Free Essay

Forensics

In: Computers and Technology

Submitted By gorivishal
Words 937
Pages 4
Name: Nupur Vijay Gholap
Weekly Solutions Template

Hands on project 4-4:
Answer:

Case Project 4-5
Answer:
To acquire the data from the source file following methods can be used: 1. Disk-to-Image files: FKT Imager can be used to disk-to-image files from other proprietary formats. We need not segment the data as entire 2 GB can be stored directly. FKT runs on the windows and needs write blocking device. FKT can read AccessData, Expert Witness, SafeBack, SMART and raw format files, CD and DVD files.
Proprietary format tools run an option to compress or not compress image files of a source drive, to save space on the target drive. Hashing helps check the integrity of the data. Various tools can integrate metadata into the image file
But there exits an inability to share an image between different vendors’ computer forensics analysis tools. Like ILook imaging tool IXimager produces IDIF, IRBF, and IEIF but can be read only by ILook. Proprietary format tools produce a segmented file of 650 MB. Maximum file size per segment can be 2 GB.

2. Disk-to-disk copy: UNIX/Linux dd command does disk-to-disk copy. dd command is very easy and effective in a Linux machine. But for that we need equal or larger space in the target disk to copy full image from the source disk.
Raw formatting is a technique in which we use dd command to generate image files which are split into smaller segments and are exact bit-by-bit replica of the original disk. These are sequential flat files of the source drive. Hardware and software duplicators are available for disk to disk copy. Hard duplicators like Logicube Talon,etc and software duplicators like SafeBack, EnCase, etc.
Raw format is faster data transfers and has the ability to disregard minor data read errors. Versatility is a big deal as the output because many forensics tools can read the raw format, making it a universal acquisition format for most tools. It needs equal storage space as compression option is unavailable. Freeware versions, sometimes might not collect marginal (bad) sectors on the source drive, meaning they have a little threshold of retry reads on frail media spots on suspect drive. Many acquisition tools also provide a validation check by using Cyclic Redundancy Check (CRC-32), Message Digest 5 (MD5), and Secure Hash Algorithm (SHA-1 or newer) hashing functions. Separate file is created containing the hash value. FTK Imager and ProDiscover are couple of tools which can be used.

3. Logical disk to disk/sparse acquisition :
It’s used to collect specific files from the suspect drive, as the evidence files. This method is used when the time is limited and we don’t need to copy entire drive of suspect.
Example: Suppose in a case there is row over certain illicit email by the suspect. His only email needs to be checked rather than entire file. It saves time and target disk space. Software like EPICS can be used for the same. It can copy Outlook .pst or .ost files

Hands on project 5-5

Answer

Case study 5-4
Answer
To investigate the case following steps should be followed: 1. I will need to issue the search warrant against Mr. Zane first. Or since it’s a private institute, I will need permission of the highest authority here. 2. I need following things to carry out the search-
Small Computer toolkit
Large capacity storage
USB cable
Write-blockers
3. Then I will ask the highest authority of the institution to avoid the use of Mr. Zane’s system by anyone. Also let the system be in the state it is, if its off, leave it off, if it on, leave it on. 4. While investigating the office of Mr. Zane, him being unaware of the investigation, I would first click pictures of the office to place the stuff back as it first was after investigation. 5. I will then boot my forensic workstation to Windows and go to AccessData. 6. I will connect the system to the target drive and use FTK with write-blocker to copy the data to the target drive. 7. I will use CD or DVD on MM tapes to store the acquitted data. 8. It is necessary to know that it is difficult to retrieve entire data if Mr. Zane has deleted the data as the RAM can overwrite when other programs are run. 9. Also when FTK is booted on Windows, it runs on the same RAM of source data and there are high chances of programs over-writing the deleted files. Hence it’s difficult to maintain integrity of data.

* Lab Answers
2.1
1. d – The MFT is not updated until all the remnants have been overwritten by the new data.
2. a – Recovering files that have been deleted but not overwritten.
3. d - 7
4. b – The MFT is updated to indicate free space when the files are deleted.
5. b – Writing 0s and 1s to the file remnant locations

2.3
1. a - .dd
2. c – CD or DVD
3. c - .eve images to ISO
4. d - .dd
5. a – Forensics investigators should be familiar with more than one forensic analysis tools because they can maintain the chain of custody.

2.4
1. d - .eve
2. b – is not optimized to search large volume of data
3. a – be small enough to fit on a floppy disk as a portable imaging tool
4. a – MD5
5. b – Because the file hash verified that the “chain of custody” has been maintained during the imaging process.

