The Experts below are selected from a list of 144 Experts worldwide ranked by ideXlab platform

Kim-kwang Raymond Choo - One of the best experts on this subject based on the ideXlab platform.

  • Chapter 7 – Forensic Collection of Cloud Storage Data: Does the Act of Collection Result in Changes to the Data or its Metadata?
    Cloud Storage Forensics, 2020
    Co-Authors: Darren Quick, Ben Martini, Kim-kwang Raymond Choo
    Abstract:

    The timely acquisition and preservation of data from cloud storage can be an issue for law enforcement agencies and other digital Forensic practitioners. In a jurisdiction which has legal provisions to collect data available to a computer or device, the process may involve accessing an account to collect the data. Using three popular public cloud storage providers (Dropbox, Google Drive, and Microsoft SkyDrive) as case studies, this chapter explores the process of collecting data from a cloud storage account using a browser and also downloading files using client software. We then compare these with the original files and undertake analysis of the resulting data. We determined that there were no changes to the contents of files during the process of upload, storage, and download to the three cloud storage services. The timestamps of the files were also examined in relation to the files downloaded via a browser and via client software. It was observed that some of the timestamp information remained the same throughout the process of uploading, storing, and downloading files. Timestamp information may be a crucial aspect of an investigation, prosecution, or civil action, and therefore it is important to record the information available and to understand the circumstances relating to a timestamp on a file.

  • electronic crime investigations in a virtualised environment a Forensic process and prototype for evidence Collection and analysis
    Australian Journal of Forensic Sciences, 2018
    Co-Authors: Ijaz Ahmad, Kim-kwang Raymond Choo, Haider Abbas, Asad Raza, Anam Sajid, Maruf Pasha, Farrukh Aslam Khan
    Abstract:

    AbstractThe constant evolution of virtualisation technologies and the availability of anti-Forensic techniques and tools complicate efforts by Forensic investigators to investigate a crime or a cyber security incident. Forensic Collection can be complicated and requires significant efforts to investigate incidents involving contemporary technologies (e.g. crime launched from a virtual machine and there had been attempts to erase evidence after the incident). This paper presents a Forensic process to collect and analyse traces of a virtual machine and its corresponding manager, recorded across multiple sources including the file system, Windows registry, history, and log files from a Forensic viewpoint. To demonstrate utility of the Forensic mechanism, the Virtual Machine Forensic Artefact Collector (VMFAC) prototype is developed and presented in this paper.

  • Evidence and Forensics in the Cloud: Challenges and Future Research Directions
    IEEE Cloud Computing, 2017
    Co-Authors: Kim-kwang Raymond Choo, Christian Esposito, Aniello Castiglione
    Abstract:

    Digital investigation in the cloud is challenging, but there's also opportunities for innovations in digital Forensic solutions (such as remote Forensic Collection of evidential data from cloud servers client devices and the underlying supporting infrastructure such as distributed file systems). This column describes the challenges and opportunities in cloud Forensics.

  • Digital Forensics in the cloud era: the decline of passwords and the need for legal reform
    Trends and issues in crime and criminal justice, 2016
    Co-Authors: Ben Martini, Quang Do, Kim-kwang Raymond Choo
    Abstract:

    Online and cloud computing services are increasingly prevalent to the point where, for many people, they are integral to communication in their daily lives. From a criminal justice perspective, this makes them key sources of evidence for prosecuting both traditional and online crime (Quick, Martini & Choo 2014). However, the successful prosecution of individuals who commit crimes involving electronic evidence relies upon two major factors. The first is appropriately resourced law enforcement agencies and Forensic practitioners who are able to collect, analyse and present the evidence (Quick and Choo 2014); the second is a legislative framework that facilitates the Collection of evidence in the modern era, particularly where much of the relevant electronic evidence may be stored beyond the jurisdiction of the investigating law enforcement agency, and the nation's borders generally (Choo 2010, 2014). Given the relatively recent advent and changing face of cloud computing technologies, and their widespread use, it is important to discuss these factors when looking at the challenges of collecting evidence from cloud computing systems in the current statutory environment, and the technical challenges of authentication in Forensic Collection-particularly as cloud service providers continue to enhance the security of their services.This paper first discusses the various provisions for search and seizure of evidence available to Australian law enforcement agencies. It then focuses on the increasing emphasis placed on the security of online services in recent times and the effect this has had on authentication. Where digital Forensics are used to collect evidence of a crime within a law enforcement agency's physical jurisdiction, it is common practice to take a physical bit-stream image of the storage in the devices to be Forensically analysed. The methods used to collect this image do not generally require authentication, as the process requires physical control of the device. In the online environment users-and, generally, Forensic practitioners-do not have physical access to the storage devices hosting their data.There is still a need, however, for a copy of the electronic evidence to be analysed and, ultimately, presented.It has become relatively common for Forensic practitioners, particularly those outside the jurisdiction of the cloud service provider, to obtain copies of electronic evidence using similar technical means as the user (eg a client-visible application programming interface or API). There is some doubt as to the Forensic soundness of this process, particularly in terms of the lack of preservation measurements such as cryptographic hashes (which act as a unique identifier) matching for the source and the Forensic image (an identical duplicate of the data source), and the increased potential for contamination, depending on the software tools used. As such, the most appropriate means of undertaking such a Collection remain undetermined.Regardless of the tools or methods used, most online services require authentication for every data access request. This relies on the practitioner gaining access to the user's credentials. These credentials have traditionally been a username and password, and law enforcement agencies have developed various methods, such as extracting them from application caches, to obtain them from suspects or their devices. As service providers improve the security of their services, however, there are fewer avenues available for collecting these credentials. This is at least in part due to the increase in tokenbased authentication systems in contemporary apps. A token-based system typically requires the user's credentials only once, at initial logon. These credentials are then used to obtain one or more tokens that are used for future authentication as required. This is discussed in greater detail in the Authentication systems section of this paper.To ensure law enforcement are able to maintain and, optimally, improve their current capabilities in evidence Collection from online and cloud services, they must clearly understand the operation of contemporary authentication systems. …

