Challenges in Digital Forensic Research R.I. Ferguson ian.ferguson@abertay.ac.uk ● 2 minute intro to Digital Forensics ● Some challenges ● scale ● cloud ● the encryption boundary ● anti-forensics
Digital Forensics in 2 mins ● Sub-discipline of computer security ...sort of ● Cybercrime taxonomy ● “With”, “by”, “for”, etc. ● Goal: re-creation of events from recovered evidence ● ACPOS guidelines ● Lifecycle of an investigation ● Tools/methodology
Challenges - Scale ● Case workload ● Storage device capacity ● Number ● people ● Devices ● Speed of evolution ● Of digital environment ● Of threat
Challenges – the cloud ● Where's the data? – – May not be in/on one disk/server/country/continent – - jurisdiction – - holatilty – - heterogeneity –
The encryption boundary disk system RAM encrypted data processor un-encrypted data Video RAM Internet
Anti-forensics International Terrorism, people ● Better trafficking, drug smuggling, major financial fraud cybercriminals ● Legality of using Organisation/ Rape, murder hacker intelligence techniques in Burglary, car crime investigation? Vandalism, pickpocketing amount
Questions? ian.ferguson@abertay.ac.uk
Recommend
More recommend