A Brief Introduction to Digital Forensics Based in large part on the July 29, 2014 BitCurator workshop at METRO, as well as the SAA DAS curriculum *** Kevin Schlottmann November 23, 2015
What is digital forensics? "…identifying, preserving, analyzing, and presenting digital evidence…" http://aic.gov.au/documents/9/C/A/%7B9CA41AE8-EADB-4BBF-9894-64E0DF87BDF7%7Dti118.pdf
Briefest history of digital media Trends – more density; cheaper; more and more transactions done and stored digitally
Why apply digital forensics? *To ensure data integrity and ease automation and processing
Why apply digital forensics? *In other words: preserve significant properties such as authenticity and reliability Edmund Locard
Why apply digital forensics? *In other words: to ensure provenance, original order, chain of custody, and context of digital objects Disk image; layers; MAC times; deleted items; temp files; file system and OS information; one checksum to manage; an image is das Ding an sich; SIP/AIP
Just one part of the plan
BC, FTK, USB, JHOVE, E01, METS, PREMIS Many, many tools BC, FTK, USB, JHOVE, E01, METS, PREMIS
What is BitCurator? *Customized Linux OS running in virtual machine with a tightly integrated, well-documented suite of open-source digital forensics tools
What is BitCurator? *Customized Linux OS running in virtual machine…
What is BitCurator? *Customized Linux OS running in virtual machine…
What is BitCurator? *…a tightly integrated, well-documented suite of open-source digital forensics tools
1. Creating a disk image
2. Analyzing the disk image
3. Create access copy
Just one part of the plan
Who is doing this work? http://www.trevorowens.org/2014/06/digital-archivists-doing-or-leading-the-digital/
What skills might digital archivists have? Firm understanding of archival principles: provenance, original order, creation context Firm understanding of archival standards: levels of description, DACS, the EAC suite Outlines of METS, MARC/MODS/DC, PREMIS, and how they might fit together Metadata wrangling tools: Excel, csv, OpenRefine A “power tool” : XSLT, xQuery, command-line tools (grep, sed), or Python Actionable curiosity http://gavialib.com/2013/09/the-one-skill/
What am I doing right now? Using METS files to manage disk images ePADD for email processing
Just one part of the plan
Additional Reading Thank you! *BitCurator wiki [http://wiki.bitcurator.net/index.php?title=Main_Page] *From Bitstreams to Heritage report [http://www.bitcurator.net/docs/bitstreams-to-heritage.pdf] *You’ve Got to Walk Before You Can Run: First Steps for Managing Born-Digital Content Received on Physical Media [http://www.oclc.org/content/dam/research/publications/library/2012/2012-06.pdf?urlm=168601] Thank you!