Forensics
process of using scientific knowledge for collecting, analyzing, and presenting
evidence to the courts
Computer Forensics
the use of analytical and investigative techniques to identify, collect, examine and
preserve evidence/information which is magnetically stored or encoded.
Digital Forensics
proliferation of smartphones, smartwatches, and other devices in computer
forensics
Objective of computer forensics
To recover, analyze, and present computer-based material in such a way that it
can be used as evidence in a court of law.
Digital Evidence
information that has been processed and assembled so that it is relevant to an
investigation and supports a specific finding or determination.
Chain of Custody
information that has been processed and assembled so that it is relevant to an
investigation and supports a specific finding or determination.
Four types of Evidence
real, documentary, testimonial, demonstrative
,Real Evidence
a physical object that someone can touch, hold, or directly observe.
Documentary Evidence
data stored as written matter, on paper, or in electronic files
Demonstrative Evidence
information that forensic specialists use to support or interpret real or
documentary evidence.
Tesimonial
information that forensic specialists use to support or interpret real or
documentary evidence.
Digital System Forensics Analysis
disk forensics, email forensics, network forensics, internet forensics, softwaree
forensics, live system forensics, cell phone forensics
Federal Privacy Act of 1974
establishes a code of information-handling practices that governs the collection,
maintenance, use, and dissemination of information about individuals
Privacy Protection Act of 1980
protects journalists from being required to turn over to law enforcement any work
product and documentary materials, including sources, before it is disseminated
to the public.
Communications Assistance to Law Enforcement Act of 1994
,federal wiretap law for traditional wired telephony. It was expanded in 2004 to
include wireless, voice over packets, and other forms of electronic
communications, including signaling traffic and metadata.
Unlawful Access to Stored Communications: 18 U.S.C. § 2701
covers access to a facility through which electronic communication is provided or
exceeding the access that was authorized.
Electronic Communications Privacy Act of 1986
governs the privacy and disclosure, access, and interception of content and
traffic data related to electronic communications.
Computer Security Act of 1987
was passed to improve the security and privacy of sensitive information in federal
computer systems.
Foreign Intelligence Surveillance Act of 1978
a law that allows for collection of "foreign intelligence information" between
foreign powers and agents of foreign powers using physical and electronic
surveillance.
Child Protection and Sexual Predator Punishment Act of 1998
requires service providers that become aware of the storage or transmission of
child pornography to report it to law enforcement.
Children's Online Privacy Protection Act of 1998
protects children 13 years of age and under from the collection and use of their
personal information by websites.
Communications Decency Act of 1996
, designed to protect persons 18 years of age and under from downloading or
viewing material considered indecent.
Slack Space
the space between the end of a file and the end of the cluster, assuming the file
does not occupy the entire cluster.
Telecommunications Act of 1996
includes many provisions relative to the privacy and disclosure of information in
motion through and across telephony and computer networks.
Daubert Standard
Standard used by a trial judge to make a preliminary assessment of whether an
expert's scientific testimony is based on reasoning or methodology that is
scientifically valid and can properly be applied to the facts at issue.
Sarbanes-Oxley Act of 2002
contains many provisions about recordkeeping and destruction of electronic
records