selective and intelligent imaging using digital evidence bags

25
Selective and Intelligent Imaging Using Digital Evidence Bags Presented by Ryan O’Donnell

Upload: torn

Post on 17-Mar-2016

31 views

Category:

Documents


3 download

DESCRIPTION

Selective and Intelligent Imaging Using Digital Evidence Bags. Presented by Ryan O’Donnell. Introduction. Selective Imaging Intelligent Imaging Digital Evidence Bags. Current Method. Current methods use the bitstream image Suitable for smaller sized sources Works for the majority of cases - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Selective and Intelligent Imaging Using Digital Evidence Bags

Selective and Intelligent Imaging Using Digital Evidence

BagsPresented by Ryan O’Donnell

Page 2: Selective and Intelligent Imaging Using Digital Evidence Bags

•Selective Imaging•Intelligent Imaging•Digital Evidence Bags

Introduction

Page 3: Selective and Intelligent Imaging Using Digital Evidence Bags

Current methods use the bitstream image•Suitable for smaller sized sources•Works for the majority of cases•Is there anything better?

Current Method

Page 4: Selective and Intelligent Imaging Using Digital Evidence Bags

With this method the entire drive is NOT captured.

In some best practice guidelines (ACPO) selective imaging may be used as an alternative to the traditional bitstream imaging capture method

Selective Imaging (SI)

Page 5: Selective and Intelligent Imaging Using Digital Evidence Bags

•large source (primary reason)•forensic triage•intelligence gathering•legal requirements

Why use Selective Imaging?

Page 6: Selective and Intelligent Imaging Using Digital Evidence Bags

•Manualo choose exact files that are captured•Semi-Automatico choose categories (file extensions, file

hash, file signature, etc)•Automatico imager uses configuration for acquisition

Selective Imaging Techniques

Page 7: Selective and Intelligent Imaging Using Digital Evidence Bags

To maintain integrity of collected data, we must record all files and their provenance.

Provenance can be recorded by •physical sector location•logical cluster location and offset•folder location

Integrity of Selective Imaging -1

Page 8: Selective and Intelligent Imaging Using Digital Evidence Bags

Which is best? Keep in mind, the provenance must be•unique•unambiguous•concise •repeatable

Integrity of Selective Imaging -2

Page 9: Selective and Intelligent Imaging Using Digital Evidence Bags

•Primary key- physical sectors•Secondary key- logical clusters and offset•Tertiary key- folder location

All keys should be documented, but use the appropriate key for your audience.

Integrity of Selective Imaging -3

Page 10: Selective and Intelligent Imaging Using Digital Evidence Bags

•Automatically images and processes drive•No need for technologically proficient investigator•Acquires all relevant information that would normally be relevant to the case

Intelligent Imaging

Page 11: Selective and Intelligent Imaging Using Digital Evidence Bags

• How do you go about capturing the knowledge of the technical experts that are familiar with digital technical complexities and legal domain experts and combine them?

• How do you know that you have captured everything relevant to the case under investigation or have not missed evidence of other offences?

Intelligent Imaging Concerns

Page 12: Selective and Intelligent Imaging Using Digital Evidence Bags

DEB is a universal container for digital information from any source. They allow provenance to be recorded and provide continuity maintenance throughout the life of the exhibit.

Digital Evidence Bags (DEB)

Page 13: Selective and Intelligent Imaging Using Digital Evidence Bags

DEB Overview Diagram

Page 14: Selective and Intelligent Imaging Using Digital Evidence Bags

•tag file•index files•bag files

The index and bag files together are known as an Evidence Unit (EU).

DEB Components

Page 15: Selective and Intelligent Imaging Using Digital Evidence Bags

DEB Framework

Page 16: Selective and Intelligent Imaging Using Digital Evidence Bags

A plain text file made up of•DEB Header•Evidence Units•DEB Footero records the number of EU in the DEB; sealed

with hash•Tag continuity blocks (TCB)o application function, signature and timestamp

DEB Tag file

Page 17: Selective and Intelligent Imaging Using Digital Evidence Bags

•investigating officer•creation timestamp•evidence description•Index format using metatags

Header File

Page 18: Selective and Intelligent Imaging Using Digital Evidence Bags

•Labelso file name, origin, attributes, command•Timestampso modified, accessed, created•Numerico sector, cluster, logical size, physical size• Integrityo hash values

Header Index Metatags

Page 19: Selective and Intelligent Imaging Using Digital Evidence Bags

•records all EUso includes integrity hash of both index and

bag files•EU 0 is reserved for case noteso imager information

configuration, revision, hash, selection criteriao any case information

Tag File - Evidence Units

Page 20: Selective and Intelligent Imaging Using Digital Evidence Bags

Imager Configuration File

Page 21: Selective and Intelligent Imaging Using Digital Evidence Bags

DEB Tag File Example

Page 22: Selective and Intelligent Imaging Using Digital Evidence Bags

DEB Diagram

Page 23: Selective and Intelligent Imaging Using Digital Evidence Bags

Evidence Unit Detail

Page 24: Selective and Intelligent Imaging Using Digital Evidence Bags

There must be sufficient information about the provenance so when restored it is identical to what would have been acquired with a bitstream image

The Ultimate Test

Page 25: Selective and Intelligent Imaging Using Digital Evidence Bags

The container is key to selectively capturing data.

Utilizing these methods provides structure in investigations with vast amounts of information.

Conclusion