Similar Documents

Premium Essay

Forensics

...In the article it was discussing all the different types of forensics there are. People think there is just one type of forensics, but there’s a wide range of all different types. I also picked this article because I think people should realize that forensics is a very hard field to go into. You really have to really have heart to be able to go into this field. Investigator’s really have to go into detail about every little thing. In the investigations you really cannot miss a single detail. The article also goes in depth about what sciences are required to take, and for that person to really know. To be in the field you really have to love what you do. Many people often misunderstand Forensic Science and believe it is much more capable than it really is. People typically think that what they watch on T.V. is 100% true. Actually what you see on T.V. is mainly false or over exaggerated in some way. Criminal Investigation is the largest and most known form of Forensic Science. More of the known areas that people know about Forensics are; Fingerprinting, DNA Identification, Fiber Samples, Computer Animation, etc. What people see on T.V. is that it takes about an hour for the people on the NCIS, or Law & Order to figure everything. Typically it takes months at a time, and most of the time aren’t even accurate concepts. This article relates to my life, because forensics is really all about a puzzle. I feel like my life is like a puzzle. But in a good way. This article......

Words: 314 - Pages: 2

Premium Essay

Forensic

...medical examiners use similar phrases. Most people enjoy watching CSI, Criminal minds, and Law and Order. If you haven’t guessed by now, I am totally interested in crime scenes and how people die. A forensic pathologist is a great profession that requires hard work, dedication, and flexibility. A Forensic Pathologist is a person who examines the bodies of people who died suddenly, unexpectedly, or violently. They are in charge of determining a person death. A medical examiner perform autopsy and trace evidence from the body for further information. This profession works hand and hand with criminal law. As a medical examiner, you are responsible for finding the exact cause of death. “I wanted to be a forensic scientist for a long time. It's like putting the pieces of a puzzle together. Solving mysteries seemed like it would be fun, scary and exciting all at the same time.” Forensic Pathologist performs a full death investigation. As a coroner, evaluates crime scene evidence. There is a large vocabulary that forensic pathologist must learn. The terminology that medical examiners use is totally different from everyday language. They use medical terms that doctors use for body parts. Education is very important no matter what career path you choose. For a forensic pathologist, you will need plenty of education you must go to high school and college; you must also make good grades. In high school, you should strive to keep a B average. Asking your......

Words: 1117 - Pages: 5

Free Essay

Forensic

...Subspecialties of forensic psychologySubspecialties of forensic psychologySubspecialties of forensic psychology Forensic psychology is defined as the application of psychological knowledge to the legal system (Bartol & Bartol, 2012: 6). The concept of forensic psychology can be misunderstood, because the definition does not explain much. The easiest way to explain forensic psychology is to break it down into its subspecialties and describe where psychological knowledge can be applied. There are five subspecialties of forensic psychology, namely police psychology, psychology of crime and delinquency, victimology and victim services, legal psychology and correctional psychology. I will discuss legal psychology and correctional psychology. · Legal psychology Legal psychology is the study of human behavior relevant to the law. This subspecialty of forensic psychology consists of those theories that describe, explain and predict human behavior by reference to the law. Bartol & Bartol (2012) described that early in a case when attorneys are preparing for a trial and gathering information psychologist can be called in to testify. Main roles of a forensic psychologist in the USA includes, acting as a consultant to law enforcement, acting as trial consultants (jury selection, case preparation and pre-trial publicity), presenting psychology to appeal courts, doing forensic assessment and acting as an expert witness (insanity defense, competence to stand trial, sentencing, eyewitness...

Words: 1988 - Pages: 8

Premium Essay

Forensic

...Forensic Toxicology     It was during the years of 1998 and 2001 that a very demure and innocent looking woman named Van le Thahn began her killing spree. Thahn was 49 years old  at the time and was from the city of Ho Chi Minh in Vietnam. Van le Thahn successfully poisoned 13 people with cyanide. Named the Vietnamese Black Widow, Van would intentionally place herself in situations that would allow her to interact with people who were rich and affluent. After gaining access to the circle, Van would befriend those that she thought would be easy targets and victims to her scheme. She would cook for her new found “friends” and provide drinks that contained cyanide which ultimately ended their lives. Van did not discriminate when it came to her targets in some cases. It is estimated that Van killed thirteen people during the years of her killing spree, among the thirteen people she killed included was her mother-in-law, brother-in-law, and two ex-husbands. It is speculated that the killing of the members of Van’s extended family was due to ongoing family problems. Van’s main goal for the selection of her targets and killing them was to take their most valuables items for her possession or sell them for the money. It is estimated that Van was able to steal more than twenty thousand US dollars from her victims. Because of the nature of these killings it made finding out that Van was the killer hard. It is without a doubt that had it not been for the expertise of a Forensic......

