StudentShare
Contact Us
Sign In / Sign Up for FREE
Search
Go to advanced search...
Free

Forensic Computing Development - Essay Example

Cite this document
Summary
The essay "Forensic Computing Development" focuses on the critical analysis of the major issues in the development of forensic computing. OS Forensic is software used to easily uncover and extract relevant forensic data hidden in a computer within a short period…
Download full paper File format: .doc, available for editing
GRAB THE BEST PAPER91.1% of users find it useful
Forensic Computing Development
Read Text Preview

Extract of sample "Forensic Computing Development"

? Forensic Computing     Forensic Computing OS Forensic is software used to easily uncover and extract relevant forensic data hidden in a computer within a short time period. This tool will enable the user to search/find files faster than the default search functionality that comes pre-installed in Windows operating system. It is known to be one of the most powerful and fastest tools in searching or locating files. OS forensics does not miss or omit files during the search operation, a weakness associated by the default search tool that comes with Windows systems. Its fastness does not affect the results so the user can be well assured that OS forensics will locate every single file on the hard disk. A user can use criteria such as size, filename, creation and modified dates in locating files. The search results returned by OS forensics are made available in different views which include the timeline view, thumbnail view and file listing (Beijnum, 2009, p. 23). This helps the user determine the pattern of activity on the computer and know where significant file change occurred. Besides locating the files, this tool can go further to search within contents of each file for a full analysis. OS forensics has a powerful pre-indexed search capability that offers full text search to hundreds of file formats. Below is a list of what results OS forensics can offer: Highlighting Wildcard searches Relevance ranked search results Exclusion searches Date sorting or date range searching Exact phrase matching "Google-like" context results File listing view of search results The file formats that can be indexed by OS forensics include: RTF, WPD, SWF, DJVU, DOC, PDF, PPT, XLS, JPG, GIF, PNG, TIFF, XLSX, MHT, ZIP, MP3, DWF, DOCX, PPTX and more. In addition, it has a feature that helps analyze files so as to determine their file type if they lack file extension. The advanced hashing algorithm in OS forensics can help create a unique fingerprint that is used to identify a file. OS forensics can help the investigator to organize the evidence discovered into a cryptographically secure single file. The expert can add more results and evidence to the case file for future reference and analysis and be confident that the case file cannot be tampered with. Case management helps the user to organize and aggregate case items and results from OS forensics. An advantage of this software is that it can be installed and run from a USB flash drive thus helps you in keeping your investigation tools and reports with you when you are mobile (Cansolvo & Scholtz, 2004, p. 85). A user should avoid installing any software on the target machine so as to avoid the risk of unintentionally overwriting or deleting valuable forensic data left by the suspect. With OS forensics, the computer expert can export case files as customizable and accessible reports that show all the evidence gathered. This feature helps to deliver a summary of readable forensic findings to law enforcement agents or clients at any time during the investigation. OS forensics can be used to retrieve e-mail messages directly from their archives without the need to install email client programs such as thunderbird or Outlook (Dimitrova, Bellotti, Lozanova & Roumenin, 2011). It reads directly into the archive and displays everything from message headers, HTML, Rich Text Format and regular Text. Supported file formats are: Mbox for thunderbird, UNIX mail, Eudora and more. Pst for outlook. Msg for outlook. Dbx for outlook express. Eml for outlook express. All the attachments associated with the specified email can be extracted too. Email searching functionality embedded in OS forensics can be used to quickly search across all the content in the email’s archive effectively. OS forensics Email Viewer The forensic value of carrying out the processes described above may vary depending on various factors such as who needs the information and for what purpose is the information in question needed (Lin & Stead, 2009, p. 67). This valuable process helps in figuring out what took place, how it happened, the time it happened and the parties involved. Some fields in which computer forensics techniques and methodologies are applied include: Finding out the root cause of a system failure. Finding the people behind misuse of computer systems. Finding who committed a crime. Finding victims of a suspected criminal. Figuring out criminal events planned and stopping them from happening. Examples of more specific criminal activities that would require computer experts to carry out forensics would be such as murder cases, financial fraud, child pornography, theft of trade secrets, harassment, infringement of copyrights