Wait a second!
More handpicked essays just for you.
More handpicked essays just for you.
Assignment on computer forensics
Computer forensics 2 pg essay
Case project 11-1 digital forensics
Don’t take our word for it - see why 10 million students trust us with their essay needs.
Recommended: Assignment on computer forensics
Introduction Forensic science is as the application of science to the law. Digital forensics, also known as computer and network forensics, has many definitions. Generally, it is considered the application of science to the identification, collection examination, and analysis of data while preserving the integrity of the information and maintaining a strict chain of custody for the data. Analysing and reporting on digital data in a way that is legally admissible. It can be used in the detection and prevent crime and in any dispute where evidence is stored digitally. Computer forensics follows a similar process to other forensic disciplines, and faces similar issues. Types of Computer Forensic Investigations Computer based crime …show more content…
But to construe this term in such a way that both the technocrats and home users may easily get its concept, it can be defined as "Developing sector-by-sector copy of a disk followed by the compression of these images in the form of a file. The captured image can be stored on any other divergent media or device and can be restored later as per need at any point of investigation." The modus operandi and approach of the working on this technology involves four key steps that include proper identification, preservation, in-depth analysis and presentation of the digital evidences In forensic investigations, one other reason for creating the images of data on hard disks can be generation of backup of the original stored data. But the core purpose of it is digital investigation and analysis in the course of frauds, forgeries, scams, etc. A good quality disk imaging backup tool by no means alters the original and true evidence. Instead, it creates a replica of all the data on other media and makes them available for detailed …show more content…
While most people think of backing up data, disk imaging programs back up not only data but also the computer's systems and configuration. Data Protection: Most users create a disk image to prevent data loss from a virus, system crash or disk failure. every hard drive is going to die eventually. If so, you can buy a new hard drive and replace the dead one, and then restore disk image to bring your computer to the state when it works well and all data is intact. System Migration: Because the performance of SSD is better than HDD, more and more people are more willing to clone HDD to SSD or migrate OS to another computer with better hardware. Thus, disk imaging is an alternative way to directly clone. Also, you can create a system image. OS Deployment: Large companies often need to buy large numbers of new computers with same or different hardware. Installing operating system and programs into each of them one by one requires a lot of time and effort and has a significant possibility of human error. Therefore, system administrators create a disk image with fully prepared applications environment of a well-adjust system to quickly deploy it to each computer by using PXE network boot. This method saves time and
Digital Forensic is the process of uncovering and interpreting electronic data that can be used in a court of law. It requires a set of standards to show how the information that is gathered, preserve, and analyzed is strictly followed. The analysts need to understand the evolution of the current technology and how it will impact how they gather their information. The investigator is able to uncover evidence and analyze it to gain the understanding of the motives, crime, and the criminal’s identity to help solve the crime. As computers and technology continue to become a part of our everyday lives, the cyber realm contains a growing realm for evince in all types of criminal investigations (Cummings, 2008) Digital forensics is a way to connect information security and law enforcement. It ensures that the digital evidence is collected in a way that it can make it into the courts in an unhampered or uncontaminated way (Dlamini, M., Eloff, J. & Eloff, M., 2009).
Forensic science has paved the way to a new world of technological advancements in solving crime, through DNA analysis, new technology such as M-Vac, improving systems such as CODIS and other investigative methods. As forensic science technology advances, the chance of an individual being able to commit a crime and walk away free without leaving any trace of evidence will lessen. While forensic science has its limitations, it can be the only way to provide an accurate account of what actually occurred at some crime scenes.
Technologies are advancing in today's world where more information is being generated, stored and distributed through digital gadgets. This requires investigators and forensic expert to increase the use of digital evidence gathering as a tool to fight against cyber-crime (International competition network, n.d.).
National Forensic Science Technology Center. (n.d.). A simplified guide to digital evidence. Retrieved from http://tychousa10.umuc.edu/CCJS321/1402/6383/class.nsf/Menu?OpenFrameSet&Login
Forensic Science, recognized as Forensics, is the solicitation of science to law to understand evidences for crime investigation. Forensic scientists are investigators that collect evidences at the crime scene and analyse it uses technology to reveal scientific evidence in a range of fields. Physical evidence are included things that can be seen, whether with the naked eye or through the use of magnification or other analytical tools. Some of this evidence is categorized as impression evidence2.In this report I’ll determine the areas of forensic science that are relevant to particular investigation and setting out in what method the forensic science procedures I have recognized that would be useful for the particular crime scene.
The transitional growth in the forensic science sector has not been without challenges. Though the world has experienced increased capabilities and scientific knowledge, which has led to faster investigations and results, many forensic experts have argued that forensic laboratory testing, in the light of 21st century technological advancements, is yet to meet the expected rate in quick available testing and analysis (Mennell & Shaw, 2006). This is with respect to the growing rate of crime and the high demand of quick crime scene testing and analysis. In the science of crime scene, analysis and interpretation of evidence is majorly dependent on forensic science, highlighting the change in the role of forensic sciences (Tjin-A-Tsoi, 2013). In the business of forensic science, time is beginning to play important role in the evidence testing and analysis which is becoming crucial in reducing ...