Words: 1979 - Pages: 8

Premium Essay

Forensic Pathology

...A forensic pathologist (which is known to most people as a medical examiner), is heavily involved in the criminal justice system and medical system. The medical examiner's main job is to conduct an autopsy on the victim of any unnatural form of death. Their primary task in potential criminal cases is to find the cause of death and confirm if it was homicidal, suicidal, or an accident. The cause of death is what police investigators use as their lead to track down potential suspects. Some work in local parts of government, hospitals, medicals schools, and in private practice which would contract their service to other government agencies. They perform autopsies, write out autopsy reports, look over victim's medical records, and interview the victim's next of kin. They also have to be trained in the legal system and to be able to testify in court cases involving death or injury (“Forensic Pathology,” 2009). Most forensic pathologist start as a resident, then after residency they awarded the title medical examiner. They can continue working to deputy chief medical examiner and the top position chief medical examiner. It takes between 13 to 15 years of education to become a forensic pathologist. This includes your bachelor degree and medical course requirements, followed by four years of medical school, and four years practicing forensic pathology as a resident. Once all of this is completed, you are required to accomplish a one year fellowship. The last and final step to be a......

Words: 659 - Pages: 3

Premium Essay

Forensic Accounting

...Forensic accounting is the specialty practice area of accountancy that describes engagements that result from actual or anticipated disputes or litigation. "Forensic" means "suitable for use in a court of law", and it is to that standard and potential outcome that forensic accountants generally have to work. Forensic accountants, also referred to as forensic auditors or investigative auditors, often have to give expert evidence at the eventual trial. There are several organizations worldwide that provide continuing education and certification for forensic accountants. There has been a growing need for this specialized field with recent company scandals that have occurred. Forensic accountants utilize an understanding of business information and financial reporting systems, accounting and auditing standards and procedures, evidence gathering and investigative techniques, and litigation processes and procedures to perform their work. The main goal of their engagements is to provide the answers to the how, where, what, why, and who committed the alleged allegations. They will use the same basic procedures for obtaining evidence of the crimes that they investigate. They will examine records and interview suspects to determine the answers to these questions. Forensic accountants are also increasingly playing more proactive risk reduction roles by designing and performing extended procedures as part of the statutory audit, acting as advisers to audit committees, fraud......

Words: 346 - Pages: 2

Free Essay

Forensic Science

...WEEK 1- INTRODUCTION TO FORENSIC SCIENCE Quote "Every contact leaves a trace." - Edmond Locard (1877 - 1966) Learning Objective(s) At the end of this topic, you should be able to: 1. Define 'Forensic Science'; 2. Explain the limits of Forensic Science; 3. Identify the types of forensic work; 4. Describe Locard's Exchange Principle; 5. Differentiate Reconstruction & Re-enactment. Synopsis To illustrate the scope and diversity of Forensic Science, place it in its legal context, and describe the various types of forensic work. There will also be a discussion of Comparison leading to Association, Reconstruction versus Re-enactment, Locard's Exchange Principle, and the limits of Forensic Science. Various case studies will also be analysed throughout the lecture. Case Studies Felicia Lee; Walter Dinivan; Madam Jetkor Miang Singh; Roberto Calvi; Buck Ruxton & the Jigsaw Murders; Acid Bath Haigh; 2005 London Bombings; "Brides in the Bath"; Gareth Williams; The Woodchipper Murder WEEK 2- CHEMICAL ANALYSIS IN FORENSIC SCIENCE Quote "Actus non facit reum nisi mens sit rea" The act is not culpable unless the mind is also guilty. Learning Objective(s) At the end of this topic, you should be able to: 2A. Atomic Structure & Spectroscopy 1. Explain the structure of the atom and Bohr's model; 2. Differentiate between emission and absorption spectroscopy; 3. Explain the chemistry behind EDX and SEM-EDX; 4. Explain the chemistry in NAA; 2B.......

