Premium Essay

Forensic Evidence in It

In: Computers and Technology

Submitted By javajunkie
Words 22743
Pages 91
U.S. Department of Justice Office of Justice Programs National Institute of Justice

APR. 04

Special

REPORT

Forensic Examination of Digital Evidence: A Guide for Law Enforcement

U.S. Department of Justice Office of Justice Programs 810 Seventh Street N.W. Washington, DC 20531

John Ashcroft Attorney General Deborah J. Daniels Assistant Attorney General Sarah V. Hart Director, National Institute of Justice

This and other publications and products of the U.S. Department of Justice, Office of Justice Programs, National Institute of Justice can be found on the World Wide Web at the following site: Office of Justice Programs National Institute of Justice http://www.ojp.usdoj.gov/nij

APR. 04

Forensic Examination of Digital Evidence: A Guide for Law Enforcement

NCJ 199408

Sarah V. Hart Director

This document is not intended to create, does not create, and may not be relied upon to create any rights, substantive or procedural, enforceable at law by any party in any matter civil or criminal. Opinions or points of view expressed in this document represent a consensus of the authors and do not represent the official position or policies of the U.S. Department of Justice. The products, manufacturers, and organizations discussed in this document are presented for informational purposes only and do not constitute product approval or endorsement by the U.S. Department of Justice. This document was prepared under Interagency Agreement #1999–IJ–R–094 between the National Institute of Justice and the National Institute of Standards and Technology, Office of Law Enforcement Standards. The National Institute of Justice is a component of the Office of Justice Programs, which also includes the Bureau of Justice Assistance, the Bureau of Justice Statistics, the Office of Juvenile Justice and Delinquency Prevention, and the Office for Victims of Crime....

Similar Documents

Free Essay

Forensic Evidence

...Forensic Science is the application of science to the law. In recent years the use of forensic science has become increasingly necessary to help with criminal and civil investigations. Although forensic evidence is admissible in court one must keep in mind how that evidence made its way to the court system. I will take you through the process. For there to be admissible evidence for a court case there must be physical evidence which would have been collected at a crime scene therefore there must have been some kind of crime committed. A crime with physical evidence doesn’t necessarily mean something violent but it can be. Theft, arson, car accident and murder are just a few examples of what a crime can be. The process begins when the crime has been committed, to the officers arriving on the scene, to surveying the scene, collecting the evidence, submitting it to the lab, submitting it as evidence and finally the acceptance of the evidence. When a call is sent out regarding a possible crime and the first officer arrives on scene it is that officer’s obligation to do a few things as precise as possible: 1. seek medical attention for those who may need it, 2. arrest or detain any perpetrators, and 3. secure the crime scene. Securing the crime scene is extremely important because you want to be able to retrieve as much evidence as possible. By securing the crime scene you are blocking off the area from unauthorized personnel. You want to keep the foot traffic......

Words: 1263 - Pages: 6

Premium Essay

Cis 4203 Forensics Discussion 1 - Overview of Evidence

...Discussion 1 - Overview of Evidence Due Sunday by 11:59pm Available after May 16 at 12am Learning Objectives and Outcomes * Determine the appropriate digital forensic analysis technique for a given scenario. Assignment Requirements Review the information in the text sheet entitled “Overview of Evidence and Digital Forensic Analysis Techniques,” which describes different types of digital forensic analysis techniques, such as disk forensics and e-mail forensics. Based on the information in the text sheet and in your assigned reading for this week, discuss the following scenarios and determine which type of forensic analysis technique(s) should be used, and why:   1. The Federal Trade Commission disclosed a law suit against unknown credit card fraudsters. Over 15 companies were being run by "money mules," people who transfer stolen goods or money from one country to another. The money mules were recruited via a spam e-mail message. E-mail forensics—The study of the source and content of e-mail as evidence. E-mail forensics includes the process of identifying the sender, recipient, date, time, and origination location of an e-mail message. You can use e-mail forensics to identify harassment, discrimination, or unauthorized activities. There is also a body of laws that deal with retention and storage of e-mails that are specific to certain fields, such as financial and medical. Disk forensics—The process of acquiring and analyzing information stored on physical......