  • TrustCom/BigDataSE/ISPA (1) - Forensic Collection and Analysis of Thumbnails in Android
    2015
    Co-Authors: Ming Di Leom, Christian Javier D'orazio, Gaye Deegan, Kim-kwang Raymond Choo
    Abstract:

    JPEG thumbnail images are of interest in Forensic investigations as images from the thumbnail cache could be intact even when the original pictures have been deleted. In addition, a deleted thumbnail is less likely to be fragmented due to its small size. The focus of existing literature is generally on the desktop environment. Considering the increasing capability of smart mobile devices, particularly Android devices, to take pictures and videos on the go, it is important to understand how thumbnails can be collected from these devices. In this paper, we examine and describe the various thumbnail sources in Android devices and propose a methodology for thumbnail Collection and analysis from Android devices. We also demonstrate the utility of our proposed methodology using a case study (e.g. thumbnails could be recovered even when the file system is heavily fragmented). Our findings also indicate that collective information obtained from the recovered fragmented JPEG image (e.g. metadata) and the thumbnail could be akin to recovering the full image for Forensic purposes.

Bradford A Pindzola - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Collection of trace chemicals from diverse surfaces with strippable coatings
    Analyst, 2013
    Co-Authors: Michael J Jakubowski, Kevin J Beltis, Paul M Drennan, Bradford A Pindzola
    Abstract:

    Surface sampling for chemical analysis plays a vital role in environmental monitoring, industrial hygiene, homeland security and Forensics. The standard surface sampling tool, a simple cotton gauze pad, is failing to meet the needs of the community as analytical techniques become more sensitive and the variety of analytes increases. In previous work, we demonstrated the efficacy of non-destructive, conformal, spray-on strippable coatings for chemical Collection from simple glass surfaces. Here we expand that work by presenting chemical Collection at a low spiking level (0.1 g m−2) from a diverse array of common surfaces – painted metal, engineering plastics, painted wallboard and concrete – using strippable coatings. The Collection efficiency of the strippable coatings is compared to and far exceeds gauze pads. Collection from concrete, a particular challenge for wipes like gauze, averaged 73% over eight chemically diverse compounds for the strippable coatings whereas gauze averaged 10%.

  • strippable coatings for Forensic Collection of trace chemicals from surfaces
    Analytical Chemistry, 2012
    Co-Authors: Kevin J Beltis, Paul M Drennan, Michael J Jakubowski, Bradford A Pindzola
    Abstract:

    Surface sampling for chemical analysis plays a vital role in applications like environmental monitoring, industrial hygiene, homeland security, and Forensics. The standard surface sampling tool is a simple cotton gauze pad, but as techniques become more sensitive and the variety of analytes increases, gauze is failing to meet the needs of the community. Here, the Collection of eight small molecules from glass surfaces with three different commercial spray-on, strippable coatings was demonstrated and their Collection efficiency, as measured by gas chromatography/mass spectrometry, was compared to that of a standard cotton gauze. The three coating systems recovered 87–95% of the each compound, on average, from a nominal initial surface coverage of 0.1 g/m2 per analyte. These recoveries were 3-fold better than the cotton gauze which had an average Collection efficiency of 31%.

Nicolas Christin - One of the best experts on this subject based on the ideXlab platform.

  • Passe-partout: A general Collection methodology for android devices
    IEEE Transactions on Information Forensics and Security, 2013
    Co-Authors: Daniel Votipka, Nicolas Christin
    Abstract:

    The Android platform has been deployed across a wide range of devices, predominately mobile phones, bringing unprecedented common software features to a diverse set of devices independent of carrier and manufacturer. Modern digital Forensics processes differentiate Collection and analysis, with Collection ideally only occurring once and the subsequent analysis relying upon proper Collection. After exploring special device boot modes and Android's partitioning schema we detail the composition of an Android bootable image and discuss the creation of such an image designed for Forensic Collection. The major contribution of this paper is a general process for data Collection of Android devices and related results of experiments carried out on several specific devices. © 2011 Vidas, Zhang & Christin. Published by Elsevier Ltd. All rights reserved.

