Computer Investigation Process…
by cisspfix on Sep.18, 2009, under General
“Necessity is the Mother of all Inventions”, sophistication of digital environment lead to the discovery of Computer Forensics. Computer Forensics is an investigative process of collecting and examining of electronic evidence to form a structured report which can be produced in a court as a evidence. Computer Forensic is introduced when crime is facilitated either by using computer or on Computer or Network itself. Computer Forensic also deals with the issue, such as Privacy, Copy Infringement, and Software ownership. For the collection of Electronic Evidence, it is required to follow certain pre-established procedure and steps, which ensures the identity of culprit. By following such methodologies, computer crime investigation can be done effectively and efficiently.
Investigating Computer Crimes
If any forensic investigation involves Computer in one way or another, then the investigation is coined as Computer Forensic Investigation. Development of technology from the last two decades is so rapid that it made lot easier for criminals to hide information about their crimes, one advantage enjoyed by investigators is that any type of Computer Crime results in some type of clue and evidence stored on computer but still there are number of Cyber Crimes which requires Computer Forensic investigation, some of them are:
- Unauthorized access
- Property Theft (misuse of information)
- Forgery
- Privacy breach
- Computer fraud.
- Child pornography
Methodology of Forensic Investigation
First and Foremost step of Investigation process is Complaint. Investigation will never going to occur if it remain un-noticed, unless appropriate authorities are not aware of the crime being committed, criminal gets away with crime. There are some fundamental steps involved in forensic investigation,
Preparation (of the investigator, not the data)
Computer Forensic Investigators must be prepared with the tools and procedures used during investigation, these tools include Hardware as well as Software which are used to secure evidence and data.
Collection (the data)
Next important step is to collect damaged data as efficiently as possible, damaged data typically includes deleted files, formatted hard disk, deleted partitions or any other form of electronic storage medium like compact disk, USB drives etc. Special care must be taken when handling computer evidence: most digital information is easily changed, and once changed it is usually impossible to detect that a change has taken place (or to revert the data back to its original state) unless other measures have been taken.
Analysis
This step involves proper examination and evaluation of gathered information. During analysis it is very important that the collected data and information aren’t modified in any way, otherwise property of data will change. Therefore it is very necessary to use tools that won’t modify data. Chiefly Forensic Analysis consists of manual review of material on the media, reviewing the Windows registry for suspect information, discovering and cracking passwords, keyword searches for topics related to the crime, and extracting e-mail and images for review.
Reporting
After the completion of Analysis, a detailed report is generated enlisting all possible evidences and information. This Report is produced as a legal evidence before court whenever required.
The Role of Evidence
Collection of Evidence is the sole reason behind the Forensic Investigation; therefore Evidence plays a vital role in Computer Forensic Investigation. The Digital Evidence should be properly studied, preserved and presented. These Evidences are presented in court during legal process and questioning. Collection of Evidence is done in several steps, first of which is Identification of Evidence followed by the Recovery of Evidence, this is accomplished viewing log files, recovering data using different forensic tools. One more important point which should be kept in mind during Investigation is security of Data, Digital Evidence and Data must be secured throughout the investigation.
Volatile Evidence
Data stored in temporary storage media [Random Access Memory(RAM), Cache Memory, Onboard memory of different peripherals like Graphics and video card etc ) are termed as Volatile Memory because data stored in it depends on the electricity for their existence, as soon as the system is powered off, stored data will be permanently vanished. It is therefore very important to collect such data first.
Acquiring Evidence
This is the next step of processing evidence. Acquisition process involves in making exact copy of digital evidence. It is very important that the original data isn’t altered, damaged or destroyed in doing so.
Disk Imaging
This technique is used to preserve the original evidence as it was seized. Disk imaging is different from back up of a disk in a way that while creating backup, only active files of a system are copied. Whereas during disk imaging exact replica of original disk is formed.
Retaining Data and Timestamp:
Retaining the Date and Time of creation and modification of Data is a vital factor to be kept in mind in criminal issues. Timestamp in a file are very important evidence, since the timestamp is according to the system clock which is in turn depends on the time zone. It should always investigated that which time zone is configured on the system, it may be possible that criminal deliberately change the time zone so that the data does not co-relate with the real time.
