Effective Digital Forensics Research is Investigator- Centric Robert J. Walls Brian Neil Levine Marc Liberatore Clay Shields University of Massachusetts Amherst Georgetown University rjwalls@cs.umass.edu 1 forensics.umass.edu
rjwalls@cs.umass.edu 2 forensics.umass.edu
rjwalls@cs.umass.edu 2 forensics.umass.edu
rjwalls@cs.umass.edu 3 forensics.umass.edu
rjwalls@cs.umass.edu 3 forensics.umass.edu
Digital forensics contends with the CSI-effect . rjwalls@cs.umass.edu 4 forensics.umass.edu
and security ^ Digital forensics contends with the CSI-effect . rjwalls@cs.umass.edu 4 forensics.umass.edu
Digital forensics lacks a solid scientific foundation . rjwalls@cs.umass.edu 5 forensics.umass.edu
Digital forensics struggles with practical challenges . rjwalls@cs.umass.edu 6 forensics.umass.edu
Digital forensics impacts people directly . rjwalls@cs.umass.edu 7 forensics.umass.edu
rjwalls@cs.umass.edu 8 forensics.umass.edu
Security, privacy, & forensics? rjwalls@cs.umass.edu 9 forensics.umass.edu
rjwalls@cs.umass.edu 10 forensics.umass.edu
5 principles for researchers . rjwalls@cs.umass.edu 11 forensics.umass.edu
rjwalls@cs.umass.edu 12 forensics.umass.edu
rjwalls@cs.umass.edu 13 forensics.umass.edu
Digital Forensics is Investigator-Centric 1 rjwalls@cs.umass.edu 14 forensics.umass.edu
1: Forensics is Investigator-Centric > Research is investigator driven. rjwalls@cs.umass.edu 15 forensics.umass.edu
1: Forensics is Investigator-Centric > Research is investigator driven. > Consider both goals and constraints. rjwalls@cs.umass.edu 15 forensics.umass.edu
1: Forensics is Investigator-Centric > Research is investigator driven. > Consider both goals and constraints. > Break the rules lose the case. rjwalls@cs.umass.edu 15 forensics.umass.edu
1: Forensics is Investigator-Centric > Research is investigator driven. > Consider both goals and constraints. > Break the rules lose the case. > The rules change. rjwalls@cs.umass.edu 15 forensics.umass.edu
Forensics and law are inseparable 2 rjwalls@cs.umass.edu 16 forensics.umass.edu
2: Forensics and law are inseparable > Law is struggling to keep up. rjwalls@cs.umass.edu 17 forensics.umass.edu
2: Forensics and law are inseparable > Law is struggling to keep up. > How does seizure apply to data? rjwalls@cs.umass.edu 17 forensics.umass.edu
2: Forensics and law are inseparable > Law is struggling to keep up. > How does seizure apply to data? > Unproven techniques are risky. rjwalls@cs.umass.edu 17 forensics.umass.edu
Investigations are about People 3 rjwalls@cs.umass.edu 18 forensics.umass.edu
3: Investigations are about people > Focus on the person, not the machine. rjwalls@cs.umass.edu 19 forensics.umass.edu
3: Investigations are about people > Focus on the person, not the machine. > Intent is outside of security domain. rjwalls@cs.umass.edu 19 forensics.umass.edu
3: Investigations are about people > Focus on the person, not the machine. > Intent is outside of security domain. > Crime may not violate security. rjwalls@cs.umass.edu 19 forensics.umass.edu
Still useful to catch the Dumb Ones 4 rjwalls@cs.umass.edu 20 forensics.umass.edu
4: Still useful to catch the dumb ones > Doesn’t have to be foolproof to be useful. rjwalls@cs.umass.edu 21 forensics.umass.edu
4: Still useful to catch the dumb ones > Doesn’t have to be foolproof to be useful. > Tech savvy criminals aren’t more dangerous. rjwalls@cs.umass.edu 21 forensics.umass.edu
4: Still useful to catch the dumb ones > Doesn’t have to be foolproof to be useful. > Tech savvy criminals aren’t more dangerous. > 40% is still good. rjwalls@cs.umass.edu 21 forensics.umass.edu
Keep it 5 Simple rjwalls@cs.umass.edu 22 forensics.umass.edu
5: Keep it simple > Make it simple for investigators to use it. rjwalls@cs.umass.edu 23 forensics.umass.edu
5: Keep it simple > Make it simple for investigators to use it. > Must be within Investigator capabilities. rjwalls@cs.umass.edu 23 forensics.umass.edu
5: Keep it simple > Make it simple for investigators to use it. > Must be within Investigator capabilities. > Often simpler non-computer solutions. rjwalls@cs.umass.edu 23 forensics.umass.edu
Forensics research without these principles is not forensics. rjwalls@cs.umass.edu 24 forensics.umass.edu
1: Forensics is Investigator-Centric. 2: Forensics and law are inseparable. 3: Investigations are about people. 4: Still useful to catch the dumb ones. 5: Keep it simple. This work was supported in part by NSF awards CNS-1018615, CNS-0905349, and DUE-0830876, and in part by NIJ award 2008-CE-CX- K005. rjwalls@cs.umass.edu 25 forensics.umass.edu
Recommend
More recommend