Words: 1646 - Pages: 7

Free Essay

Types of Forensics

...FORENSICS Forensics, by and large, is the application of science to the legal process. It is an emerging research domain in India. There are many different types of forensic sciences baring their vital presence possibly in every field of human endeavor. Of these, let us now discuss about the computational, cyber and the DNA forensics. COMPUTATIONAL FORENSICS: The development of computational methods or mathematical and software techniques to solve forensic issues is called computational forensics. These methods analyze the evidence beyond human cognitive ability. They scrutinize a large volume of data, which is at any case impossible for a human mind to figure out. In spite of this, we can’t say that these techniques alone would serve our purpose because computational forensics is a field which needs huge collaboration between recognition and reasoning abilities of humans combined with comprehension and analytic abilities of the tool or a machine, which is most of the times, a computer. Computational forensics aids us to model the uncertain. At the crime scenes, we usually get incomplete or broken evidences. These evidences are later on modeled by the computational forensic tool which gives us first clues from its largest biometric database (fingerprints, criminal histories, mug-shots, scar and tattoo, physical characteristics like height, weight, hair and eye color and aliases), which is a collection of significant information regarding the criminals, their criminal......

Words: 1917 - Pages: 8

Free Essay

Computer Forensics

...Computer Forensics Through the Years Prof. Pepin Galarga Computer Forensics Sep 11, 2010 Table of Content Introduction …………………………………………………………………………………Page 2 The Early Years……………………………………………………………….......................Page 3 Early Training Programs …………………………………………………………………....Page 4 Typical Aspects of Computer Forensic Investigations ……………………………………..Page 5 Legal Aspects of Computer Forensics …………………………………………..……...…..Page 6 Conclusion ………………………………………………………………………………….Page 7 References………………………………………………………………………………..…Page 8 Introduction If you manage or administer information systems and networks, you should understand computer forensics. Forensics is the process of using scientific knowledge for collecting, analyzing, and presenting evidence to the courts. (The word forensics means “to bring to the court.”) Forensics deals primarily with the recovery and analysis of latent evidence. Latent evidence can take many forms, from fingerprints left on a window to DNA evidence recovered from blood stains to the files on a hard drive. Because computer forensics is a new discipline, there is little standardization and consistency across the courts and industry. As a result, it is not yet recognized as a formal “scientific” discipline. Image by Flickr.com, courtesy of Steve Jurvetson Computer forensics is the study of extracting, analyzing and documenting evidence from a computer system or network. It is often used by law enforcement officials to seek...

Words: 1382 - Pages: 6

Free Essay

Forensic Accouhting

...Forensic Accounting in Practice Twana Bethea BUS 508 May 21, 2013 Dr. Phyllis Praise Abstract Forensic Accounting is the application of the skills and training of a chartered accountant to disputes and investigations. Fraud is usually hidden in the accounting systems of organizations and that’s where forensic accountants play a critical role. Forensic accountants are contacted by companies when they need to figure out where a fraud was committed in their company. The accountants interview witnesses, analyze evidence such as email traffic between all parties involved. They will also freeze bank accounts if needed. They are hired to find out what happen and who was involved. If the case goes to trial they can be called to testify. The key skill of the forensic accountant is communicating complex financial transaction or data in a concise manner using images, graphs and languages that can be easily understood by non-accountants, the judiciary, and juries. With the growing complexity of business related investigations, Forensic Accounting professionals are increasing and the need is as well for investigations of business and financial issues. Forensic Accounting Practices Forensic Accounting has been in exist for many years, today there have been an increase in the need for this type of profession. Forensic accounting is the practice of integration of accounting, auditing and investigative skills. The accountings provide a court with an accounting analysis on the......

Words: 1442 - Pages: 6

Free Essay

Mathematics and Forensics

...Mathematics and Forensics 8 March, 2015 Math History - 109 In a world filled with technology, accountability, and a desire for higher quality of living; the world owes it all to math. As children grow up and are taught mathematics in countries all over the world; they are all being taught the same language. Math is the universal language of the world and math has changed the world from the time of the Egyptians to the present day era of technology. Mathematicians like Nicolaus Copernicus gave the world the truth of the universe with heliocentrism, while Isaac Newton gave the world the modern laws of physics. Mathematics has even paved its way into music with each beat of music being timed by numbers. Math is everywhere and people with brilliant minds can use mathematics to contribute to the world in very positive ways. One such way is the science of forensics. Without math, forensics could not exist. As population growth increases at an alarming rate, people have to find ways of holding people accountable for unlawful behavior. Forensic science has allowed civilization to evolve and become less barbaric and move towards factual based evidence when solving crimes against nature. Forensic science measures facts involving a crime and figure out the truth behind those measurements. Whether it is the skid marks from a vehicle collision or blood splatter analysis; mathematics is the reason why this can be done. Forensics have paved the way to a better justice system......