  • Toward a general Collection methodology for Android devices
    Digital Investigation, 2011
    Co-Authors: Timothy Vidas, Chengye Zhang, Nicolas Christin
    Abstract:

    The Android platform has been deployed across a wide range of devices, predominately mobile phones, bringing unprecedented common software features to a diverse set of devices independent of carrier and manufacturer. Modern digital Forensics processes differentiate Collection and analysis, with Collection ideally only occurring once and the subsequent analysis relying upon proper Collection. After exploring special device boot modes and Android's partitioning schema we detail the composition of an Android bootable image and discuss the creation of such an image designed for Forensic Collection. The major contribution of this paper is a general process for data Collection of Android devices and related results of experiments carried out on several specific devices.

Michael J Jakubowski - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Collection of trace chemicals from diverse surfaces with strippable coatings
    Analyst, 2013
    Co-Authors: Michael J Jakubowski, Kevin J Beltis, Paul M Drennan, Bradford A Pindzola
    Abstract:

    Surface sampling for chemical analysis plays a vital role in environmental monitoring, industrial hygiene, homeland security and Forensics. The standard surface sampling tool, a simple cotton gauze pad, is failing to meet the needs of the community as analytical techniques become more sensitive and the variety of analytes increases. In previous work, we demonstrated the efficacy of non-destructive, conformal, spray-on strippable coatings for chemical Collection from simple glass surfaces. Here we expand that work by presenting chemical Collection at a low spiking level (0.1 g m−2) from a diverse array of common surfaces – painted metal, engineering plastics, painted wallboard and concrete – using strippable coatings. The Collection efficiency of the strippable coatings is compared to and far exceeds gauze pads. Collection from concrete, a particular challenge for wipes like gauze, averaged 73% over eight chemically diverse compounds for the strippable coatings whereas gauze averaged 10%.

  • strippable coatings for Forensic Collection of trace chemicals from surfaces
    Analytical Chemistry, 2012
    Co-Authors: Kevin J Beltis, Paul M Drennan, Michael J Jakubowski, Bradford A Pindzola
    Abstract:

    Surface sampling for chemical analysis plays a vital role in applications like environmental monitoring, industrial hygiene, homeland security, and Forensics. The standard surface sampling tool is a simple cotton gauze pad, but as techniques become more sensitive and the variety of analytes increases, gauze is failing to meet the needs of the community. Here, the Collection of eight small molecules from glass surfaces with three different commercial spray-on, strippable coatings was demonstrated and their Collection efficiency, as measured by gas chromatography/mass spectrometry, was compared to that of a standard cotton gauze. The three coating systems recovered 87–95% of the each compound, on average, from a nominal initial surface coverage of 0.1 g/m2 per analyte. These recoveries were 3-fold better than the cotton gauze which had an average Collection efficiency of 31%.

Kevin J Beltis - One of the best experts on this subject based on the ideXlab platform.

  • Forensic Collection of trace chemicals from diverse surfaces with strippable coatings
    Analyst, 2013
    Co-Authors: Michael J Jakubowski, Kevin J Beltis, Paul M Drennan, Bradford A Pindzola
    Abstract:

    Surface sampling for chemical analysis plays a vital role in environmental monitoring, industrial hygiene, homeland security and Forensics. The standard surface sampling tool, a simple cotton gauze pad, is failing to meet the needs of the community as analytical techniques become more sensitive and the variety of analytes increases. In previous work, we demonstrated the efficacy of non-destructive, conformal, spray-on strippable coatings for chemical Collection from simple glass surfaces. Here we expand that work by presenting chemical Collection at a low spiking level (0.1 g m−2) from a diverse array of common surfaces – painted metal, engineering plastics, painted wallboard and concrete – using strippable coatings. The Collection efficiency of the strippable coatings is compared to and far exceeds gauze pads. Collection from concrete, a particular challenge for wipes like gauze, averaged 73% over eight chemically diverse compounds for the strippable coatings whereas gauze averaged 10%.

  • strippable coatings for Forensic Collection of trace chemicals from surfaces
    Analytical Chemistry, 2012
    Co-Authors: Kevin J Beltis, Paul M Drennan, Michael J Jakubowski, Bradford A Pindzola
    Abstract:

    Surface sampling for chemical analysis plays a vital role in applications like environmental monitoring, industrial hygiene, homeland security, and Forensics. The standard surface sampling tool is a simple cotton gauze pad, but as techniques become more sensitive and the variety of analytes increases, gauze is failing to meet the needs of the community. Here, the Collection of eight small molecules from glass surfaces with three different commercial spray-on, strippable coatings was demonstrated and their Collection efficiency, as measured by gas chromatography/mass spectrometry, was compared to that of a standard cotton gauze. The three coating systems recovered 87–95% of the each compound, on average, from a nominal initial surface coverage of 0.1 g/m2 per analyte. These recoveries were 3-fold better than the cotton gauze which had an average Collection efficiency of 31%.