In conclusion, I understand in digital forensics when copying a bit by bit of a hard drive the examiner must use a write blocker, either software or hardware to avoid possibility of accidentally damaging the evidence contents. After imaging is completed the forensic examiner will have a generated hash value of the bit by bit copy of the evidence hard drive. This hash value (dіgitаl fіngerprіnt) is important to digital forensic because it shows the integrity of all evidence is maintained and to avoid tampering or spoliation. So my question is this, how can we say the integrity of the client's forensic image evidence is not tainted when we know for a fact that the client's computer was filled with malware infections (Trojan)? In my opinion by the time the examiner started investigating the client's hard drive all the
Unlike other windows, windows 8 are more secure and reliable. As for the business use this windows has a PDF version which is a good resource for the release and preview which relatively appealing for them. The other features would be useful for specific niches of a wide interest of the new refresh and reset purpose. Such features has ability to return a user`s personal computer (PC) to a pristine state without any need of wiping the stored data. On embracing such upgrading the user managers are able to captures reflect of the system prior deployment and store it in the hard drive of a computer or a network share. In a case of computer user error, computer malware or any other com...
The use of computers in homes, schools, offices, and other places has increased in the past few years due to technological developments. As computers have become important components of modern communication, their increased use has also led to the emergence of computer crimes. Computer crimes basically involve the use of a computer system to carry out an illegal activity. In attempts to lessen the frequency and impact of computer crimes, law enforcement agencies use computer forensic to investigate these offenses. Actually, computer crimes are governed by specific laws and dealt with through conducting a computer forensic investigation (Easttom & Taylor, 2011, p.337). Notably, a computer forensic investigation is usually carried out through the use of computer forensic tools, which help in collection of evidence based on the specific offense.
Presently, because the importance of digital forensics it has its own field of computer forensic expertise, training and certification.
What did they do ? Before we talk about it any further, we have to know some definitions that we use in digital forensics and digital evidence, not only two of them but the others too. This chapter will explain about it . Before we talk about it any further, we have to know the definition of what we are talking about. In the introduction we already know what digital forensic and digital evidence shortly are. In this chapter, we will more explore what they are, and some state that we found when we search about digital forensic and digital evidence. Computer forensics is a broad field and applied to the handling of crimes related to information technology. The goal of computer forensic is to securing and analyzing digital
Forensic science Forensic is a Greek word meaning ‘of the forum'. Forensic science can, therefore, be defined as the application of science to public matters. It could also be defined as the application of science to civil and criminal law. The scope of forensic science Science is wide and therefore one might wonder which science is related to forensics.
The biggest challenge investigators face and who is involved with high tech crime is the fast-paced constant evolving nature of technology. When companies come out with new devices or new versions of old devices which is almost all the time, and those who gather digital evidence must remain current to be able to locate and preserve all potential evidence. As technology evolves the capacities of these devices will rapidly increase while their form factor grows continually smaller. Investigators must preserve digital evidence to make sure it is suitable for presentation in court as well. Investigators must first never change a crime scene or alter evidence. It is their goal to document and preserve the scene exactly as it was when the crime occurred. Extreme caution and care is needed because the mere act of documenting or cataloging a crime scene means that investigators are interacting with the scene. The second concern is the physical fragility of the evidence. Care must be taken to keep items from getting wet, stepped on etc, this can also be applied to digital evidence. Investigators have been able to examine hard disk drives that have been through fires because the drives are usually air and water tight and impervious to temperatures into the thousands of degrees. The third issue is that digital evidence can be lo...
“The word ‘forensics’ means “connected with the courtroom”; so forensic science is, therefore, concerned with gathering hard evidence that can be presented in a trial” (Innes 9). Forensic science is a science that is applied specifically to legal matters, whether criminal or civil. “Few areas in the realm of science are as widespread and important as forensic science” (Hunter 12). Forensics is the one science that is most commonly used in everyday life. It is also a branch of science that incorporates other branches of science such as biology, chemistry, and etc. Since it is used almost every day “No one can dispute the importance of the contributions to society made by forensic science; the ability to solve crime is undeniably important” (Hunter 13). Forensic science has given criminal investigation a new edge. “Advances in science have opened the door for more effective evidence discovery, howev...
Digital evidence shall be treated like other evidence but more sensitive due to the possibility of the data or evidence being corrupted. Digital evidence deals with a large amount of personal information and requires special training or tools to ensure its validity. A computer forensic investigation utilizes all means necessary to retrieve all evidence is maintained, custody is established, and the proper procedures are put in place so that nothing is compromised. The National Institute of Standards and Technology (NIST) an investigator will need to follow an uncompromising code of procedures. These procedures are a part of a layered defense and are set up to divert any modifications to the source disk.