Words: 951 - Pages: 4

Free Essay

Computer Forensics

...Computer Forensics Through the Years Prof. Pepin Galarga Computer Forensics Sep 11, 2010 Table of Content Introduction …………………………………………………………………………………Page 2 The Early Years……………………………………………………………….......................Page 3 Early Training Programs …………………………………………………………………....Page 4 Typical Aspects of Computer Forensic Investigations ……………………………………..Page 5 Legal Aspects of Computer Forensics …………………………………………..……...…..Page 6 Conclusion ………………………………………………………………………………….Page 7 References………………………………………………………………………………..…Page 8 Introduction If you manage or administer information systems and networks, you should understand computer forensics. Forensics is the process of using scientific knowledge for collecting, analyzing, and presenting evidence to the courts. (The word forensics means “to bring to the court.”) Forensics deals primarily with the recovery and analysis of latent evidence. Latent evidence can take many forms, from fingerprints left on a window to DNA evidence recovered from blood stains to the files on a hard drive. Because computer forensics is a new discipline, there is little standardization and consistency across the courts and industry. As a result, it is not yet recognized as a formal “scientific” discipline. Image by Flickr.com, courtesy of Steve Jurvetson Computer forensics is the study of extracting, analyzing and documenting evidence from a computer system or network. It is often used by law enforcement officials to seek...

Words: 1382 - Pages: 6

Free Essay

Forensic Science in the 21st Century

...Forensic Science in the 21st Century By: Crystal Lyle AJS/584 - FORENSIC SCIENCE AND PSYCHOLOGICAL PROFILING STEVEN HOENIG 2-29-16 This paper will examine my perception and concept of forensic science in the 21st century. It will also examine the importance of forensic science to policing criminal investigation court process, and the efforts of various levels in security. In addition to analyzing the importance of forensic science, I will give a historical approach. I will discuss the accuracy of the media representation of forensic science and how issues. Lastly, I will discuss the influence the CSI effect have on the judicial process. Forensic Science is the application of science to criminal and civil laws that are enforced by law enforcement agencies in a criminal justice system. Another definition of forensic science is principles and techniques to matters of criminal justice, especially as it relates to the collection, examination, and analysis of physical evidence. In 1929, a Los Angeles police department establish the first American forensic lab. Forensic science has been around over 300 years or more and it continues to improve and emerge today as science and technical knowledge find more improved and accurate techniques. Forensic science has come to be a critical instrument in allowing guilt or demonstrating innocence in the system of criminal justice. In the late 80’s (DNA), society was accepting of (DNA) and forensic science continues to develop and......

Words: 1265 - Pages: 6

Free Essay

Forensic Testimony in Court

...Examine Forensic Testimony Forensic evidence has become more and more important in the court case for proving the guilt or innocence of a criminal defendant. Due to new technology the world of forensics is becoming more and more advanced providing law enforcement with all types of new investigatory tools and ways for the court to prove or disprove guilt. It is essential for law enforcement agencies to have trained forensic personnel with the skills to properly collect the evidence first to ensure the evidence does not become lost, destroyed, or damaged and the forensic evidence is accepted in a court of law. Improper collection of evidence is only one of many potential challenges associated with forensic evidence but it is an important challenge that must be addressed. Forensic evidence is collected at the crime scene. If the evidence is not properly documented and collected it can be found to be unreliable in the court process. In order for forensic evidence to be accepted in a court of law it must be documented through sketches, photographs, and video tapings and it must be collected using accepted standard forensic collection methods. If evidence is not properly documented or collected the chain of evidence is broken and the court will exclude the evidence from the court case. The chain of evidence refers to an important aspect of forensic involving the movement of evidence. In order to show the court the evidence was located and collected at the scene...

