The Experts below are selected from a list of 6 Experts worldwide ranked by ideXlab platform
Muhammad Nuh Al-azhar - One of the best experts on this subject based on the ideXlab platform.
-
Steganography Forensic: Metadata Analysis for Steganography Detection
2016Co-Authors: Muhammad Nuh Al-azharAbstract:Steganography is an art to hide secret message inside a carrier file which is commonly image file in the form of JPG or BMP. After created, the carrier file is then sent to other members of a certain group for secure communication. Only the group members identify the carrier file and understand the message embedded. Each steganography tools has their own method to perform the hiding process in which the tools are different one another. For Digital Forensic Analyst, steganography is a challenge to detect it. The carrier file still looks good and nothing is suspicious visually on it. This book explains how to perform Metadata Analysis to detect the existence of a steganography carrier file. Moreover, with Metadata Analysis, Digital Forensic Analyst could identify the type of steganography tools used to embed the secret message into the image file. At this moment, this steganography technique is frequently used by many intelligent agencies as their telecommunication channel which is secured from detection and interception of third parties. Even the third parties do not have an idea about to recognize it.
Sukhvinder Hara - One of the best experts on this subject based on the ideXlab platform.
-
DaP∀: Deconstruct and Preserve for All: A Procedure for the Preservation of Digital Evidence on Solid State Drives and Traditional Storage Media
Advanced Sciences and Technologies for Security Applications, 2018Co-Authors: Ian Mitchell, Josué Ferriera, Tharmila Anandaraja, Sukhvinder HaraAbstract:Human error is often a cause of contamination of potential Digital evidence and can jeopardise an entire case. One of the biggest problems is the data acquisition stage that requires the Digital Forensic Analyst to make bit-for-bit copies of the device seized. This procedure, despite using write-blockers, can go wrong. The proposed Deconstruct and Preserve for all (DaP∀) aims at mitigating the risk involved in exposing any data to these procedures and ensures that third parties get an exact match; the process works on SSDs, GPT formatted devices, and other traditional formats, e.g. HDD. The results show a GPT TRIM enabled SSD imaged multiple times produces verification of matched hashes. With these results, it is proposed that DaP∀ should be considered as a Standard Operating Procedure (SOP) when completing data acquisition.
Ian Mitchell - One of the best experts on this subject based on the ideXlab platform.
-
DaP∀: Deconstruct and Preserve for All: A Procedure for the Preservation of Digital Evidence on Solid State Drives and Traditional Storage Media
Advanced Sciences and Technologies for Security Applications, 2018Co-Authors: Ian Mitchell, Josué Ferriera, Tharmila Anandaraja, Sukhvinder HaraAbstract:Human error is often a cause of contamination of potential Digital evidence and can jeopardise an entire case. One of the biggest problems is the data acquisition stage that requires the Digital Forensic Analyst to make bit-for-bit copies of the device seized. This procedure, despite using write-blockers, can go wrong. The proposed Deconstruct and Preserve for all (DaP∀) aims at mitigating the risk involved in exposing any data to these procedures and ensures that third parties get an exact match; the process works on SSDs, GPT formatted devices, and other traditional formats, e.g. HDD. The results show a GPT TRIM enabled SSD imaged multiple times produces verification of matched hashes. With these results, it is proposed that DaP∀ should be considered as a Standard Operating Procedure (SOP) when completing data acquisition.
Josué Ferriera - One of the best experts on this subject based on the ideXlab platform.
-
DaP∀: Deconstruct and Preserve for All: A Procedure for the Preservation of Digital Evidence on Solid State Drives and Traditional Storage Media
Advanced Sciences and Technologies for Security Applications, 2018Co-Authors: Ian Mitchell, Josué Ferriera, Tharmila Anandaraja, Sukhvinder HaraAbstract:Human error is often a cause of contamination of potential Digital evidence and can jeopardise an entire case. One of the biggest problems is the data acquisition stage that requires the Digital Forensic Analyst to make bit-for-bit copies of the device seized. This procedure, despite using write-blockers, can go wrong. The proposed Deconstruct and Preserve for all (DaP∀) aims at mitigating the risk involved in exposing any data to these procedures and ensures that third parties get an exact match; the process works on SSDs, GPT formatted devices, and other traditional formats, e.g. HDD. The results show a GPT TRIM enabled SSD imaged multiple times produces verification of matched hashes. With these results, it is proposed that DaP∀ should be considered as a Standard Operating Procedure (SOP) when completing data acquisition.
Tharmila Anandaraja - One of the best experts on this subject based on the ideXlab platform.
-
DaP∀: Deconstruct and Preserve for All: A Procedure for the Preservation of Digital Evidence on Solid State Drives and Traditional Storage Media
Advanced Sciences and Technologies for Security Applications, 2018Co-Authors: Ian Mitchell, Josué Ferriera, Tharmila Anandaraja, Sukhvinder HaraAbstract:Human error is often a cause of contamination of potential Digital evidence and can jeopardise an entire case. One of the biggest problems is the data acquisition stage that requires the Digital Forensic Analyst to make bit-for-bit copies of the device seized. This procedure, despite using write-blockers, can go wrong. The proposed Deconstruct and Preserve for all (DaP∀) aims at mitigating the risk involved in exposing any data to these procedures and ensures that third parties get an exact match; the process works on SSDs, GPT formatted devices, and other traditional formats, e.g. HDD. The results show a GPT TRIM enabled SSD imaged multiple times produces verification of matched hashes. With these results, it is proposed that DaP∀ should be considered as a Standard Operating Procedure (SOP) when completing data acquisition.