Dissertation/ Thesis

Assessing the reliability of digital evidence from live investigations involving encryption

Λεπτομέρειες βιβλιογραφικής εγγραφής
Τίτλος: Assessing the reliability of digital evidence from live investigations involving encryption
Συγγραφείς: Hargreaves, Christopher James
Συνεισφορές: Chivers, H.
Στοιχεία εκδότη: Cranfield University, 2009.
Έτος έκδοσης: 2009
Θεματικοί όροι: 004, Forensic engineering - Data processing, Forensic Computing, Microcomputers, Data encryption - Computer science, Computer security, Criminal investigation, Electronic records - Law and legislation, Digital signatures
Περιγραφή: The traditional approach to a digital investigation when a computer system is encountered in a running state is to remove the power, image the machine using a write blocker and then analyse the acquired image. This has the advantage of preserving the contents of the computer’s hard disk at that point in time. However, the disadvantage of this approach is that the preservation of the disk is at the expense of volatile data such as that stored in memory, which does not remain once the power is disconnected. There are an increasing number of situations where this traditional approach of ‘pulling the plug’ is not ideal since volatile data is relevant to the investigation; one of these situations is when the machine under investigation is using encryption. If encrypted data is encountered on a live machine, a live investigation can be performed to preserve this evidence in a form that can be later analysed. However, there are a number of difficulties with using evidence obtained from live investigations that may cause the reliability of such evidence to be questioned. This research investigates whether digital evidence obtained from live investigations involving encryption can be considered to be reliable. To determine this, a means of assessing reliability is established, which involves evaluating digital evidence against a set of criteria; evidence should be authentic, accurate and complete. This research considers how traditional digital investigations satisfy these requirements and then determines the extent to which evidence from live investigations involving encryption can satisfy the same criteria. This research concludes that it is possible for live digital evidence to be considered to be reliable, but that reliability of digital evidence ultimately depends on the specific investigation and the importance of the decision being made. However, the research provides structured criteria that allow the reliability of digital evidence to be assessed, demonstrates the use of these criteria in the context of live digital investigations involving encryption, and shows the extent to which each can currently be met.
Τύπος εγγράφου: Thesis Or Dissertation
Γλώσσα: English
Σύνδεσμος πρόσβασης: https://ethos.blethoshyku.com/concern/thesis_or_dissertations/512751
Αριθμός Καταχώρησης: edsble.512751
Βάση Δεδομένων: British Library EThOS
FullText Text:
  Availability: 0
CustomLinks:
  – Url: https://ethos.blethoshyku.com/concern/thesis_or_dissertations/512751
    Name: EDS - British Library EThOS (ns324271)
    Category: fullText
    Text: View record in EThOS
Header DbId: edsble
DbLabel: British Library EThOS
An: edsble.512751
RelevancyScore: 920
AccessLevel: 3
PubType: Dissertation/ Thesis
PubTypeId: dissertation
PreciseRelevancyScore: 919.994262695313
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Assessing the reliability of digital evidence from live investigations involving encryption
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Hargreaves%2C+Christopher+James%22">Hargreaves, Christopher James</searchLink>
– Name: Author
  Label: Contributors
  Group: Au
  Data: Chivers, H.
– Name: Publisher
  Label: Publisher Information
  Group: PubInfo
  Data: Cranfield University, 2009.
– Name: DatePubCY
  Label: Publication Year
  Group: Date
  Data: 2009
– Name: Subject
  Label: Subject Terms
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22004%22">004</searchLink><br /><searchLink fieldCode="DE" term="%22Forensic+engineering+-+Data+processing%22">Forensic engineering - Data processing</searchLink><br /><searchLink fieldCode="DE" term="%22Forensic+Computing%22">Forensic Computing</searchLink><br /><searchLink fieldCode="DE" term="%22Microcomputers%22">Microcomputers</searchLink><br /><searchLink fieldCode="DE" term="%22Data+encryption+-+Computer+science%22">Data encryption - Computer science</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security%22">Computer security</searchLink><br /><searchLink fieldCode="DE" term="%22Criminal+investigation%22">Criminal investigation</searchLink><br /><searchLink fieldCode="DE" term="%22Electronic+records+-+Law+and+legislation%22">Electronic records - Law and legislation</searchLink><br /><searchLink fieldCode="DE" term="%22Digital+signatures%22">Digital signatures</searchLink>
– Name: Abstract
  Label: Description
  Group: Ab
  Data: The traditional approach to a digital investigation when a computer system is encountered in a running state is to remove the power, image the machine using a write blocker and then analyse the acquired image. This has the advantage of preserving the contents of the computer’s hard disk at that point in time. However, the disadvantage of this approach is that the preservation of the disk is at the expense of volatile data such as that stored in memory, which does not remain once the power is disconnected. There are an increasing number of situations where this traditional approach of ‘pulling the plug’ is not ideal since volatile data is relevant to the investigation; one of these situations is when the machine under investigation is using encryption. If encrypted data is encountered on a live machine, a live investigation can be performed to preserve this evidence in a form that can be later analysed. However, there are a number of difficulties with using evidence obtained from live investigations that may cause the reliability of such evidence to be questioned. This research investigates whether digital evidence obtained from live investigations involving encryption can be considered to be reliable. To determine this, a means of assessing reliability is established, which involves evaluating digital evidence against a set of criteria; evidence should be authentic, accurate and complete. This research considers how traditional digital investigations satisfy these requirements and then determines the extent to which evidence from live investigations involving encryption can satisfy the same criteria. This research concludes that it is possible for live digital evidence to be considered to be reliable, but that reliability of digital evidence ultimately depends on the specific investigation and the importance of the decision being made. However, the research provides structured criteria that allow the reliability of digital evidence to be assessed, demonstrates the use of these criteria in the context of live digital investigations involving encryption, and shows the extent to which each can currently be met.
– Name: TypeDocument
  Label: Document Type
  Group: TypDoc
  Data: Thesis Or Dissertation
– Name: Language
  Label: Language
  Group: Lang
  Data: English
– Name: URL
  Label: Access URL
  Group: URL
  Data: <link linkTarget="URL" linkTerm="https://ethos.blethoshyku.com/concern/thesis_or_dissertations/512751" linkWindow="_blank">https://ethos.blethoshyku.com/concern/thesis_or_dissertations/512751</link>
– Name: AN
  Label: Accession Number
  Group: ID
  Data: edsble.512751
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=edsble&AN=edsble.512751
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Text: English
    Subjects:
      – SubjectFull: 004
        Type: general
      – SubjectFull: Forensic engineering - Data processing
        Type: general
      – SubjectFull: Forensic Computing
        Type: general
      – SubjectFull: Microcomputers
        Type: general
      – SubjectFull: Data encryption - Computer science
        Type: general
      – SubjectFull: Computer security
        Type: general
      – SubjectFull: Criminal investigation
        Type: general
      – SubjectFull: Electronic records - Law and legislation
        Type: general
      – SubjectFull: Digital signatures
        Type: general
    Titles:
      – TitleFull: Assessing the reliability of digital evidence from live investigations involving encryption
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Hargreaves, Christopher James
      – PersonEntity:
          Name:
            NameFull: Chivers, H.
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Type: published
              Y: 2009
          Identifiers:
            – Type: issn-locals
              Value: edsble
ResultId 1