Words: 1538 - Pages: 7

Free Essay

Forensicscience

...1)Introduction; Crime today is at an extreme high. However, forensic science has been there to help solve every crime committed Forensic science is the scientific method of gathering and examining information about the past. The word forensic comes from the Latin forēnsis, meaning "of or before the forum. The word forensic basically means the key to solve a crime.This is the technology used to help forensic teams to analyze and solve crimes.- This is especially important in law enforcement where forensics is done in relation to criminal or civil law,[1] but forensics are also carried out in other fields, such as astronomy, archaeology, biology and geology to investigate ancient times. Forensic Science is used to Identify Criminals Rape, murder, theft, and other crimes almost always leave a devastating mark on the victim. . In modern forensic science, the crime laboratories include photography section, Evidence storage section, identification section, chemistry section, General examination section, Fire arms section, instrument section and crime scene search section. 2)Origins of forensic science: In 16th-century Europe, medical practitioners in army and university settings began to gather information on the cause and manner of death. Ambroise Paré, a French army surgeon, systematically studied the effects of violent death on internal organs.[9][10] Two Italian surgeons, Fortunato Fidelis and Paolo Zacchia, laid the......

Words: 3403 - Pages: 14

Free Essay

Types of Forensics

...FORENSICS Forensics, by and large, is the application of science to the legal process. It is an emerging research domain in India. There are many different types of forensic sciences baring their vital presence possibly in every field of human endeavor. Of these, let us now discuss about the computational, cyber and the DNA forensics. COMPUTATIONAL FORENSICS: The development of computational methods or mathematical and software techniques to solve forensic issues is called computational forensics. These methods analyze the evidence beyond human cognitive ability. They scrutinize a large volume of data, which is at any case impossible for a human mind to figure out. In spite of this, we can’t say that these techniques alone would serve our purpose because computational forensics is a field which needs huge collaboration between recognition and reasoning abilities of humans combined with comprehension and analytic abilities of the tool or a machine, which is most of the times, a computer. Computational forensics aids us to model the uncertain. At the crime scenes, we usually get incomplete or broken evidences. These evidences are later on modeled by the computational forensic tool which gives us first clues from its largest biometric database (fingerprints, criminal histories, mug-shots, scar and tattoo, physical characteristics like height, weight, hair and eye color and aliases), which is a collection of significant information regarding the criminals, their criminal......

Words: 1917 - Pages: 8

Free Essay

Weight Loss

...Forensic Accounting 1 Assignment 3: Forensic Accounting in Practice BUS 508 Professor: Edwin Quinn Jr. Carmesha Eldridge May 19, 2013 Forensic Accounting 2 1. Determine the most important five (5) skills that a forensic accountant needs to possess and evaluate the need for each skill. Be sure to include discussion regarding the relationship between the skill and its application to business operations. One of the most essential skills is being analytical. Forensic accountants must make sure that they are in a position to uncover financial deceptions by critically analyzing them with an understanding of fraud schemes. A forensic accountant is deductive analysis or the ability to take a shot at the financial contradictions that are not a normal pattern of the company to uncover potential financial fraud. Being analytical is essential to remaining an effective forensic accountant. They need to be able to analyze the validity of each transaction the company recorded to make sure that the transactions were reported accurately and fairly. They must possess the knowledge and expertise to interpret financial statements or work under situations where information has been either destroyed or tampered with and be analytical and put the pieces of the puzzle back together again. Forensic accountants should be detailed orientated. Being a forensic accountant means that you will be looking at large quantities of numbers from supporting documents and various financial......

Words: 1792 - Pages: 8

Premium Essay

Forensic Computing Practice Case Study

...SCHOOL OF COMPUTING Bachelor of Computer Science / Bachelor of Software Engineering Forensic Computing Practice Assignment 2 Student declaration: I declare that:  I understand what is meant by plagiarism  The implication of plagiarism have been explained to me by our lecturer This assignment is my own work. Name ID 1)Nicholas Tan Tian Shen 0307878 Forensic Computing Practice Assignment 2 Due Date : Soft-copy submission on 10/11/14. Individual Assignment Question 1 a. What can a cloud provider do in terms of providing digital forensics data in the event of any legal dispute, civil or criminal case, cyber-attack, or data breach? Cloud provider need to provide the evidence by being forensically ready. To...

