such as e-mail in their default location, or by searching for certain