#share-button{ border-top:1px solid #ccc;border-bottom:1px solid #ccc; padding:8px 0px;margin:10px 0px;width:100%;float:left;height:20px;font-family: 'Noto Sans', sans-serif; font-size: 12px; font-weight: 400;} #share-button p{ float:left; background:#fafafa; display:block; padding:5px 8px !important; margin-top:-3px; border-radius:6px 6px;} #share-button a{ position:relative; float:left; border-radius:6px 6px; display:block; color:#fafafa; padding:5px 8px; margin:-3px 3px 3px;} #share-button a:hover{ }

Search This Blog

Showing posts with label paper. Show all posts
Showing posts with label paper. Show all posts

Friday, June 27, 2014

Adding digital forensic readiness to the email trace header

Abstract
The protection strategies proposed and implemented to protect users against spam, focus on specific areas that need tobe protected e.g. Anti-Spam filters that protect the user’s mailbox from bulk unsolicited email. Digital forensics is based on scientifically proven methods to collect and analyze digital information. Employing digital forensic techniques to gather and analyze email information provides a new dimension to the fight against spam.
Adding digital forensic readiness to email will allow for the gathering of forensic information. The digital forensic information can be used to verify information contained in the trace header of an email. The authors propose augmentations to the receive header, that is part of the trace header, currently specified for SMTP to implement digital forensic readiness.
Incorporating digital forensics, adds a level of integrity to the trace header information that can be used for other purposes e.g. creating a spam detection mechanism or tracing the origin of spam. Digital forensic information is added to the email envelope so there is no effect to the content of the email. Therefore, the content remains untouched.
The authors examine the addition of digital forensic information and highlight the changes that will need to be implemented in the SMTP trace header. The authors propose the gap detection algorithm that is used to find gaps in the received-tokens of the received header. The information that is generated by the gap detection algorithm is also discussed. In conclusion, the addition of digital forensic readiness adds a level of integrity to the SMTP trace header that can be used to add a level of trust.

Keywords-SMTP; Spam; Digital forensics; Digital forensic
information; Digital forensic readiness;
F.R. Van Staden and H.S. Venter
Download Link :

A Digital Forensic Investigation Model for Online Social Networking

Abstract
The growth of Online Social Network ing (OSN) has encouraged new ways of communicating and sharing information and is used regularly by millions of people; it now seem s that OSN will be an enduring part of everyday life. The rapid growth of OSN has also resulted in an increase in its use for significant criminal activities and perpetrators are becoming increasingly sophisticated in their attempts to use technology in order to evade detection and perform crim inal acts. For this reason a standard model of digital forensic investigation for OSN will be proposed in this paper. The proposed model incorporates the existing traditional fram eworks, allowing us to compile a comprehensive digital forensic investigation model specifically for OSN.
By : Norulzahrah M. Zainudin, Madjid Merabti, David Llewellyn-Jones
Download Link :

ANALISIS ALGORITMA INSERTION SORT, MERGE SORT DAN IMPLEMENTASINYA DALAM BAHASA PEMROGRAMAN C++

ABSTRACT

This paper presents the study of implementation and performance in sorting process, using two different algorithms, namely Insertion Sort and Merge Sort. In the first stage, the two algorithms were implemented in C++ language to sort several numbers typed by a user. In the second stage, the source codes for those algorithms were modified to enable sorting randomly generated numbers with the amount as requested by the user. To find out how well they performed in sorting out the data, therefore in the last stage the two algorithms were tested to sort random numbers with predetermined amount ranges and the results were compared. From the experiments performed, merge sort algorithm had shown a better performance, particularly in a large number of data (> 10000). Insertion sort algorithm has the advantage in lower complexity algorithm, notably in the best case condition and since it does not use recursion routines in sorting process, hence it does not require as much storage space or memory as needed by merge sort algorithm. 
Keywords: Algorithm, Insertion Sort, Merge Sort, Performance, C++ language
ABSTRAK