Words: 3104 - Pages: 13

Premium Essay

Professional Standard

...assignment is Computer Forensics Investigator I picked this job because I think that is the career path I want to take. I am currently getting my degree in Information technology and want to go for a bachelor’s in information systems security. The job of a Computer Forensics Investigator is to identify and collect digital data and evidence from all sorts of media like hard drives, flash drives and even the Internet. Once the digital evidence and data our collected then the Computer Forensics Investigator must examine and analyze the evidence to find out what the data is and what it was used for. The Computer Forensics Investigator must also help with the collecting of physical evidence at crime scenes such as computers and digital media. A day in the like of a Computer Forensics Investigator would in tale of the investigator going to a crime scene and collecting of evidence and talking it back to the computer lab. Where the investigator would take the evidence say a computer and getting all the digital data off the drive where they can analyze the data and the hand any incriminating evidence over to the lead investigator to aid in the capture of the criminals. The Investigator may even need to go as far as retrieve data from the drive that has been deleted this can be a completed task in its self because it can talk days some times to retrieve this deleted data and then all the data might not be available to get a complete file. The next thing the Computer Forensics......

Words: 570 - Pages: 3

Free Essay

Mobile Forensics in Healthcare

...2009 Eighth International Conference on Mobile Business Mobile Forensics in Healthcare Connie Justice, Huanmei Wu Computer & Information Technology Purdue School of Engineering and Technology Indiana University Purdue University Indianapolis 799 W. Michigan St., ET 301 Indianapolis, IN 46202 {cjustice, hw9}@iupui.edu Abstract -- Mobile communication has been heavily applied in the current healthcare system for health information exchange. Patient information security has become a major concern, especially with the wide adoption of electronic medical records. Mobile Forensics has been utilized by law enforcement to systematically procure and preserve mobile evidence. However, the adoption of mobile forensics in the healthcare lags behind. The goal of our project is to examine the options and to provide recommendations for adoption and customization of mobile forensics in the healthcare field. An open-ended survey of local healthcare and related facilities around Indianapolis has been explored to examine the current status of Mobile Forensics in the healthcare field. The results have been evaluated using statistical analysis. A methodology is being proposed that would use mobile forensics procedures taking into account the regulatory measures that have to be instituted due to the Health Insurance Portability and Accountability Act (HIPAA) of 1996. Keywords-mobile forensics, healthcare. Evelyn Walton Informatics Indiana University Purdue University Indianapolis 799 W.......

Words: 4340 - Pages: 18

Free Essay

Hair Banding: Casey Anthony Case

...conduct while Holland (2015) asserts that criminal laws refer to the state laws, which make certain actions illegal and punishable by fines or imprisonment. Accordingly, the case of Casey Anthony falls under the criminal and as such, the forensic evidence gathered from the trunk of her car makes her criminally reliable, as the said evidence is admissible in the court of law. The forensic experts from the Federal Bureau of Investigation (FBI) examined a band of hair recovered from her vehicle, which exposed evidence of apparent decomposition. Forensic analysis of the recovered band of hair showed consistence with the band of hair of the deceased. The FBI experts who conducted forensic analysis on the band of hair told the court that the sample had many consistencies in relation to the post-mortem banding. Moreover, microscopic hair examination specialist told the jurors that the root portion of the air was dark and, therefore, consistent with the evidence presented by the FBI. The analyzed evidence showed that the hair was evicted forcibly from the deceased. Further, an investigator of the crime scene testified that that there was an odor smell emanating from Casey Anthony’s car, which indicted that there was decomposition in the car. All this evidence prompted the court to judge Casey Anthony with first-degree murder when the remains of the deceased were found near the home of the defendant’s parents. However, the defense team for Casey Anthony asserted that the deceased......

