Open main menu
Home
Random
Recent changes
Special pages
Community portal
Preferences
About Wikipedia
Disclaimers
Incubator escapee wiki
Search
User menu
Talk
Dark mode
Contributions
Create account
Log in
Editing
Computer forensics
Warning:
You are not logged in. Your IP address will be publicly visible if you make any edits. If you
log in
or
create an account
, your edits will be attributed to your username, along with other benefits.
Anti-spam check. Do
not
fill this in!
{{short description|Branch of digital forensic science}} [[File:Computer Investigations and Analysis Division (39033998171).jpg|thumb|A forensic expert examining a mobile device that was seized during an investigation]] [[File:PersonalStorageDevices.agr.jpg|thumb|Media types used for computer forensic analysis: a [[Fujifilm FinePix]] [[digital camera]], two [[flash memory]] cards, a [[USB flash drive]], a 5GB [[iPod]], a [[CD-R]] or [[DVD recordable]], and a [[Mini CD]].]] {{ForensicScience|digital}} '''Computer forensics''' (also known as '''computer forensic science''')<ref name="noblett"/> is a branch of [[digital forensics|digital forensic science]] pertaining to evidence found in computers and digital [[storage media]]. The goal of computer forensics is to examine digital media in a forensically sound manner with the aim of identifying, preserving, recovering, analyzing, and presenting facts and opinions about the digital information. Although it is most often associated with the investigation of a wide variety of [[computer crime]], computer forensics may also be used in civil proceedings. The discipline involves similar techniques and principles to [[data recovery]], but with additional guidelines and practices designed to create a legal [[audit trail]]. Evidence from computer forensics investigations is usually subjected to the same guidelines and practices as other digital evidence. It has been used in a number of high-profile cases and is accepted as reliable within U.S. and European court systems. ==Overview== In the early 1980s, personal computers became more accessible to consumers, leading to their increased use in criminal activity (for example, to help commit [[fraud]]). At the same time, several new "computer crimes" were recognized (such as [[Software cracking|cracking]]). The discipline of computer forensics emerged during this time as a method to recover and investigate [[digital evidence]] for use in court. Since then, computer crime and computer-related crime has grown, with the FBI reporting a suspected 791,790 internet crimes in 2020, a 69% increase over the amount reported in 2019.<ref>{{cite web|url=https://www.ic3.gov/Media/PDF/AnnualReport/2020_IC3Report.pdf |title=2020 Internet Crime Report |website=IC3.gov}}</ref><ref>{{cite web|title=IC3 Releases 2020 Internet Crime Report |url=https://www.fbi.gov/news/press-releases/fbi-releases-the-internet-crime-complaint-center-2020-internet-crime-report-including-covid-19-scam-statistics |website=Federal Bureau of Investigation}}</ref> Today, computer forensics is used to investigate a wide variety of crimes, including [[child pornography]], fraud, [[espionage]], [[cyberstalking]], murder, and rape. The discipline also features in civil proceedings as a form of information gathering (e.g., [[Electronic discovery]]). Forensic techniques and expert knowledge are used to explain the current state of a ''digital artifact'', such as a computer system, storage medium (e.g., [[hard disk drive|hard disk]] or [[CD-ROM]]), or an [[electronic document]] (e.g., an email message or JPEG image).<ref name="cf-education"/> The scope of a forensic analysis can vary from simple [[information retrieval]] to reconstructing a series of events. In a 2002 book, ''Computer Forensics'', authors Kruse and Heiser define computer forensics as involving "the preservation, identification, extraction, documentation and interpretation of computer data".