Investigating Company Policy Violations
Investigation Process of Companies are totally different from the other types of Investigations. Normally when Cyber crime occurs on house computers, police are called for proper investigation. In a Corporate World a team of some specialized skilled peoples are formed which is known as Incident Response Team. This team is responsible for finding the type of Cyber crime occurred and eventually contact police for further investigation, depending upon the type of crime occurred and what is found in investigation. This Incident Response Team also deal with the internal matter of the company like security breach by company employee, unauthorized access to company’s computer etc. It is not always necessary to include police investigation when policies are violated, sometime it is dealt by company itself by taking disciplinary action against the accused employee. But still Forensic Investigations is important because these procedures create a tighter case, thus leaving no point to argue the facts.
November 2nd, 2009 on 6:44 PM
Other variant is possible also
March 2nd, 2010 on 10:26 PM
Great article, Thank You! Just came across this interesting quote and wish to share – “Friends show their love – in times of trouble, not in happiness.” Have a nice day!
April 19th, 2010 on 11:41 PM
My friend mentioned to me your blog, so I thought I’d check it out. Very interesting material, will be back for more!
April 20th, 2010 on 9:21 PM
OH…And I have run 3 Virus scans and a defrag and its come up with nothing
_____________
grow taller
April 22nd, 2010 on 3:01 AM
Outstanding, thanks for posting!
April 23rd, 2010 on 5:47 AM
I just needed to say that I found your site via Goolge and I am glad I did. Keep up the good work and I will make sure to bookmark you for when I have more free time away from the books. Thanks again!
April 27th, 2010 on 9:54 PM
Good post mate!! Keep ‘em flowing!
May 11th, 2010 on 6:54 PM
Hi there could I quote some of the material found in this blog if I provide a link back to your site?
May 12th, 2010 on 7:06 AM
Hi Yes you are welcome to quote anything from my blog. It a pleasure if you provide link back to my site. Give me your blog address, so sometime I can also read your thoughts.
May 12th, 2010 on 7:57 AM
I am unquestionably bookmarking this blog and sharing it with my acquaintances. You will be getting plenty of visitors to your website from me!
May 15th, 2010 on 4:29 PM
May 20th, 2010 on 2:14 AM
nice post. thanks.
May 20th, 2010 on 3:28 PM
I would like to thank you for the efforts you have made in writing this article. I am hoping the same best work from you in the future as well and i have start my own blog now, it’s about to domain name , thanks for your effort
May 24th, 2010 on 1:00 AM
Thankfully, whilst I was searching bing I came across your quality internet site. I must say the content and information here is top grade, and will be really helpful to me and I suspect others. To be sure I come back regularly I have added the website to my favourites.
free ecards
May 26th, 2010 on 2:36 AM
Nice! Hey I think you have a great blog going here,I found it on Bing and plan on returning regularly for the information that you all are providing.
May 29th, 2010 on 6:58 AM
The layout for your blog is a bit off in Opera. Nonetheless I like your web site. I may have to install a “normal” browser just to enjoy it.
May 30th, 2010 on 3:23 AM
Hello may I quote some of the content from this post if I reference you with a link back to your site?
May 30th, 2010 on 10:43 AM
This blog helped me explain this subject to my son. Thanks
May 31st, 2010 on 4:06 AM
Yes ofcourse you can quote anything from my Blog… Knowledge is for all…. Thanks
May 31st, 2010 on 4:12 AM
Thanks for the information….. Try Mozilla Firefox….. I will look at the problem and try to rectify it…..
May 31st, 2010 on 12:34 PM
Howdy there,just identified your Blog when i google something and wonder what web hosting do you use for your web site,the speed is more faster than my blog, i really need it.will back to check it out,i appreciate it!
June 1st, 2010 on 8:12 PM
Hi, I am visit your site with my I phone. You have a very nice desgin and interest post. At home I will add you to my rss reader, didn’t mess that up.
June 2nd, 2010 on 6:46 AM
I had problems seeing in Chrome but it works fine in Internet Explorer. Anway, the post is good. I am very happy to have discovered this.
June 2nd, 2010 on 7:06 AM
Excellent. I haven’t had the same view here in Russia, but I suppose that isn’t too too hard to imagine.
June 5th, 2010 on 8:33 AM
I really enjoy keeping up with these articles. It completely helps me get through my day.
June 16th, 2010 on 10:03 AM
You have really great taste on catch article titles, even when you are not interested in this topic you push to read it.
June 16th, 2010 on 11:27 AM
You did a good job.
June 17th, 2010 on 9:24 PM
Hey may I use some of the information from this entry if I reference you with a link back to your site?
June 22nd, 2010 on 4:21 AM
Thanks for posting this great information
June 25th, 2010 on 3:43 AM
My cousin recommended this blog and she was totally right keep up the fantastic work!