Chapter 22
Applying Forensic Science to Networks
On completion of this chapter, the student will:
– Be aware of the need to gather intelligence about the target systems prior to the actual search.
– Recognize the similarity between the intelligence gathering in preparation for seizing and
conducting vulnerability assessments.
– Be aware of proper methods for preserving evidence on networked devices.
Chapter Summary
As discussed in earlier chapters, when handling digital evidence it is necessary to establish chain
of custody, document the state of items in situ, and take other steps to preserve the evidence so
that it can be authenticated at a later date. This chapter presents a methodology for processing
digital evidence and describes key concepts and their importance, including copying all data
Note: The practice of obtaining two separate copies of storage media using two different tools
may be prohibitively expensive in investigations involving hundreds of computers. In such
situations, to save time and resources, it may be necessary to make one copy and then a backup
Additionally, this chapter provides an overview of examination and analysis of digital evidence.
Some digital investigators begin a forensic examination by looking for items in places where
they are commonly found such as e-mail in their default location, or by searching for certain
and repeatable, digital investigators need a methodology for the examination step of the
Investigative Process presented in Chapter 4. This chapter takes concepts from forensic science
and demonstrates how they apply to the examination and analysis of digital evidence. Chapter 24
demonstrates how some of the examination tasks can be implemented using common tools,
providing the basics for an SOP for examining digital evidence on computers.
An effort is made to connect the applied material in this chapter with the investigative and
reconstruction processes described in earlier chapters. Additionally, this chapter familiarizes
students with various file types. Instructors are encouraged to explore other file types to give
Multiple Choice Questions
1. Preservation of digital evidence can involve which of the following?
2. A forensic image of a drive preserves which of the following?
3. Examination of digital evidence includes (but is not limited to) which of the following
activities?
4. Analysis of digital evidence includes which of the following activities?
5. On a Windows machine, the MD
6. Evidence can be related to its source in which of the following ways?
7. Different types of analysis include which of the following?
8. When a website is under investigation, before obtaining authorization to seize the
systems it is necessary to:
9. Which of the following is NOT an information gathering process?
10. Unlike law enforcement, system administrators are permitted to ________ on their
network when it is necessary to protect the network and the data it contains.
11. Although it was not designed with evidence collection in mind, _______can still be
useful for examining network traffic.
12. Issues to be aware of when connecting to a computer over a network and collecting
information include:
13. Occasionally, an intrusion detection system may trigger an alarm caused by an innocent
packet that coincidentally contains intrusion class characteristics. This type of alert is
called:
14. Information security professionals submit samples of log files associated with certain
intrusion tools to help others detect attacks on the mailing lists at:
15. Which of the following are situations where a bitstream copy may not be viable?
True or False Questions
1. When a computer contains digital evidence, it is always advisable to turn it off
immediately.
2. A forensic image of a hard disk drive preserves the partition table.
3. All forensic tools acquire digital evidence from storage media in the same way.
4. It is not necessary to sanitize/wipe a hard drive purchased directly from a manufacturer.
5. Chain of custody enables anyone to determine where a piece of evidence has been, who
handled it when, and what was done to it since it was seized.
6. No two files can have the same MD5 value.
7. The chance of two different files having the same MD5 value is roughly one in 340
billion billion billion billion which is approximately equivalent to winning 30,000 billion
billion billion first prizes in the Hong Kong Mark Si
which randomly picks 6 numbers from 1 to 47 with a one in 10,737,573 chance of
winning first prize.
8. After the MD5 value of a piece of digital evidence has been calculated, any change in
that piece of evidence can be detected.
9. When drawing up an affidavit for a warrant, it is important to specifically mention all
desired digital evidence.
10. When seeking authorization to search a network and digital evidence that may exist in
more than one jurisdiction it is not necessary to obtain a search warrant for each location.
11. Digital investigators should remember that evidence can reside in unexpected places,
such as network routers.
12. Active monitoring is time consuming, invasive, and costly and should only be used as a
last resort.
13. A digital evidence class characteristic is similar to toolmark analysis in the physical
world.
14. TCP/IP network traffic never contains useful class characteristics.
15. It is not possible to recover deleted system or network log files.
Discussion Questions
1. If you are investigating a homicide and, while executing a search warrant, you find a
s to contain child pornography, what would
you do?
2. Other than verifying the integrity of a file, how can the MD5 value of a file be useful?
3. What are the limitations of the message digest of digital evidence?
4. What does a digital signature tell you?
5. What is the difference between a class characteristic and an individualizing
characteristic? Give examples of each involving digital evidence.
6. How would you search for all image files on a disk? Explain the rationale of your
approach.
Scenario
Suppose that your immediate area is a crime scene. What potential sources of digital
evidence do you find? For two of these items, describe how you would preserve and