<ref name="kruse"/> They describe the discipline as "more of an art than a science," indicating that forensic methodology is backed by flexibility and extensive [[domain knowledge]]. However, while several methods can be used to extract evidence from a given computer, the strategies used by law enforcement are fairly rigid and lack the flexibility found in the civilian world.<ref name="gunsch"/> === Cybersecurity === Computer forensics is often confused with [[cybersecurity]]. Cybersecurity focuses on prevention and protection, while computer forensics is more reactionary and active, involving activities such as tracking and exposing. System security usually encompasses two teams: cybersecurity and computer forensics, which work together. A cybersecurity team creates systems and programs to protect data; if these fail, the computer forensics team recovers the data and investigates the intrusion and theft. Both areas require knowledge of computer science.<ref>{{cite web|title=What Is Computer Forensics? |url=https://www.wgu.edu/blog/computer-forensics2004.html |website=Western Governors University}}</ref> === Computer-related crimes === Computer forensics are used to convict those involved in physical and digital crimes. Some of these computer-related crimes include interruption, interception, copyright infringement, and fabrication. ''Interruption'' relates to the destruction and stealing of computer parts and digital files. ''Interception'' is the unauthorized access of files and information stored on technological devices.<ref>{{cite book|last1=Kruse II|first1=Warren G.|last2=Heiser|first2=Jay G.|title=Computer Forensics: Incident Response Essentials |publisher=Pearson Education |date=2001 |isbn=978-0-672-33408-5}}</ref> [[Copyright infringement]] refers to using, reproducing, and distributing copyrighted information, including software piracy. ''Fabrication'' involves accusing someone of using false data and information inserted into the system through an unauthorized source. Examples of interceptions include the Bank NSP case, Sony.Sambandh.com case, and business email compromise scams.<ref>{{cite book|last=Sabry|first=Fouad|title=Digital Forensics: How digital forensics is helping to bring the work of crime scene investigating into the real world |publisher=One Billion Knowledgeable |date=2022 |isbn=978-1-792-30942-6}}</ref> ==Use as evidence== In court, computer forensic evidence is subject to the usual requirements for [[digital evidence]]. This requires that information be authentic, reliably obtained, and admissible.<ref name="theadam"/> Different countries have specific guidelines and practices for evidence recovery. In the [[United Kingdom]], examiners often follow [[Association of Chief Police Officers]] guidelines that help ensure the authenticity and integrity of evidence. While voluntary, the guidelines are widely accepted in British courts. Computer forensics has been used as evidence in [[criminal law]] since the mid-1980s. Some notable examples include:<ref name="casey"/> * [[Dennis Rader|BTK Killer]]: Dennis Rader was convicted of a string of serial killings over sixteen years. Towards the end of this period, Rader sent letters to the police on a floppy disk.<ref>{{cite web|title=The Capture of Serial Killer Dennis Rader, BTK|url=https://www.psychologytoday.com/za/blog/wicked-deeds/202302/the-capture-of-serial-killer-dennis-rader-btk |website=Psychology Today}}</ref> [[Metadata]] within the documents implicated an author named "Dennis" at "Christ Lutheran Church," helping lead to Rader's arrest.<ref>{{cite web|last=Dooley|first=Sean|title=BTK serial killer's daughter: 'We were living our normal life... Then everything upended on us' |url=https://abcnews.go.com/US/btk-serial-killers-daughter-living-normal-life-upended/story?id=60428529 |website=ABC News}}</ref> * [[Joseph Edward Duncan]]: A spreadsheet recovered from Duncan's computer contained evidence showing him planning his crimes. Prosecutors used this to demonstrate [[Premeditated murder|premeditation]] and secure the [[Capital punishment|death penalty]].<ref name="handbook"/> * [[Sharon Lopatka]]: Hundreds of emails on Lopatka's computer led investigators to her killer, Robert Glass.