Download presentation
Presentation is loading. Please wait.
1
A Brief Introduction to Digital Forensics
Based in large part on the July 29, 2014 BitCurator workshop at METRO, as well as the SAA DAS curriculum *** Kevin Schlottmann November 23, 2015
2
What is digital forensics?
"…identifying, preserving, analyzing, and presenting digital evidence…"
3
Briefest history of digital media
Trends – more density; cheaper; more and more transactions done and stored digitally
4
Why apply digital forensics?
*To ensure data integrity and ease automation and processing
5
Why apply digital forensics?
*In other words: preserve significant properties such as authenticity and reliability Edmund Locard
6
Why apply digital forensics?
*In other words: to ensure provenance, original order, chain of custody, and context of digital objects Disk image; layers; MAC times; deleted items; temp files; file system and OS information; one checksum to manage; an image is das Ding an sich; SIP/AIP
7
Just one part of the plan
8
BC, FTK, USB, JHOVE, E01, METS, PREMIS
Many, many tools BC, FTK, USB, JHOVE, E01, METS, PREMIS
9
What is BitCurator? *Customized Linux OS running in virtual machine with a tightly integrated, well-documented suite of open-source digital forensics tools
10
What is BitCurator? *Customized Linux OS running in virtual machine…
11
What is BitCurator? *Customized Linux OS running in virtual machine…
12
What is BitCurator? *…a tightly integrated, well-documented suite of open-source digital forensics tools
13
1. Creating a disk image
14
2. Analyzing the disk image
15
3. Create access copy
16
Just one part of the plan
17
Who is doing this work?
18
What skills might digital archivists have?
Firm understanding of archival principles: provenance, original order, creation context Firm understanding of archival standards: levels of description, DACS, the EAC suite Outlines of METS, MARC/MODS/DC, PREMIS, and how they might fit together Metadata wrangling tools: Excel, csv, OpenRefine A “power tool” : XSLT, xQuery, command-line tools (grep, sed), or Python Actionable curiosity
19
What am I doing right now?
Using METS files to manage disk images ePADD for processing
20
Just one part of the plan
21
Additional Reading Thank you! *BitCurator wiki
[ *From Bitstreams to Heritage report [ *You’ve Got to Walk Before You Can Run: First Steps for Managing Born-Digital Content Received on Physical Media [ Thank you!
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.