and many more (Dimitrova, Bellotti, Lozanova & Roumenin, 2011, p. 38). Incriminating files are likely to be located on the suspect’s or victim’s computer. OS forensics works by use of advanced hashing algorithms which create a digital fingerprint that is unique and used in identifying a file. By comparing hash values, OS forensics determines if a file has been tampered with or corrupted (Ksherti, 2010). This can also help identify if an unknown file belongs to a set of known files regardless of file extension or differing file name. Use the Create/Verify hash module to create a digital identifier that is unique to a disk volume or file by calculating its hash value. You can choose any of the cryptographic algorithms in creating a hash such as MD5, SHA-256 and SHA-1. A single hash value created for disk volumes helps in describing directory structures, unallocated space and content of files. Comparing the original and new hash value helps detect if a disk volume has been tampered with or corrupted. A process known as disk cloning is done using a free OS forensics tool known as OSF Clone to create exact disk duplicates which are used alongside the original disk (Fowler, 2003). The shortcomings associated with the open source version of OS forensics are: Inability to mine deeper in the data Lack of dedicated support from developers at any time. Adding the ability to dig deeper in the data functionality is important in dealing with very complicated cases involving computer experts as the suspects of crime. Computer experts who know what the software capabilities are may try to hide incriminating evidence deeper in the files thus making it difficult for the software to locate that piece of information (Napa, 2011). Commercial versions of forensic software come with an added advantage of user support from the official developers unlike the open source version which is not guaranteed (Cimino & Shortlife, 2006). A client may request for a particular feature to be included in the commercial version and the response time is expected to be much faster as compared to one requesting for the same feature added in the open source version. The commercial alternatives of digital forensic software are; Internet Evidence Finder, Spector CNE Investigator, Registry Recon, EnCase, EPRB, COFEE, Windows to go, Forensic Assistant, Nuix, PeerLab, X-Way Forensics, Intella, Forensics Apprentice, FTK, Paraben P2 Commander and SafeBack. Not all commercially available forensics software can match the open source equivalent versions (Adigun, Ojo & Olugbara, 2011). This depends on several factors that the companies may have taken into consideration before developing the commercial software. The factors considered include, The target market. Financial capabilities of the company in hiring highly skilled programmers and marketing. Features to be included. The research carried out. These factors may help determine whether the commercial alternatives will be useful, efficient, productive and reliable than the open source equivalent. Bibliography Adigun, O., Ojo, S. O., & Olugbara, O. O. (2011) A grid enabled framework for ubiquitous healthcare service provisioning. Advances in Grid Computing, 230-252. Retrieved: http://cdn.intechopen.com/pdfs/13951/InTech-A_grid_enabled_framework_for_ubiquitous_healthcare_service_provisioning.pdf Beijnum, V. et al. (2009) Mobile virtual communities for telemedicine: research challenges and opportunities. International Journal of Computer Science and Applications, 6 (2), 19-37. Cansolvo, S. & Scholtz, J. (2004) Towards a framework for evaluating ubiquitous computing applications. Pervasive Computing, 82-88. Cimino, J. & Shortlife, H. (2006) Biomedical Informatics: Computer Applications in Health Care and Biomedicine. New York: Springer. Dimitrova, M., Bellotti, L., Lozanova, S. & Roumenin, C. (2011) Cloud computing framework for new medical interface technologies. Institute of Systems Engineering and Robotics, Bulgarian Academy of Sciences. Fowler, M. (2003) Patterns of Enterprise Application Architecture. New York: Addison-Wesley Professional. Ksherti, N. (2010) Cloud computing in developing economies: drivers, effects and policy measures. Retrieved: http://www.ptc.org/ptc10/program/images/papers/papers/Paper_Nir%20Kshetri_B8.pdf Lin, H. & Stead, W. (2009) Computational Technology for Effective Health Care: Immediate Steps and Strategic Directions. New York: National Academies Press. Napa, A. (2011) Wireless Mobile Communication and Healthcare: Second International ICST Conference; Revised Selected Papers. New York: Springer. Read More
Cite this document
  • APA
  • MLA
  • CHICAGO
(“Forensic computing Essay Example | Topics and Well Written Essays - 1250 words”, n.d.)
Forensic computing Essay Example | Topics and Well Written Essays - 1250 words. Retrieved from https://studentshare.org/information-technology/1470766-forensic-computing
(Forensic Computing Essay Example | Topics and Well Written Essays - 1250 Words)
Forensic Computing Essay Example | Topics and Well Written Essays - 1250 Words. https://studentshare.org/information-technology/1470766-forensic-computing.
“Forensic Computing Essay Example | Topics and Well Written Essays - 1250 Words”, n.d. https://studentshare.org/information-technology/1470766-forensic-computing.
  • Cited: 0 times