<ref name="casey"/> * [[Corcoran Group]]: In this case, computer forensics confirmed parties' duties to preserve [[digital evidence]] when [[litigation]] had commenced or was reasonably anticipated. Hard drives were analyzed, though the expert found no evidence of deletion, and evidence showed that the defendants intentionally destroyed emails.<ref name="casey"/> * [[Dr. Conrad Murray]]: Dr. Conrad Murray, the doctor of [[Michael Jackson]], was convicted partially by digital evidence, including medical documentation showing lethal amounts of [[propofol]]. * [[Mark Twitchell]], also known as the "Dexter Killer," Twitchell was convicted with the help of a deleted document recovered from his laptop titled "SKConfessions." This file, which detailed his criminal activities, served as a key piece of evidence in the case. == Forensic process == {{Main article|Digital forensic process}} [[File:Portable_forensic_tableau.JPG|thumb|A portable Tableau [[Forensic disk controller|write blocker]] attached to a [[Hard disk drive|hard drive]]]] Computer forensic investigations typically follow the standard digital forensic process, consisting of four phases: acquisition, examination, analysis, and reporting. Investigations are usually performed on static data (i.e., [[Disk imaging#Hard drive imaging|acquired images]]) rather than "live" systems. This differs from early forensic practices, when a lack of specialized tools often required investigators to work on live data. === Computer forensics lab === The computer forensics lab is a secure environment where electronic data can be preserved, managed, and accessed under controlled conditions, minimizing the risk of damage or alteration to the evidence. Forensic examiners are provided with the resources necessary to extract meaningful data from the devices they examine.<ref>{{Cite web |title=Chapter 3: Computer Forensic Fundamentals - Investigative Computer Forensics: The Practical Guide for Lawyers, Accountants, Investigators, and Business Executives [Book] |url=https://www.oreilly.com/library/view/investigative-computer-forensics/9781118235225/OEBPS/9781118235225_epub_c03.htm |access-date=2022-03-04 |website=www.oreilly.com |language=en}}</ref> === Techniques === Various techniques are used in computer forensic investigations, including: ; Cross-drive analysis : This technique correlates information found on multiple [[Hard drive|hard drives]] and can be used to identify [[social networks]] or detect anomalies.<ref>{{Cite journal |last=Garfinkel |first=Simson L. |date=2006-09-01 |title=Forensic feature extraction and cross-drive analysis |journal=Digital Investigation |series=The Proceedings of the 6th Annual Digital Forensic Research Workshop (DFRWS '06) |language=en |volume=3 |pages=71β81 |doi=10.1016/j.diin.2006.06.007 |issn=1742-2876 |doi-access=free}}</ref><ref>{{Cite journal |last1=David |first1=Anne |last2=Morris |first2=Sarah |last3=Appleby-Thomas |first3=Gareth |date=2020-08-20 |title=A Two-Stage Model for Social Network Investigations in Digital Forensics |url=https://dspace.lib.cranfield.ac.uk/bitstream/1826/15732/4/Two-Stage_Model_for_Social_Network_Investigations_in_Digital_Forensics-2020.pdf |journal=Journal of Digital Forensics, Security and Law |volume=15 |issue=2 |doi=10.15394/jdfsl.2020.1667 |issn=1558-7223 |s2cid=221692362 |doi-access=free}}</ref> ; Live analysis : The examination of computers from within the operating system using forensic or existing [[sysadmin tools]] to extract evidence. This technique is particularly useful for dealing with [[Encrypting File System|encrypting file systems]] where encryption keys can be retrieved, or for imaging the logical hard drive volume (a live acquisition) before shutting down the computer. Live analysis is also beneficial when examining networked systems or cloud-based devices that cannot be accessed physically.