Centro de Documentação da PJ
Monografia

CD290
DIGITAL FORENSICS
Digital forensics [Documento electrónico] / ed. André Årnes.- Hoboken, NJ : Wiley, 2018.- 1 CD-ROM ; 12 cm
Ficheiro de 30,7 MB em formato PDF (365 p.).
ISBN 9781119262404


INFORMÁTICA FORENSE, CRIME INFORMÁTICO, SEGURANÇA INFORMÁTICA, SOFTWARE

Preface. List of figures. List of tables. List of examples. List of definitions. List of abbreviations. List of contributors. 1 Introduction (André Årnes). 1.1 Forensic science. 1.1.1 History of Forensic Science. 1.1.2 Locard’s Exchange Principle. 1.1.3 Crime Reconstruction. 1.1.4 Investigations. 1.1.5 Evidence Dynamics. 1.2 Digital Forensics. 1.2.1 Crimes and Incidents. 1.2.2 Digital Devices, Media, and Objects. 1.2.3 Forensic Soundness and Fundamental Principles. 1.2.4 Crime Reconstruction in Digital Forensics. 1.3 Digital Evidence. 1.3.1 Layers of Abstraction. 1.3.2 Metadata. 1.3.3 Error, Uncertainty, and Loss. 1.3.4 Online Bank Fraud – A Real-World Example. 1.3.4.1 Modus Operandi. 1.3.4.2 The SpyEye Case. 1.4 Further Reading. 1.5 Chapter Overview. 1.6 Comments on citation and notation. 2 The Digital Forensics Process (Anders O. Flaglien). 2.1 Introduction. 2.1.1 Why Do We Need a Process? 2.1.2 Principles of a Forensics Process. 2.1.3 Finding the Digital Evidence. 2.1.4 Introducing the Digital Forensics Process. 2.2 The Identification Phase. 2.2.1 Preparations and Deployment of Tools and Resources. 2.2.2 The First Responder. 2.2.3 At the Scene of the Incident. 2.2.3.1 Preservation Tasks. 2.2.4 Dealing with Live and Dead System. 2.2.5 Chain of Custody. 2.3 The Collection Phase. 2.3.1 Sources of Digital Evidence. 2.3.2 Systems Physically Tied to a Location. 2.3.3 Multiple Evidence Sources. 2.3.4 Reconstruction. 2.3.5 Evidence Integrity and Cryptographic Hashes. 2.3.6 Order of Volatility. 2.3.7 Dual-Tool Verification. 2.3.8 Remote Acquisition. 2.3.9 External Competency and Forensics Cooperation. 2.4 The Examination Phase. 2.4.1 Initial Data Source Examination and Preprocessing. 2.4.2 Forensic File Formats and Structures. 2.4.3 Data Recovery. 2.4.4 Data Reduction and Filtering. 2.4.5 Timestamps. 2.4.6 Compression, Encryption and Obfuscation. 2.4.7 Data and File Carving. 2.4.8 Automation. 2.5 The Analysis Phase. 2.5.1 Layers of Abstraction. 2.5.2 Evidence Types. 2.5.3 String and Keyword Searches. 2.5.4 Anti-Forensics. 2.5.4.1 Computer Media Wiping. 2.5.4.2 Analysis of Encrypted and Obfuscated Data. 2.5.5 Automated Analysis. 2.5.6 Timelining of Events. 2.5.7 Graphs and Visual Representations. 2.5.8 Link Analysis. 2.6 The Presentation Phase. 2.6.1 The Final Reports. 2.6.2 Presentation of Evidence and Work Conducted. 2.6.3 The Chain of Custody Circle Closes. 2.7 Summary. 2.8 Exercises. 3 Cybercrime Law (Inger Marie Sunde). 3.1 Introduction. 3.2 The International Legal Framework of Cybercrime Law. 3.2.1 The Individuals Involved in Criminal Activity and in Crime Preventing Initiatives. 3.2.2 The National Legal System versus the International Legal Framework. 3.2.3 Fundamental Rights Relating to Cybercrime Law – The ECHR. 3.2.4 Special Legal Framework: The Cybercrime Convention. 3.2.5 Interpretation of Cybercrime Law. 3.3 Digital Crime – Substantive Criminal Law. 3.3.1 General Conditions for Criminal Liability. 3.3.2 Real-Life Modus Operandi. 3.3.3 Offenses against the Confidentiality, Integrity, and Availability of Computer Data and Systems. 3.3.4 Computer-Related Offenses. 3.3.5 Content-Related Offenses. 3.3.6 Offenses Related to Infringements of Copyright and Related Rights. 3.3.7 Racist and Xenophobic Speech. 3.4 Investigation Methods for Collecting Digital Evidence. 3.4.1 The Digital Forensic Process in the Context of Criminal Procedure. 3.4.2 Computer Data That Are Publicly Available. 3.4.3 Scope and Safeguards of the Investigation Methods. 3.4.4 Search and Seizure (Article 19) 3.4.5 Production Order. 3.4.6 Expedited Preservation and Partial Disclosure of Traffic Data. 3.5 International Cooperation in Order to Collect Digital Evidence. 3.5.1 Narrowing the Focus. 3.5.2 A Special Note on Transborder Access to Digital Evidence. 3.5.3 Mutual Legal Assistance. 3.5.4 International Police Cooperation and Joint Investigation Teams. 