Digital Forensics Chris Rozic
Direction Definition of digital forensics Areas of required expertise Collection of digital evidence Actual investigation Examples of forensic software Digital Forensics example
Definition A scientific, systematic inspection of a computer system and its contents for evidence or supportive evidence of a crime or other illegitimate computer use. Must be techno-legal in nature
General Process
Must knows of Forensics Investigator Must be highly knowledgeable in many areas Computer forensics protocols Network infrastructures Evidence control E-discovery tools
Collection of evidence Done in three parts Workstation of the offender Server accessed by offender The connecting network Must take extreme caution while handling the captured information Consider the organization
Actual Investigation Analyze the surrounding Photograph Power down machine and inspect Documentation
Duplicate Hard Drive Duplicate entire hard drive at sector level Use hardware to write block Create image Completeness Accuracy Create MD5 hash
Forensics tools Encase nGenius Flow Recorder Guidance software Allows for a digital snapshot of the storage medium under investigation nGenius Flow Recorder Security-hardened, Linux-based appliance that continuously captures, stores, and analyzes large volumes of network traffic
Encase Most popular Specifically designed for law enforcement Creates mirrored images User friendly interface
Creation of MD5 with Encase File Integrity: Completely Verified, 0 Errors. Acquisition Hash: 340C8B5EF96DCCEE4B552CE084CCF941 Verification Hash: 340C8B5EF96DCCEE4B552CE084CCF941
nGenius Flow Recorder Available in two appliances Enterprise appliance platform Workgroup appliance platform Allows for 24x7 recording and diagnosis
Advantages of nGenius Deep traffic stream capture Provide packet-level visibility Application reconstruction/playback Complete post-event analysis Automatic notification Network forensics analysis
Digital Forensics Example Chandra Levy Missing April 30, 2001 Used e-mail and the internet prior to disappearance Ultimately led to her whereabouts a year later
Conclusion There are many areas where digital forensics is applicable One of the largest growing fields requiring knowledge across different spectrums Allows for numerous job opportunities in specialized areas
Questions ?
References www.protiviti.com www.nGeniusflowrecorder.com www.computerforensics-wikpedia.com Personal notes