<ref>https://espace.curtin.edu.au/bitstream/handle/20.500.11937/93974/Adams%20RB%202023%20Public.pdf?sequence=1&isAllowed=y</ref> ; Deleted files : A common forensic technique involves recovering deleted files. Most [[Operating system|operating systems]] and [[File system|file systems]] do not erase the physical file data, allowing investigators to reconstruct it from the physical [[Disk sector|disk sectors]]. Forensic software can "carve" files by searching for known file headers and reconstructing deleted data. ; [[Stochastic forensics]] : This method leverages the stochastic properties of a system to investigate activities without traditional digital artifacts, often useful in cases of [[data theft]]. ; [[Steganography]] : Steganography involves concealing data within another file, such as hiding illegal content within an image. Forensic investigators detect steganography by comparing file hashes, as any hidden data will alter the hash value of the file. === Mobile device forensics === ; Phone logs : Phone companies typically retain logs of received calls, which can help create timelines and establish suspects' locations at the time of a crime.<ref name=":02"/> ; Contacts : Contact lists are useful in narrowing down suspects based on their connections to the victim.<ref name=":02"/> ; Text messages : Text messages contain timestamps and remain in company servers, often indefinitely, even if deleted from the device. These records are valuable evidence for reconstructing communication between individuals.<ref name=":02"/> ; Photos : Photos can provide critical evidence, supporting or disproving alibis by showing the location and time they were taken.<ref name=":02"/> ; Audio recordings : Some victims may have recorded pivotal moments, capturing details like the attacker's voice, which could provide crucial evidence.<ref name=":02"/> === Volatile data === Volatile data is stored in memory or in transit and is lost when the computer is powered down. It resides in locations such as registries, cache, and RAM. The investigation of volatile data is referred to as "live forensics." When seizing evidence, if a machine is still active, volatile data stored solely in [[Random access memory|RAM]] may be lost if not recovered before shutting down the system. "Live analysis" can be used to recover RAM data (e.g., using Microsoft's [[COFEE]] tool, WinDD, [[WindowsSCOPE]]) before removing the machine. Tools like CaptureGUARD Gateway allow for the acquisition of physical memory from a locked computer.{{Citation needed|reason=Add a source describing which versions of Windows CaptureGUARD can unlock and under which circumstances.|date=December 2020}} RAM data can sometimes be recovered after power loss, as the electrical charge in memory cells dissipates slowly. Techniques like the [[cold boot attack]] exploit this property. Lower temperatures and higher voltages increase the chance of recovery, but it is often impractical to implement these techniques in field investigations. Tools that extract volatile data often require the computer to be in a forensic lab to maintain the chain of evidence. In some cases, a live desktop can be transported using tools like a [[mouse jiggler]] to prevent sleep mode and an [[uninterruptible power supply]] (UPS) to maintain power. Page files from file systems with journaling features, such as [[NTFS]] and [[ReiserFS]], can also be reassembled to recover RAM data stored during system operation. === Analysis tools === {{see also|List of digital forensics tools}} Numerous open-source and commercial tools exist for computer forensics. Common forensic analysis includes manual reviews of media, Windows registry analysis, password cracking, keyword searches, and the extraction of emails and images. Tools such as [[Autopsy (software)]], [[Belkasoft Evidence Center X]], [[Forensic Toolkit]] (FTK), and [[EnCase]] are widely used in digital forensics. == Professional education and careers == === Digital forensics analyst === A digital forensics analyst is responsible for preserving digital evidence, cataloging collected evidence, analyzing evidence relevant to the ongoing case, responding to cyber breaches (often in a corporate context), writing reports containing findings, and testifying in court.