Friday, October 19, 2012

October 2012 : some challenges in digital evidence

This week we will have an ENFSI-meeting in Rome of the Forensic IT Working group, were the new developments in forensic IT are discussed as well as solutions.

In Forensic IT currently we have the next seven long term challenges :

  1. big data 
  2. malware
  3. number of students in ICT
  4. encryption 
  5. different formats 
  6. diversity 
  7. presenting complicated evidence in court
  1. big data 
The issue with big data is that cases are growing rapidly. If all data from a person is collected in a case, the amount grow rapidly, also due to multimedia and fast datalinks. Currently indexing over 100 Petabyte is not easy, also HADOOP has issues with it and new solutions are developed by social networks such as facebook. Indexing video data is also not easy. Filtering is important, and triage is one of the solutions. Cloud computing is an issue here, since often the data is available in other states with different jurisdictions.

2. malware

Issues with malware developers is that it is difficult to investigate. Zero day exploits can be seen more often, and botnets and other attacks of many systems such as SCADA, are an issue. Malware on mobile phones is so common that the FBI placed a warning. Lawyers might use it as defense. Even medical devices can be infected by malware. Also people claim that governments  develop malware.

3. number of students in ICT

ICT and related studies are not very popular, so it is difficult to fill all vacancies. Software engineers are difficult to hire, and are needed for all developments.

4. encryption

With encryption methods getting more sophisticated and also implemented in hardware such as SSD-disks, live forensics methods are the choice instead of trying to break the keys. However live systems should be shielded from network communication, since it is possible to remotely wipe systems.

5. different formats
Many developers will make new file formats which deviate from the file format, and use coding which is not public. Analysing and repairing them is important. The golden age as Simon Garfinkel mentioned  is over, and we will enter a digital forensic crisis.

6. diversity 
There are many hardware  manufacturers as well as software developments. It is hard to keep up with developments and have methods available for doing a forensic analysis. Mobile device forensics with chip extraction is an option, however remains time consuming and expensive.

7. presenting complicated evidence in court
Often digital evidence especially in hacking cases is difficult to interpret for juries and judges. The challenge for the forensic examiner is to present the evidence in court such that it is acceptable. Many times new methods have to be developed and validated for the court, and also privacy laws have to be taken care of.


2 comments:

DNA Testing Immigration said...

Forensic Science uses a number of experiments researches and tests to resolve all types of issues.It plays an important role in our life.

SIFS INDIA said...

Thanks for this!!!
SIFS INDIA Experts Opinions and Reports are acceptable in every court in India and abroad (In India- U/S 45 of Indian Evidence Act) and Our Educational Courses Certificates are valid and legal.
SIFS-Investigation Department
2443, Basement, Hudson Lane,Kingsway Camp,Behind GTB Metro Station, Delhi - 110009
Phone : 09953 546 546, 09871 502 343
Email : contact@sifsindia.com, forensicdocument@gmail.com
Website : www.sifsindia.com, www.sifs.in , www.sifs.org.in