Words: 955 - Pages: 4

Premium Essay

Welcome to Homicide

...Welcome to Homicide Forensic Science is a fundamental component of the justice system. Forensic scientists use scientific techniques and knowledge to assist law enforcement in investigations and solving crimes. They collect and analyze numerous types of evidence, including blood, body fluids; DNA; and human tissue. Forensic scientists assist the decision makers by showing the prosecutor if the issue has merit before it reaches the courtroom thereby reducing the number of cases having to be heard. Their decisions are based on scientific investigations and not circumstantial evidence or unreliable witnesses. Forensic scientists can restore faith in the judicial system with the use of science and technology for facts in criminal and civil investigations. The legal system is established on the belief that the legal process results in justice for all. History of forensic science The history of Forensic science or the applying of scientific principles to legal questions has a lengthy and interesting history. The first recorded autopsy was reported in 44 B.C was on Julius Caesar, where the Roman physician, Antistius proclaimed that he had 23 wounds on his body but only one was fatal. In 1248, a Chinese book entitled “His Duan Yu” (meaning The Washing Away of Wrongs) explaining how to tell apart a drowning from a strangulation. This was also the first recorded use of medicine to assist in solving crimes. In 1590, the first microscope was developed. In 1775,......

Words: 2382 - Pages: 10

Premium Essay

Forensics

...this research paper was to analyze three anti-forensic techniques for potential methods of mitigating their impact on a forensic investigation. Existing research in digital forensics and anti-forensics was used to determine how altered metadata, encryption, and deletion impact the three most prominent operating systems. The common file systems for these operating systems were analyzed to determine if file system analysis could be used to mitigate the impact of the associated anti-forensic technique. The countermeasures identified in this research can be used by investigators to reduce the impact of anti-forensic techniques on an investigation. Also, the results could be used as a basis for additional research. File system analysis can be used to detect and mitigate the impact of the three methods of anti-forensics researched under the right circumstances. Some areas of anti-forensics and file systems have been relatively well-researched. However continued research is necessary to keep pace with changes in file systems as well as anti-forensic techniques. Keywords: Cybersecurity, Albert Orbinati, Windows, Linux, Macintosh, file table. MITIGATING THE IMPACT OF ANTI-FORENSIC TECHNIQUES THROUGH FILE SYSTEM ANALYSIS by Gabriel A. Flynn A Capstone Project Submitted to the Faculty of Utica College August 2012 in Partial Fulfillment of the Requirements for the Degree of Master of Science Cybersecurity – Intelligence & Forensics © Copyright 2012 by Gabriel Flynn All......

Words: 11835 - Pages: 48

Free Essay

Forensic Science in the 21st Century

...Forensic Science in the 21st Century AJS/592 Aug 2012 Forensic Science in the 21st Century Forensic science is regarded as an essential component in the resolution of crimes and law enforcement. Collecting and deciphering evidence properly and preserving crime scenes are two of the most important elements in crime-solving. Consequently, technological advances are relevant to the limited and challenging forensic science field. Also, it is a field wherein technical aptitude is attained only by the amalgamation of various dynamics. For example, supervision, continuing education, proficiency, training, experience, coupled with appreciativeness of scientific protocols and methods proposed against a setting of harsh professional beliefs. This submission delves into forensic science’s contributions to policing and criminal investigations, court processes, and security efforts. Also it explores the media’s representation of forensic science, influence on popular opinion for justice-related issues, and “CSI” effect on the judicial process. Forensic Science Contributions to Policing and Criminal Investigations The geneses of criminalistics or forensic science are mainly European. Forensic science is an amalgamation of various disciplines, such as chemistry, mathematics, geology, physics, and biology to examine physical evidence associated with crime. Previously, the employment of......

Words: 1778 - Pages: 8