<ref>{{Cite web |date=2022-12-28 |title=What Is a Digital Forensic Analyst? |url=https://www.eccouncil.org/cybersecurity-exchange/computer-forensics/what-is-digital-forensic-analyst/ |url-status=live |archive-url=https://web.archive.org/web/20221128021454/https://www.eccouncil.org/cybersecurity-exchange/computer-forensics/what-is-digital-forensic-analyst/ |archive-date=2022-11-28 |access-date=2022-12-28 |website=EC Council}}</ref> A digital forensic analyst may also be referred to as a computer forensic analyst, digital forensic examiner, cyber forensic analyst, forensic technician, or other similarly named titles, though these roles perform similar duties.<ref>{{Cite web |date=2022-12-28 |title=CISA Cyber Defense Forensics Analyst |url=https://www.cisa.gov/cyber-defense-forensics-analyst |url-status=live |archive-url=https://web.archive.org/web/20221105031326/https://www.cisa.gov/cyber-defense-forensics-analyst |archive-date=2022-11-05 |access-date=2022-12-28 |website=Cybersecurity & Infrastructure Security Agency (CISA)}}</ref> === Certifications === Several computer forensics certifications are available, such as the ISFCE [[Certified computer examiner|Certified Computer Examiner]], Digital Forensics Investigation Professional (DFIP), and IACRB Certified Computer Forensics Examiner. The top vendor-independent certification, particularly within the EU, is the Certified Cyber Forensics Professional (CCFP).<ref>{{cite web |title=Cybersecurity Certification |url=https://www.isc2.org/Certifications/CISSP# |access-date=2022-11-18 |website=isc2.org}}</ref><ref>{{cite web |title=CCFP Salaries surveys |url=https://www.itjobswatch.co.uk/jobs/uk/ccfp.do |url-status=dead |archive-url=https://web.archive.org/web/20170119005256/http://www.itjobswatch.co.uk/jobs/uk/ccfp.do |archive-date=2017-01-19 |access-date=2017-06-15 |publisher=ITJobsWatch}}</ref> Many commercial forensic software companies also offer proprietary certifications.<ref>{{cite web |title=X-PERT Certification Program |url=http://www.x-pert.eu/ |access-date=2015-11-26 |publisher=X-pert.eu}}</ref> ==See also== * [[Certified Forensic Computer Examiner]] * [[Anti-computer forensics|Counter forensics]] * [[Cryptanalysis]] *[[Cyber attribution]] * [[Data remanence]] * [[Disk encryption]] * [[Encryption]] * [[Hidden file and hidden directory]] * [[Information technology audit]] * [[MAC times]] * [[Steganalysis]] * ''[[United States v. Arnold]]'' == References == {{reflist|refs= <ref name="theadam">{{cite web|author=Adams, R.|title='The Advanced Data Acquisition Model (ADAM): A process model for digital forensic practice|year=2012|url=https://www.researchgate.net/publication/258224615}}</ref> <ref name="casey">{{cite book|last=Casey|first=Eoghan|title=Digital Evidence and Computer Crime, Second Edition|year=2004|publisher=Elsevier|isbn=978-0-12-163104-8|url=https://books.google.com/books?id=Xo8GMt_AbQsC}}</ref> <ref name="noblett">{{cite web|title=Recovering and examining computer forensic evidence|url=https://www.fbi.gov/about-us/lab/forensic-science-communications/fsc/oct2000/computer.htm|access-date=26 July 2010|author=Michael G. Noblett|author2=Mark M. Pollitt |author3=Lawrence A. Presley |date=October 2000}}</ref> <ref name="cf-education">{{cite journal |last1=Yasinsac |first1=A. |last2=Erbacher |first2=R.F. |last3=Marks |first3=D.G. |last4=Pollitt |first4=M.M. |last5=Sommer |first5=P.M. |title=Computer forensics education |journal=IEEE Security & Privacy |date=July 2003 |volume=1 |issue=4 |pages=15β23 |doi=10.1109/MSECP.2003.1219052}}</ref> <ref name="handbook">{{cite book|last=Various|title=Handbook of Digital Forensics and Investigation|year=2009|publisher=[[Academic Press]]|isbn=978-0-12-374267-4|page=567|url=https://books.google.com/books?id=xNjsDprqtUYC|editor=Eoghan Casey|access-date=27 August 2010}}</ref> <ref name="kruse">{{cite book|title=Computer forensics: incident response essentials|year=2002|publisher=Addison-Wesley|isbn=978-0-201-70719-9|page=[https://archive.org/details/computerforensic0000krus/page/392 