Words: 1097 - Pages: 5

Free Essay

Forensic Psychology

...Forensic Psychology Name Institution Date Forensic Psychology refers to the formal intersection between the scientific section of psychology and the criminal justice systems. It involves having a thorough understanding of the criminal systems applied in various jurisdictions by constantly evaluating them at a global perspective (Bartol &Bartol, 2012). The scientific aspect of it takes this information and analyses this information and interrelates it with attorney generals, judges and other legal professionals. Moreover, the field is based on scrutinizing witness testimonies in an attempt to check its validity and make informed decisions when dealing with ambiguous court cases. The roles of forensic psychologists are multivariate. This is because they perform diverse roles according to the settings, circumstances and nature of the job. For instance, they train and evaluate police officers and, members of other law enforcement organizations. They also advise judges in determining court cases (Bartol &Bartol, 2012). For instance, when the juries are dealing with ambiguous court cases of rape, insanity or murder, all arising from mental in-capabilities of the assailants, forensic psychologies are called based on their expertise and experience to examine, evaluate and give recommendations concerning the sentencing of the culprits. Because of these several but crucial responsibilities, the field of forensic......

Words: 762 - Pages: 4

Premium Essay

Forensic Evidence in It

...U.S. Department of Justice Office of Justice Programs National Institute of Justice APR. 04 Special REPORT Forensic Examination of Digital Evidence: A Guide for Law Enforcement U.S. Department of Justice Office of Justice Programs 810 Seventh Street N.W. Washington, DC 20531 John Ashcroft Attorney General Deborah J. Daniels Assistant Attorney General Sarah V. Hart Director, National Institute of Justice This and other publications and products of the U.S. Department of Justice, Office of Justice Programs, National Institute of Justice can be found on the World Wide Web at the following site: Office of Justice Programs National Institute of Justice http://www.ojp.usdoj.gov/nij APR. 04 Forensic Examination of Digital Evidence: A Guide for Law Enforcement NCJ 199408 Sarah V. Hart Director This document is not intended to create, does not create, and may not be relied upon to create any rights, substantive or procedural, enforceable at law by any party in any matter civil or criminal. Opinions or points of view expressed in this document represent a consensus of the authors and do not represent the official position or policies of the U.S. Department of Justice. The products, manufacturers, and organizations discussed in this document are presented for informational purposes only and do not constitute product approval or endorsement by the U.S. Department of Justice. This document was prepared under Interagency Agreement #1999–IJ–R–094......

Words: 22743 - Pages: 91

Premium Essay

Mobile Forensics

...Abstract Mobile forensics involves recovering and retrieving digital evidence or data from mobile devices under forensically sound conditions utilizing established methods (Ayers, Brothers, & Jansen, 2013). The field of mobile forensics is complicated as the variety in providers, manufacturers, propriety technologies and formats are extensive. These challenges are coupled with the fast release and upgrades to mobile devices making a forensic investigator’s job more arduous in attempting to examine and analyze these devices for the purpose of recovering data and evidence (Martin, 2008). This white paper will focus on the challenges of mobile device technology, the methodology utilized in examining these devices to recover data which is crucial to security investigations; which includes the tools, techniques and procedures necessary for gathering data from various similar devices. This paper will also focus on the training and expense of acquiring efficient forensic investigators and, as well as impending approaches for addressing challenges. Introduction “The goal of mobile forensics is the practice of utilizing sound methodologies for the acquisition of data contained within the internal memory of a mobile device and associated media providing the ability to accurately report one’s findings” Mobile devices, contrary to popular belief, includes an array of devices not limited to cellular phones and smartphones, but also include table devices, mp3 players, digital......

Words: 1628 - Pages: 7

Premium Essay

Forensic Pathology

...Forensic Pathology Have you ever just wanted to come home from a long days at work and kick off your shoes and grab some food and pig out in front of the television? You began to flick through all the channels and can’t find what you are looking for so you come to CSI Miami and this had caught your attention and now you’re toned in and intrigued of what they are doing. You find yourself yelling at the T.V. saying “how they do that?” “What is that?” “Why are they doing that?” and “how did they solve the case?” Well as you began to read further all of your questions will be answered, and you will see the real from the fake and what exactly a forensic pathologist is and as well as what it takes to become one. You will learn the ins and outs of how forensic pathologist has more than just one obligation. Forensic pathology has to do with the cause and manner of how someone died, as well as working with the police and their overall investigation it is almost like they are an investigator too. There is a lot of schooling and training that goes into becoming a forensic pathologist. As you continue further you will see that forensic pathology is a part of everyday life because, someone passes on every day. Forensic pathologist are specially trained doctors/physicians that study and examine the bodies of people who are deceased suddenly, violently, or unexpectedly. It is their job to figure out the immediate reason for this cessation of life. What are the duties of a forensic......

Words: 1288 - Pages: 6