CHECK THESE SAMPLES OF Forensic Computing Development

Current Developments in Forensic Computing

This report "Current Developments in forensic computing" discusses information technology that has resulted in new possibilities for behavior.... Definition of computer forensics From the definition of various authors, forensic computing can be summarized as the legally acceptable process primarily involving identification, preservation, analysis, and presentation of digital evidence as stipulated by the court (Yasinsac, 2003; Garber, 2001; Patzakis, 2003).... The first step in forensic computing is the identification of digital evidence....
7 Pages (1750 words) Report

The Challenges of the Forensic Recovery and Examination of Data from Mobile Devices

This remarkable development of mobile technology is the origin of current security challenges.... The capability of mobile devices has increased as a result of advances in computing ability contributed by the advancement of semiconductor technology used in these devices.... This research proposal "The Challenges of the forensic Recovery and Examination of Data from Mobile Devices" discusses mobile device forensics as a dynamic field.... This paper summarizes the challenges faced in forensic recovery and examination of data from mobile devices....
14 Pages (3500 words) Research Proposal

Anti-Forensic Technologies

ecently, due to the development of anti-computer forensics into a significant field of study, more researchers have undertaken intensive studies and research on the issue.... This paper ''Anti-forensic Technologies'' tells that There has been a wide usage of anti-computer forensics all over the world.... This paper takes an overview of, and an analysis of the most widely used anti-forensic techniques.... n recent s, there has been a sharp increase in the number of anti-forensic techniques used by criminals in frustrating investigative processes....
12 Pages (3000 words) Essay

Role of Computer Forensics and Investigation Report in Criminology

In forensic investigations, slack space is usually examined because it contains residual information concerning any stored file.... Live data acquisition is a process in which computer forensic experts make a copy of the digital evidence, from a digital device, by running a program (University at Buffalo, n.... Ideally, forensic experts make a copy of the original data in order to use the copy for further analysis.... By understanding this data storage system, computer forensic experts can collect relevant evidence from computers with high precision....
5 Pages (1250 words) Research Paper

Computer Forensics Professional Certifications

In regard to a computer forensics, the demand is high especially in the police stations due to the need of understanding computers and related issues in the law enforcement line of work computer forensics involves the analysis and investigation of computing devices for the purpose of using that knowledge to provide witness in a court of law.... The author of the "Computer Forensics Professional Certifications" paper examines the pre-certification requirements of a computer forensic professional, the factors to gain certification, and the value of computer forensic certification in the cyber forensic career....
5 Pages (1250 words) Research Paper

Independent Expert Witness Use of Computer Forensic

At the basic level, computer forensics is the analysis of information contained within and created with computer systems, and techniques and methodologies are used for conducting computing investigations typically in the interest of figuring out what happened when it happened, how it happened, and who was involved.... The paper "Independent Expert Witness Use of Computer forensic" highlights that generally, now many educational institutions are offering computer forensics degrees, and related education has become a minimum requirement to stay competitive in the industry....
10 Pages (2500 words) Coursework

Mobile Digital Forensics

or this reason, a different form of intervention to curb this rising incident has resulted in the development of mobile forensics, a field that involves recover of different form of digital evidence over fraud and other related unethical incidents.... he habit of using phones in perpetuating crime and other related incidents was broadly recognized for many years; however, the particular study about how the process is done and how it can be followed up by security authorities is a new development (Marshall, 2008)....
6 Pages (1500 words) Research Paper

OSforensics Tool and Recovered Forensic Artifacts

These are not a new innovation; rather they have been used for many centuries before the development of modern forensic techniques.... The paper 'OSforensics Tool and Recovered forensic Artifacts' is an impressive example of a law presentation.... The paper 'OSforensics Tool and Recovered forensic Artifacts' is an impressive example of a law presentation.... The paper 'OSforensics Tool and Recovered forensic Artifacts' is an impressive example of a law presentation....
11 Pages (2750 words) Speech or Presentation
sponsored ads
We use cookies to create the best experience for you. Keep on browsing if you are OK with that, or find out how to manage cookies.
Contact Us