3.6 Summary. 3.7 Exercises. 4 Digital Forensic Readiness (Ausra Dilijonaite). 4.1 Introduction. 4.2 Definition. 4.3 Law Enforcement versus Enterprise Digital Forensic Readiness. 4.4 Why? A Rationale for Digital Forensic Readiness. 4.4.1 Cost. 4.4.2 Usefulness of Digital Evidence. 4.5 Frameworks, Standards, and Methodologies. 4.5.1 Standards 4.5.2 Guidelines . 4.5.3 Research. 4.6 Becoming “Digital Forensic” Ready. 4.7 Enterprise Digital Forensic Readiness. 4.7.1 Legal Aspects. 4.7.2 Policy, Processes, and Procedures. 4.7.3 People 4.7.4 Technology: Digital Forensic Laboratory. 4.7.5 Technology: Tools and Infrastructure. 4.7.6 Outsourcing Digital Forensic Capabilities. 4.8 Considerations for Law Enforcement. 4.9 Summary. 4.10 Exercises. Contents. 5 Computer Forensics (Jeff Hamm). 5.1 Introduction. 5.2 Evidence Collection. 5.2.1 Data Acquisition. 5.2.2 Forensic Copy. 5.3 Examination. 5.3.1 Disk Structures. 5.3.2 File Systems 5.4 Analysis. 5.4.1 Analysis Tools. 5.4.2 Timeline Analysis. 5.4.3 File Hashing. 5.4.4 Filtering. 5.4.5 Data Carving. 5.4.6 Memory Analysis. 5.5 Summary. 5.6 Exercises. 6 Mobile and Embedded Forensics (Jens-Petter Sandvik). 6.1 Introduction. 6.1.1 Embedded Systems and Consumer Electronics. 6.1.2 Mobile Phones. 6.1.2.1 UICC (Formerly Known as a SIM Card). 6.1.3 Telecommunication Networks. 6.1.4 Mobile Devices and Embedded Systems as Evidence. 6.1.5 Malware and Security Considerations. Contents. 6.1.6 Ontologies for Mobile and Embedded Forensics. 6.2 Collection Phase. 6.2.1 Special Considerations for Embedded Systems and Mobile Devices. 6.2.2 Handling Electronics – ESD. 6.2.3 First Contact. 6.2.4 Physical Acquisition. 6.2.5 Logical Acquisition of Data. 6.2.6 Somewhere between Physical and Logical. 6.2.7 Commercial Forensic Products. 6.2.8 What about RAM? 6.2.9 Damaged Devices. 6.2.10 Wrapping It Up. 6.3 Examination Phase. 6.3.1 Top-Down: Flash Translation Layer (FTL). 6.3.2 Top-Down: Flash File Systems. 6.3.3 Bottom-Up: Carving. 6.3.4 Bottom-Up: Keyword Search. 6.3.5 Technical Deep-Dive: FTL from Nokia 7610 Supernova. 6.3.6 Technical Deep-Dive: Flash File System – YAFFS. 6.3.7 Technical Deep-Dive: Structure – SMS PDU. 6.3.8 Technical Deep-Dive: Structure – SQLite3 Database. 6.3.9 Technical Deep-Dive: Timestamps. 6.4 Reverse Engineering and Analysis of Applications. 6.4.1 Methods. 6.4.2 Targets. 6.5 Summary. 6.6 Exercises. 7 Internet Forensics (Petter Christian Bjelland). 7.1 Introduction. 7.2 Computer Networking. 7.3 Layers of Network Abstraction. 7.3.1 The Physical Layer. 7.3.2 The Data Link, Network, and Transport Layers. 7.3.3 The Session, Presentation, and Application Layers. 7.4 The Internet. 7.4.1 Internet Backbone. 7.4.2 Common Applications. 7.4.3 Caveats. 7.5 Tracing Information on the Internet. 7.5.1 DNS and Reverse DNS. 7.5.2 Whois and Reverse Whois. 7.5.3 Ping and Port Scan. 7.5.4 Traceroute. 7.5.5 IP Geolocation. 7.5.6 Tracing BitTorrent Peers. 7.5.7 Bitcoin Unconfirmed Transaction Tracing. 7.6 Collection Phase – Local Acquisition. 7.6.1 Browser History. 7.6.2 Browser Cache. 7.6.3 Browser Cookies. 7.6.4 Email. 7.6.5 Messaging and Chats. 7.6.6 Internet of Things. 7.7 Collection Phase – Network Acquisition. 7.7.1 tcpdump and pcap. 7.7.2 DHCP Logs. 7.8 Collection Phase – Remote Acquisition. 7.8.1 Server. 7.8.2 Cloud Services. 7.8.3 Open Sources. 7.9 Other Considerations. 7.9.1 Application Programming Interfaces (APIs). 7.9.1.1 Accessing User Accounts. 7.9.2 Integrity of Remote Artifacts. 7.10 The Examination and Analysis Phases. 7.10.1 Finding Interesting Nodes in Large Networks. 7.10.2 Divide and Conquer Large Networks. 7.10.3 Making Sense of Millions of Events. 7.11 Summary. 7.12 Exercises. 8 Challenges in Digital Forensics (Katrin Franke and André Årnes). 8.1 Computational Forensics. 8.1.1 The Objectives of Computational Forensics. 8.1.2 Disciplines of Computational Forensics. 8.2 Automation and Standardization. 8.3 Research Agenda. 8.4 Summary. 9 Educational Guide (Stefan Axelsson). 9.1 Teacher’s Guide. 9.2 Student’s Guide. 9.2.1 Journals. 9.2.2 Conferences and Organizations. 9.2.3 Professional and Training Organizations. 9.2.4 Tools. 9.2.5 Corpuses. 9.3 Summary. References.