392]|url=https://archive.org/details/computerforensic0000krus|url-access=registration|author=Warren G. Kruse|author2=Jay G. Heiser|access-date=6 December 2010}}</ref> <ref name="gunsch">{{cite web|author=Gunsch, G|title=An Examination of Digital Forensic Models|date=August 2002|url=http://www.utica.edu/academic/institutes/ecii/publications/articles/A04A40DC-A6F6-F2C1-98F94F16AF57232D.pdf}}</ref> <ref name=":02">{{Cite book |last=Pollard |first=Carol |title=Computer Forensics for Dummies |publisher=John Wiley & Sons, Incorporated |year=2008 |isbn=9780470434956 |pages=219β230 |language=English}}</ref> }} ==Further reading== * A Practice Guide to Computer Forensics, First Edition (Paperback) by David Benton (Author), Frank Grindstaff (Author) * {{cite journal |last=Casey |first=Eoghan |author2=Stellatos, Gerasimos J. |year=2008 |title=The impact of full disk encryption on digital forensics |journal=Operating Systems Review |volume=42 |issue=3 |pages=93β98 |doi=10.1145/1368506.1368519 |citeseerx=10.1.1.178.3917 |s2cid=5793873 }} * {{cite journal |url=http://pages.cs.wisc.edu/~huangyz/cvpr08_Huang.pdf |title=Demosaicking recognition with applications in digital photo authentication based on a quadratic pixel correlation model |author1=YiZhen Huang |author2=YangJing Long |journal=Proc. IEEE Conference on Computer Vision and Pattern Recognition |year=2008 |pages=1β8 |access-date=2009-12-18 |archive-url=https://web.archive.org/web/20100617081150/http://pages.cs.wisc.edu/~huangyz/cvpr08_Huang.pdf |archive-date=2010-06-17 |url-status=dead }} * Incident Response and Computer Forensics, Second Edition (Paperback) by Chris Prosise (Author), Kevin Mandia (Author), Matt Pepe (Author) "Truth is stranger than fiction..." (more) * {{cite book |author1=Ross, S. |author2=Gow, A. | year = 1999| isbn = 978-1-900508-51-3 | title = Digital archaeology? Rescuing Neglected or Damaged Data Resources | url = http://www.ukoln.ac.uk/services/elib/papers/supporting/pdf/p2.pdf | publisher = British Library and Joint Information Systems Committee | location = Bristol & London }} * {{cite book|title=Computer and intrusion forensics|year=2003|publisher=Artech House|isbn=978-1-58053-369-0|page=395|url=https://books.google.com/books?id=z4GLgpwsYrkC|author=George M. Mohay}} * {{cite book|title=System Forensics, Investigation, and Response|year=2013|publisher=Jones & Bartlett|isbn=978-1284031058|page=318|url=http://www.jblearning.com/catalog/9780763791346/|author=Chuck Easttom|access-date=2013-09-23|archive-url=https://web.archive.org/web/20130614163726/http://www.jblearning.com/catalog/9780763791346/|archive-date=2013-06-14|url-status=dead|author-link=Chuck Easttom}} ===Related journals=== * ''IEEE Transactions on Information Forensics and Security'' * ''Journal of Digital Forensics, Security and Law'' * ''International Journal of Digital Crime and Forensics'' * ''Journal of Digital Investigation'' * ''International Journal of Digital Evidence'' * ''International Journal of Forensic Computer Science'' * ''Journal of Digital Forensic Practice'' * ''Cryptologia'' * ''Small Scale Digital Device Forensic Journal'' {{Digital forensics}} {{Authority control}} {{DEFAULTSORT:Computer Forensics}} [[Category:Computer forensics| ]] [[Category:Computer security procedures]] [[Category:Information technology audit]]
Edit summary
(Briefly describe your changes)
By publishing changes, you agree to the
Terms of Use
, and you irrevocably agree to release your contribution under the
CC BY-SA 4.0 License
and the
GFDL
. You agree that a hyperlink or URL is sufficient attribution under the Creative Commons license.
Cancel
Editing help
(opens in new window)
Pages transcluded onto the current version of this page
(
help
)
:
Template:Authority control
(
edit
)
Template:Citation needed
(
edit
)
Template:Cite book
(
edit
)
Template:Cite journal
(
edit
)
Template:Cite web
(
edit
)
Template:Digital forensics
(
edit
)
Template:ForensicScience
(
edit
)
Template:Main article
(
edit
)
Template:Reflist
(
edit
)
Template:See also
(
edit
)
Template:Short description
(
edit
)