Makalah ini mengetengahkan kajian implementasi dan performa proses pengurutan menggunakan dua algoritma yang berbeda, yaitu Insertion Sort dan Merge Sort. Pada tahap pertama, kedua algoritma tersebut diimplementasikan dalam bahasa C++ untuk mengurutkan sejumlah angka yang diketikkan oleh pengguna. Pada tahap kedua, kode sumber untuk kedua algoritma tersebut diubah untuk dapat mengurutkan angka yang dihasilkan secara acak dengan jumlah angka sebanyak permintaan dari pengguna. Untuk mengetahui seberapa baik performa dalam mengurutkan data, maka dalam tahap terakhir, kedua algoritma tersebut mengurutkan sejumlah angka acak dengan rentang jumlah yang sudah ditentukan dan hasilnya kemudian dibandingkan. Dari eksperimen yang sudah dilakukan, algoritma merge sort telah memperlihatkan performa yang lebih baik, khususnya untuk jumlah data yang banyak (> 10000). Adapun algoritma insertion sort memiliki keuntungan dalam hal kompleksitas algoritma yang lebih rendah terutama dalam kondisi best case dan karena tidak  menggunakan rutin rekursi dalam proses pengurutan, maka tidak membutuhkan ruang penyimpanan atau memori sebanyak algoritma Merge Sort. 
Kata kunci : Algoritma, Insertion Sort, Merge Sort, Performa, Bahasa C++
By : Arief Hendra Saptadi and Desi Windi Sari
Download Link :
http://

Analisis Forensika Digital Pada Blackberry Untuk Mendukung Penanganan Kasus Cybercrime Menggunakan Smartphone

Abstrak
Bertambahnya pengguna dan jenis smartphone, berdampak pula pada aktivitas cybercrime. Smartphone akan menjadi trend utama kegiatan cybercrime di masa yang akan datang. Blackberry adalah salah satu dari
beberapa jenis/platform smartphone yang saat ini banyak digunakan di beberapa negara termasuk Indonesia. Penelitian ini memuat sejumlah langkah penerapan forensika digital pada blackberry untuk sebuah contoh kasus non-violent cybercrime. 
Penelitian difokuskan pada manual dan logical acquisition data pada embedded dan removable memory. Melalui bantuan sejumlah tools serta teknik searching telah didapat beberapa data yang dapat dijadikan sebagai bukti digital yang kuat pada kasus contoh kasus yang dihadapi.
Kata Kunci: Forensika Digital, Smartphone, Cybercrime, Blackberry, Bukti Digital.
By : Yudi Prayudi and Muhammad Iqbal
Download Link :
http://

An Approach for Managing Knowledge in Digital Forensic Examinations

Abstract

Computers and digital devices are continuing to evolve in the areas of storage, processing power, memory, and features. Resultantly, digital forensic investigations are becoming more complex due to the increasing size of digital storage reaching gigabytes and terabytes. Due to this growth in disk storage, new approaches for managing the case details of a digital forensics investigation must be developed. In this paper, the importance of managing and reusing knowledge in digital forensic examinations is discussed, a modeling approach for managing knowledge is presented, and experimental results are presented that show how this modeling approach was used by law enforcement to manage the case details of a digital forensic examination.

Keywords: Digital Forensics, Concept Mapping, Case Domain Modeling, Digital Forensic Examinations
By : April L. Tanner and David A. Dampier
Download Link :

An Event-Based Digital Forensic Investigation Framework

Abstract

In this paper, we present a framework for digital forensics that includes an investigation process model based on physical crime scene procedures. In this model, each digital device is considered a digital crime scene, which is included in the physical crime scene where it is located.
The investigation includes the preservation of the system, the search for digital evidence, and the reconstruction of digital events. The focus of the investigation is on the reconstruction of events using evidence so that hypotheses can be developed and tested. This paper also includes definitions and descriptions of the basic and core concepts that the framework uses.
By : Brian D. Carrier and Eugene H. Spafford
Download Link :

An Examination of Digital Forensic Models

Abstract

Law enforcement is in a perpetual race with criminals in the application of digital technologies, and requires the development of tools to systematically search digital devices for pertinent evidence. Another part of this race, and perhaps more crucial, is the development of a methodology in digital forensics that encompasses the forensic analysis of all genres of digital crime scene investigations. This paper explores the development of the digital forensics process, compares and contrasts four particular forensic methodologies, and finally proposes an abstract model of the digital forensic procedure. This model attempts to address some of the shortcomings of previous methodologies, and provides the following advantages: a consistent
and standardized framework for digital forensic tool development; a mechanism for applying the framework to future digital technologies; a generalized methodology that judicial members can use to relate technology to non-technical observers; and, the potential for incorporating non-digital electronic technologies within the abstraction
By : Mark Reith, Clint Carr, Gregg Gunsch
Download Link :

An Examination of Digital Forensic Models

Abstract

Law enforcement is in a perpetual race with criminals in the application of digital technologies, and requires the development of tools to systematically search digital devices for pertinent evidence. Another part of this race, and perhaps more crucial, is the development of a methodology in digital forensics that encompasses the forensic analysis of all genres of digital crime scene investigations. This paper explores the development of the digital forensics process, compares and contrasts four particular forensic methodologies, and finally proposes an abstract model of the digital forensic procedure. This model attempts to address some of the shortcomings of previous methodologies, and provides the following advantages: a consistent
and standardized framework for digital forensic tool development; a mechanism for applying the framework to future digital technologies; a generalized methodology that judicial members can use to relate technology to non-technical observers; and, the potential for incorporating non-digital electronic technologies within the abstraction
By : Mark Reith, Clint Carr, Gregg Gunsch
Download Link :

An Ontological Approach for Digital Evidence Search

Abstract
Usage of emails for the fraudulent activities is accelerating with higher pace. There is a thirst need for the tools to analyze large collections emails forensically. Traditional Information Retrieval tools can retrieve documents those are relevant to the given query. But directly answering the questions specific to the forensics domain will make the job forensic examiners easy. In this paper a system is presented to answer questions specific to email forensics. Ontology is designed with the basic concepts of email forensics domain. Information relevant to the case under investigation is retrieved using Information Retrieval techniques. Ontology is dynamically populated with the retrieved information. Knowledge which is of interest to the forensic investigators is inferred by firing the domain specific rules with the help of inference engine. Some domain specific questions have been answered with the help of inferred knowledge. The proposed system is a prototype and it can stand as a base to develop bigger systems.

Index Terms—Digital Information Retrieval
By : Venkata Krishna Kota
Download Link :

A Small Scale Digital Device Forensics ontology

Abstract
Small Scale Digital Device Forensics (SSDDF) is a relatively new and rapidly changing field of study which is in dire need of direction. Specifically, the devices and their corresponding forensic processes and procedures are vague and in a perpetual state of uncertainty. The purpose of this paper was to develop an ontological to provide law enforcement with the appropriate knowledge regarding the devices found in the SSDD domain.
Additionally, this ontology can be used as a method to further develop a set of standards and procedures at which to approach SSDD.

Index Terms—computer and forensics, cyber and forensics, mobile and devices, PDA and forensics, forensics and small scale digital devices.
By : 
Download Link :

Digital Forensics on Small Scale Digital Devices

1 Introduction

Small Scale Digital Devices (SSDD) can be seen as a subgroup of embedded systems. An embedded system is in general a small computer with a special purpose to perform one or a few dedicated functions, e.g., a controller. The system basically consists of a microprocessor, a non-volatile memory (mostly flash) and a volatile memory (RAM) and connectors and is usually embedded as part of a complete device. Additional parts can be added to the system by design or as required. Because the embedded system is adapted to its purpose, its size and costs can be reduced. An SSDD is such a device with several appropriate build-in attachments, e.g., a graphic or network controller. Harrill and Mislan covered the terminology SSDD in [HM07] and grouped them into five categories:
• Embedded Chip Devices,
• Personal Digital Assistants (PDAs),
• Cell Phones,
• Audio / Video Devices, and
• Gaming Devices.
With the size shrinking of transistors and other device parts either more and
more functionalities can be integrated into a predefined chip size or the device can be built smaller. As a consequence, many devices cannot be assigned to only one category, e.g., multimedia smart phones with built-in digital cameras.
Such systems find their way into our normal life, e.g., in form of cell phones, MP3 player, personal organizer, router, game consoles or modern network-capable TVs. SSDDs can be used to save several personal information like contacts, photos, calendar and notes. They started to displace classic paper helpers like schedules and address books. Therefore it can be supposed that SSDDs play an important role in forensics. An SSDD can also be a non-active device, like a USB (flash) drive, which must be considered in digital forensic analysis.
The statistics of the Federal Statistical Office of Germany from January 2007 [oG07] show that the distribution of SSDDs exceeds the distribution of PCs, see Table 1.1. That is why the necessity of forensic analysis of SSDDs increased in the last few years. Forensics on SSDDs is a very young field of science and although there is a great progress in developing analyzing tools and research, this field lags behind other forensic fields. Concurrently Anti-Forensics, the science of preventing forensic analysis, is more difficult because of the small size of the devices and the user’s restricted data accessibility [vdK07].
At the moment cell phones have the greatest distribution of all SSDDs. So it is no surprise that there exist a lot of public information on cell phone forensic.
By : 
Download Link :

Digital forensics research: The next 10 years

Abstract
 
 
Today’s Golden Age of computer forensics is quickly coming to an end. Without a clear strategy for enabling research efforts that build upon one another, forensic research will fall behind the market, tools will become increasingly obsolete, and law enforcement, military and other users of computer forensics products will be unable to rely on the results of forensic analysis. This article summarizes current forensic research directions and argues that to move forward the community needs to adopt standardized, modular approaches for data representation and forensic processing.
2010 Digital Forensic Research Workshop. Published by Elsevier Ltd. All rights reserved.


By :Simson L. Garfinkel
Download Link :

Digital Forensic Trends and Future

ABSTRACT

Nowadays, rapid evolution of computers and mobile phones has caused these devices to be used in criminal activities. Providing appropriate and sufficient security measures is a difficult job due to complexity of devices which makes investigating crimes involving these devices even harder. Digital forensic is the procedure of investigating computer crimes in the cyber world. Many researches have been done in this area to help forensic investigation to resolve existing challenges. This paper attempts to look into trends of applications of digital forensics and security at hand in various aspects and provide some estimations about future research trends in this area.

KEYWORDS: Digital forensics, Image, Memory, Security, Identification, Recovery, Investigation, Intrusion, Validation.
By : Farhood Norouzizadeh Dezfoli, Ali Dehghantanha, Ramlan Mahmoud, Nor Fazlida Binti Mohd Sani, Farid Daryabar
Download Link :

Digital Forensik Apa dan Bagaimana

Abstract.
The increasing of information technology in fact followed by issues around cyber crime and computer security. Nowadays, many cases of law has opened our mind and shows us the critical of digital forensic as the method in proofing crimes beside the law and role of regulation that happening. As more criminals utilize technology to achieve their goals and avoid apprehension, there is a developing need for individuals who can analyze and utilize evidence stored on and transmitted using computers. By apllying science methods in investigating digital evidence, made digital forensic as the answer of law standing effort in digital era.

Kata kunci: digital forensik, kejahatan, bukti digital

By: Asrizal
Download Link :

DIGITAL FORENSIK DAN PENANGANAN PASCA INSIDEN

ABSTRAK

Digital Forensik merupakan bidang ilmu baru dalam dunia komputer yang berkembang pesat akhir-akhir ini dengan ditunjukannya berita-berita yang mengulas tentang kejahatan di bidang komputer serta semakin banyaknya buku-buku yang mengupas mengenai digital forensik, sehingga semakin menambah refrensi pengetahuan bagi peneliti-peneliti muda. Dengan lahirnya Undang-undang Informasi Transaksi Elektronik nomor 11 Tahun 2008, maka semakin membuat bidang ilmu ini menjadi perangkat wajib untuk membongkar kejahatan yang melibatkan dunia komputer, karena pada umumnya kejahatan komputer ini meninggalkan jejak digital, maka perlu adanya seorang ahli komputer forensik yang akan mengamankan barang bukti digital atau biasa disebut digital evidence. Komputer Forensik tentu memerlukan suatu standart operational procedure dalam mengambil bukti-bukti digital agar tidak terkontaminasi pada saat data di ambil dari digital evidence sehingga sangat memudahkan para ahli komputer forensik untuk melakukan pemulihan sistem pasca kerusakan.

Kata Kunci: Digital Forensik, Digital evidence, Forensik Disk.
By : Zuhri Ramadhan
Download Link :

Digital media triage with bulk data analysis and bulk_extractor

Abstract

Bulk data analysis eschews file extraction and analysis, common in forensic practice today, and instead processes data in “bulk,” recognizing and extracting salient details (“features”) of use in the typical digital forensics investigation. This article presents the requirements design and implementation of the bulk_extractor, a high-performance carving and feature extraction tool that uses bulk data analysis to allow the triage and rapid exploitation of digital media. Bulk data analysis and the bulk_extractor are designed to complement  traditional forensic approaches, not replace them. The approach and implementation offer several important advances over today’s forensic tools, including optimistic decompression of compressed data, context-based stop-lists, and the use of a “forensic path” to document both the physical location and forensic transformations necessary to reconstruct extracted evidence. The bulk_extractor is a stream-based forensic tool, meaning that it scans the entire media from beginning to end without seeking the disk head, and is fully parallelized, allowing it to work at the maximum I/O capabilities of the underlying hardware (provided that the system has sufficient CPU resources). Although bulk_extractor was developed as a research prototype, it has proved useful in actual police investigations, two of which this article recounts.
Keywords: Digital forensics, Bulk data analysis, bulk_extractor, Optimistic decompression, Windows hibernation files, EnCase, Forensic path, Margin, Parallelized forensic analysis, Stream-based forensic.
By : Simson L. Garfinkel
Download Link :

Forensic analysis of digital copiers

Abstract

Many modern digital copiers store copied and printed information on internal hard drives. Such information may have value as evidence. In order to test the possiblities for evidence extraction from copiers, two digital copiers containing hard drives were dismantled and forensically analyzed. The analysis shows that it is possible to retrieve exact copies of documents that has previously been copied and/or printed on digital copiers. The analysis method is evaluated and found to be applicable on most digital copiers containing hard drives, unless special precautions have been taken to protect the stored material. The ability to retrieve documents that have previously been printed or copied on digital copiers is valuable within forensics, but also raises new questions within information security.
By : Svein Yngvar Willassen, M.Sc,
Download Link :

Forensic Analysis of WhatsApp on Android Smartphones

Acknowledgements

The research and writing of this thesis has been one of the most significant academic challenges I ever had to face. Without the support and guidance of the following people, this study would not have been completed. It is to them that I owe my deepest gratitude.
I would sincerely like to thank my advisor, Dr. Golden G. Richard III for giving me an opportunity to conduct this thesis research under his excellent guidance. His exceptional knowledge, wisdom and understanding have inspired and motivated me. My professors, Dr. Shengru Tu and Dr. Adlai DePano for being on my thesis committee and mentoring me during my Master’s degree in Computer Science at University of New Orleans.
I am thankful to my friend Thomas Sires, for initiating my interest in Linux, making sure I keep it up and help me solve technical issues. I appreciate the help from Aisha Ali-Gombe, Joe Sylve and Andrew Case who are on our Information Assurance group, for their contributions in the Information Assurance field and answering my questions.
Finally, I would like to thank my Parents and each member in my family and friends for their unconditional love and support. I specially want to thank my husband Mr. Naveen Singh, who has been my core source of strength through every phase of this effort and constantly encouraged me to do my best. His systematic approach and kind feedback towards my thesis has helped me improve. Words cannot express how grateful I am to you.
My heartfelt gratitude to my precious daughter Navya Singh, who was born during my Master’s program and has spent many days without my complete attention. With her never give up attitude she has taught me perseverance to work around a problem until I succeed. Thank you for all your love my little girl, it kept me going.
By : Neha S. Thakur
Download Link :

FORENSICS PLAN GUIDE

FORENSICS PLAN GUIDE
Foreword
This document does not discuss First Response roles and responsibilities. The document starts from the point where an incident has been verified and the determination has been made that a forensic investigation is needed.
A Forensic Plan is a combination of dynamic checklist and template for recording computer investigation processing steps and information. The dynamic checklist aspect of the Forensic Plan originates from the precept that each investigation is unique. As such, each investigation has numerous contributing factors that have not been discovered nor anticipated during the planning phase of the investigation. Every investigation has components that are always required and present. These components create the basic framework of the checklist. The common phases of a forensic investigation are the identification phase, preservation phase, data collection phase, examination phase and reporting phase. As the investigation proceeds and more information is uncovered pertaining to other possible crimes, the checklist can be expanded to insure that the new information is properly documented and handled.
Since investigations have dynamic qualities, it would be inefficient to restructure current documentation each time new information was discovered. The establishment of a standard or template for recording investigative information facilitates accurate and timely recording of events, actions and information.
Key fingerprint = AF19 FA27 2F94defines a single concept for illustrating the basic elements of a This document 998D FDB5 DE3D F8B5 06E4 A169 4E46 Forensic Plan from the first initial contact through submission of the final Forensic Report. As the investigation proceeds through the forensic processes, checklist items will be accomplished and the results of those actions will be recorded in the Forensic Plan.
Often critical decisions are made during the initial contact and Preliminary Investigation Discussion (PID). This is where the scope and type of investigation are often decided. If an investigator is unprepared to discuss the requirements for a particular type of investigation, an inaccurate resource estimate will result. This often will lead to an unsuccessful investigation. The investigator must be prepared to discuss with management and properly estimate the resources required to complete the forensic investigation. Decisions made during the Preliminary Investigation Discussion will provide the framework for the forensic investigation. A framework is needed to insure that the agreed upon goals are accomplished.
During the forensic investigation, other information may be discovered that highlights other activities that need to be reported and possibly researched. The investigator must decide what items are essential to this particular investigation and restrict efforts accordingly.
By : Gerald L. King
Download Link :

Forensic Classification of Imaging Sensor Types

ABSTRACT

Digital images can be captured or generated by a variety of sources including digital cameras and scanners. In many cases it is important to be able to determine the source of a digital image. Methods exist to authenticate images generated by digital cameras or scanners, however they rely on prior knowledge of the image source (camera or scanner). This paper presents methods for determining the class of the image source (camera or scanner). The method is based on using the differences in pattern noise correlations that exist between digital cameras and scanners. To improve the classification accuracy a feature vector based approach using an SVM classifier is used to classify the pattern noise.

Keywords: digital forensic, imaging sensor classification, flatbed scanner, sensor noise
By :Nitin Khannaa and Aravind K. Mikkilinenib
Download Link :

Forensic Triage for Mobile Phones with DEC0DE

Abstract

We present DEC0DE, a system for recovering information from phones with unknown storage formats, a critical problem for forensic triage. Because phones have myriad custom hardware and software, we examine only the stored data. Via flexible descriptions of typical data structures, and using a classic dynamic programming algorithm, we are able to identify call logs and address book entries in phones across varied models and manufacturers. We designed DEC0DE by examining the formats of one set of phone models, and we evaluate its performance on other models. Overall, we are able to obtain high performance for these unexamined models: an average recall of 97% and precision of 80% for call logs; and average recall of 93% and precision of 52% for address books. Moreover, at the expense of recall dropping to 14%, we can increase precision of address book recovery to 94% by culling results that don’t match between call logs and address book entries on the same phone.
By : Robert J. Walls, Erik Learned-Miller and Brian Neil Levine
Download Link :