Digital Forensics: Essential Competencies of Cyber-Forensics Practitioners

Author(s):  
Chamundeswari Arumugam ◽  
Saraswathi Shunmuganathan
Author(s):  
Abhineet Anand ◽  
M. Arvindhan

Digital forensics is the science of preserving and analyzing digital data; this data can then be used in court cases as well as for crime detection and prevention. Digital forensics began in the 1970s and was initially used as a tool for fighting financial crime. Today, with computers and digital devices being an integral part of our professional and private lives, digital forensics are used/needed in a wide variety of disputes. Data Acquisitions is described and discuss different techniques or methodology obtain the data, facts, and figures from different resource and at a different level of the system.


2019 ◽  
pp. 1157-1177
Author(s):  
Asha Joseph ◽  
K. John Singh

This chapter is about an ongoing implementation of a digital forensic framework that could be used with standalone systems as well as in distributed environments, including cloud systems. It is oriented towards combining concepts of cyber forensics and security frameworks in operating systems. The framework consists of kernel mechanisms for data and event monitoring. The system monitoring is done in kernel mode by various kernel modules and forensic model mapping is done in user mode using the data collected by those kernel modules. Further, the authors propose a crime model mapping mechanism that makes use of rule sets that are derived from common cyber/digital crime patterns. The decision-making algorithm can be easily extended from a node in a computing cluster, to a cloud. The authors discuss the challenges to digital forensics in distributed environment and cloud extensions and provide some case studies where the proposed framework is applied.


Author(s):  
Kirti Raj Raj Bhatele ◽  
Deepak Dutt Mishra ◽  
Himanshu Bhatt ◽  
Karishma Das

This chapter provides prerequisites associated with cyber crimes, cyber forensics, and law enforcement. It consists of a brief introduction to the definition of cyber crimes, its classification, challenges associated with it and how it evolved with time, impact on the society, cyber terrorism, and the extent of problem scalability along with focusing on law enforcement aspects associated with the tracking and the prevention from such type crimes. The aspects discussed here include various cyber laws and law enforcement techniques introduced by various countries throughout the world which helps them to fight against cyber crimes. The cyber laws discussed include Australian, Canadian, United States, United Kingdom, and Indian law. This chapter also deals with the digital/cyber forensics, what does digital/cyber forensics mean, its types, and laws/rules revolving around them, like how to collect evidence, jurisdictions, and e-discovery.


Author(s):  
Asha Joseph ◽  
K. John Singh

This chapter is about an ongoing implementation of a digital forensic framework that could be used with standalone systems as well as in distributed environments, including cloud systems. It is oriented towards combining concepts of cyber forensics and security frameworks in operating systems. The framework consists of kernel mechanisms for data and event monitoring. The system monitoring is done in kernel mode by various kernel modules and forensic model mapping is done in user mode using the data collected by those kernel modules. Further, the authors propose a crime model mapping mechanism that makes use of rule sets that are derived from common cyber/digital crime patterns. The decision-making algorithm can be easily extended from a node in a computing cluster, to a cloud. The authors discuss the challenges to digital forensics in distributed environment and cloud extensions and provide some case studies where the proposed framework is applied.


This chapter evaluates the most relevant methodologies and best practices for conducting digital investigations, preserving digital forensic evidence and following chain of custody (CoC) of cybercrimes. Cybercriminals are assuming new strategies to launch their sophisticated cyberattacks within the ever-changing digital ecosystems. The authors recommend that digital investigations must continually shift to tackle cybercrimes and prosecute cybercriminals to increase international collaboration networks, to share prevention knowledge, and to analyze lessons learned. They also establish a cyber forensics model for miscellaneous ecosystems called cyber forensics model in digital ecosystems (CFMDE). This chapter also reviews the most important categories of tools to conduct digital investigations. Nevertheless, as the cybercrime sophistication keeps improving, it is also necessary to harden technologies, techniques, methodologies, and tools to acquire digital evidence in order to support and make cyber investigation cases stronger.


Author(s):  
Mohammad Suaib ◽  
Mohd. Akbar ◽  
Mohd. Shahid Husain

Digital forensic experts need to identify and collect the data stored in electronic devices. Further, this acquired data has to be analyzed to produce digital evidence. Data mining techniques have been successfully implemented in various applications across the domains. Data mining techniques help us to gain insight from a large volume of data. It helps us to predict the pattern, classify the data, and other various aspects of the data based on the users' perspective. Digital forensics is a sophisticated area of research. As the information age is revolutionizing at an inconceivable speed and the information stored in digital form is growing at a rapid rate, law enforcement agencies have a heavy reliance on digital forensic techniques that can provide timely acquisition of data, zero fault data processing, and accurate interpretation of data. This chapter gives an overview of the tasks involved in cyber forensics. It also discusses the traditional approach for digital forensics and how the integration of data mining techniques can enhance the efficiency and reliability of the existing systems used for cyber forensics.


Author(s):  
Mohammad Zunnun Khan ◽  
Anshul Mishra ◽  
Mahmoodul Hasan Khan

This chapter includes the evolution of cyber forensics from the 1980s to the current era. It was the era when computer forensics came into existence after a personal computer became a viable option for consumers. The formation of digital forensics is also discussed here. This chapter also includes the formation of cyber forensic investigation agencies. Cyber forensic life cycle and related phases are discussed in detail. Role of international organizations on computer evidence is discussed with the emphasize on Digital Forensic Research Workshop (DFRWS), Scientific Working Group on Digital Evidence (SWDGE), chief police officers' involvement. Authenticity-, accuracy-, and completeness-related pieces of evidence are also discussed. The most important thing that is discussed here is the cyber forensics data.


2020 ◽  
pp. 64-81
Author(s):  
Kirti Raj Raj Bhatele ◽  
Deepak Dutt Mishra ◽  
Himanshu Bhatt ◽  
Karishma Das

This chapter provides prerequisites associated with cyber crimes, cyber forensics, and law enforcement. It consists of a brief introduction to the definition of cyber crimes, its classification, challenges associated with it and how it evolved with time, impact on the society, cyber terrorism, and the extent of problem scalability along with focusing on law enforcement aspects associated with the tracking and the prevention from such type crimes. The aspects discussed here include various cyber laws and law enforcement techniques introduced by various countries throughout the world which helps them to fight against cyber crimes. The cyber laws discussed include Australian, Canadian, United States, United Kingdom, and Indian law. This chapter also deals with the digital/cyber forensics, what does digital/cyber forensics mean, its types, and laws/rules revolving around them, like how to collect evidence, jurisdictions, and e-discovery.


Author(s):  
Shafique Ahmed Awan ◽  
M. Malook Rind ◽  
Mazhar Ali Dootio ◽  
Abdullah Ayub Khan ◽  
Aftab Ahmed Shaikh ◽  
...  

2019 ◽  
Vol 10 (1) ◽  
pp. 24-29
Author(s):  
Aparna Chaturvedi ◽  
Ashish Awasthi

Cyber Forensics is a branch of forensic science that is aimed to restore, collect and examine the digital evidence of materials found in digital devices, in relation to cybercrimes. With the advancement in cyber area, frequent use of internet and technologies leads to cyber-attacks. Cyber forensic is opted for acquiring electronic information and investigation of malicious evidence found in system or on network in such a manner that makes it admissible in court. It is also used to recover lost information in a system. The retrived information is used to prosecute a criminal. Number of crimes committed against an internet and malware attacks over the digital devices have increased. This paper contains a brief review of the literature aimed to identify the relevant pieces of knowledge in the digital forensics field.


Sign in / Sign up

Export Citation Format

Share Document