First Steps for any Incident:
Four Stages of Investigation:
1) Collection
2) Examination
3) Analysis
4) Report & Statement
Mirror Image Copying Process:
1) Use a write-blocking device
2) Use cryptographic hash functions and check-sums to ensure integrity
3) After copying, has values and digital signatures can be verified later
Creating mirror images may require a large selection of specialised devices and equipment…
Forensic Image Tools:
Problems in Evidence Collection:
Maintaining Continuity of Evidence:
Ensuring evidence remains admissible.
• Everything in Court must be proved
• Every part of the structure of a disk is evidence
• If tampered with or accessed except under provable circumstances not affecting content, integrity as evidence is lost
Active (live) systems present a number of challenges and opportunities…
Both potentially rich sources of additional evidence, but also risks of losing data particularly to counter-forensic techniques
Copying Volatile Memory Contents Challenge Solutions:
Key Factors Contributing to Fragility of Digital Evidence and Difficulties in Accessing:
Strict Procedures Followed For Storage Media:
• Static electricity must be discharged
• The host system must be switched off
• Computer and configuration must be photographed
• Manufacturer, model & serial numbers noted
• Covers must be removed
• Internal configuration of the system must be photographed
• Storage devices can now be removed from the enclosure
• Device must also itself be photographed
• Manufacturer and other data of device noted
• Any configuration items noted
• Device placed in anti-static bag
Anti-static bag placed in envelope and sealed with tape
• Each aperture of the envelope signed and dated
• Witness must sign and date apertures
• Envelope stored in safe together with a record entry to the safe
Examination Phase:
Examination Phase must include…
System timestamps (clock), registry files, input/output access files, swap files, slack space, other nodes where evidence will accumulate, e.g. internet/web cache
Analysis Phase - Actus Reus:
The guilty act. What is there? or what has been done?
Analysis Phase - Mens Rea:
The guilty mind or intent. Is it deliberate?
Analysis Phase - Must Document: