1,720,969 research outputs found

    Interpretation of File System Metadata in a Criminal Investigation Context

    Get PDF
    The reliable reconstruction of digital events is imperative for solving criminal cases. Computers, servers, mobile and IoT devices, vehicles, and EV charging infrastructure all use either local or remote storage (cloud). The storage needs to use a file system in order to store and retrieve files. Currently, digital forensic tools implement support for the most popular file systems, either fully or partially. In order to determine what has taken place, investigators today are dependent on tools that automate much of the investigation. Unfortunately, these tools use techniques that are not necessarily published, tested or peer-reviewed, which increases the uncertainty of their results. Furthermore, investigators normally use well known artifacts from the Operating System (OS) when trying to determine what occurred, however, file system interpretation is often automated by the tools and trusted as reliable and complete by the investigators. In many cases the OS is not available, for instance, when an external storage device is seized. This means the investigator only has the file system and the file content available for investigation. We found metadata structures that may connect an external device to the computers used to create files on the device, which order these files have been created, and when the computers were booted. These findings will help investigators to identify which computers are relevant for the investigation, create timelines, and detect timestamp manipulation, but also identify which files users have created, opened, or saved. It is not unusual that external devices are damaged or reformatted with new file systems. In this context it is important to be able to recover files from the damaged file system. We were able to invent a novel and generic method to carve and identify metadata for files using equality or approximate equality to identify timestamps that are co-located, a pattern typical for file metadata structures in most file systems. Our prototype tool outperforms the other tools we tested in recovery from damaged file systems. Investigators often use timestamps to create timelines or to limit their investigation to a particular time frame. We found that both tools and different file system drivers are implemented differently, not necessarily following the file system specifications. Even normal usage of an external USB disk on multiple operating systems may change timestamps to invalid settings, and it is imperative that investigators are able to identify such usage. This thesis will focus on interpreting the file system metadata to identify and understand the accurate meaning of structures that the digital forensic tools currently do not support or only partly support, identifying new knowledge that will increase the quality of digital investigations

    Timeframe-based contiguous file carving in video surveillance systems

    Get PDF
    I straffesaker er ofte overvåkingsfilm en viktig del av bevisbildet. Det er viktig å få innhentet opptakene så tidlig som mulig på grunn av krav om sletting og lagringsplass på overvåkingssystemene. På grunn av personvernregler blir ofte opptak slettet etter en uke, og da kan bevis forsvinne om det ikke er innhentet innen det. I løpet av en etterforsking kan det også dukke opp nye bevis som gjør nye områder eller tidsrom aktuelt for innhenting av overvåkingsmateriale, og da kan gjenoppretting av slettede opptak være avgjørende. Gjenoppretting av slettede data fra uallokerte områder på en harddisk er kjent som 'carving'. Det finnes flere metoder for å gjenopprette data, og en av de mer grunnleggende er å søke etter kjente start- og slutt-signaturer i en fil. For denne er det viktig at filtypen har en definert start og slutt. En annen utprøvd metode er bilde-basert gjenoppretting. Denne leter etter de miste bestanddelene i en videofil, enkeltbilder, og gjenoppretter videoen ved å sette samme alle enkeltbildene. I tillegg kan denne metoden håndtere filer som er delvis overskrevet, samt filer som er lagret på spredte plasser på harddisken. Men, disse generiske metodene kan ha problemer med å gjenopprette overvåkingsmateriale på grunn av at dette ofte lagres i proprietære filformater. For all videodata som lagres er det svært viktig å lagre tidspunkt sammen med videoen, slik at det er mulig å tidfeste en hendelse. Og mens overvåkingssystemer kjører lagrer de en konstant strøm med ny videodata, og sletter gammel data fortløpende, enten på grunn av personvernhensyn eller for å unngå at lagringsplassen går fullt. Vi presenterer metoder som gjenoppretter overvåkingsmateriale fra flere overvåkingssystemer, inkludert Milestone, Mirasys, Avigilon og Detec, der gjenopprettingen fokuserer på et gitt tidsrom. Ved å finne gjentakende mønster omkring tidsstempler i videodataene, lages et søkemønster med mulighet for å definere et aktuelt tidsrom for å søke etter videodata. I de data som ligger omkring tidsstemplene har vi funnet nok informasjon om størrelser og avstander til å gjenopprette de tilhørende videodata. I våre resultater virker metodene til å være lovende med svært høye verdier for presisjon og gjenkallelse. I tillegg har vi utviklet en metode og et verktøy for å analysere og gjenkjenne mønster i videodata, disse mønstrene kan bestå av tidsstempel, signaturer, størrelse- og avstandsinformasjon. I vår analyse av videodata fra de forskjellige overvåkingssystemene ble denne metoden brukt til å lage gjenopprettingsmetodene for slettet overvåkingsfilm. Vi håper at denne analysemetoden og verktøyet kan danne grunnlaget for å gjenkjenne mønster i andre lignende systemer.Surveillance video is often a crucial piece of evidence in criminal investigations. It is time critical to collect the video data before it is made unavailable due to privacy policies or hard drive storage capacities. The video data is often deleted within a week or so, and if it's not collected by then, the evidence might be lost. Additional evidence may surface during the investigation in certain criminal cases, and retrieving deleted surveillance videos is often crucial. The recovery of deleted data, data from unallocated areas of the hard drives, is commonly known as carving. There are several methods of carving data; searching for a header-footer signature is one of the most basic methods and is suitable for files with a recognizable signature to determine the start and end of the file. Another reliable method is frame-based carving, which involves searching for the smallest parts of a video (frames) and reconstructing the video. This method can effectively handle fragmented and partly overwritten files. However, when it comes to retrieving surveillance video, it may not always be successful due to the unique file formats used by surveillance systems. The surveillance systems store timestamps along with the video data to help determine when an incident occurred. And while the systems are running, they are constantly storing new video data, and either by privacy policies or to prevent reaching storage capacity, the system deletes older video data. We propose carving methods for several surveillance systems, including \linebreak Milestone, Mirasys, Avigilon, and Detec, that recover video data within a timeframe of interest. By identifying patterns surrounding timestamps in the video data, our methods search for those patterns with a regular expression. The regular expression matches a range of timestamps to include a time frame of interest. In the data surrounding the timestamps, we find information to carve out the corresponding frame data. Our results indicate that the methods have very high precision and recall values for retrieving old video data not yet overwritten. We also present a method and a tool to discover patterns of timestamps, signatures, offsets, and size information within the video data. We use this method in our video data analysis and present these patterns as part of developing the carving algorithms. We hope this method and tool may lay the foundation for recognizing patterns in other systems

    Deepthought - A Case Study in Digital Forensic Tool Validation

    Get PDF
    Bevis fra digitale enheter spiller en stadig større rolle i etterforskning av kriminalsaker. Spesialverktøyene som brukes til å sikre og hente ut bevis må være nøyaktige og påvirke de beslaglagte enhetene så lite som mulig. I denne masteroppgaven identifiserer vi hvilke krav som stilles til digitale etterforskingsverktøy, samt drøfter eksisterende metodikk for å validere at slike verktøy er pålitelige. Som en del av oppgaven har vi kombinert ISO standarder for programvaretesting med etablerte metoder for validering av digitale etterforskingsverktøy. Denne metodikken gir en strukturert måte å bryte ned verktøyets funksjoner til test kriterier, i et fleksibelt rammeverk som egner seg for testing av alle digitale etterforskingsverktøy. Med økende mengder digitale beslag i straffesaker er det et økende behov for automatiserte digitale etterforskingsverktøy for å behandle og analysere beslag. Det finnes mange kommersielle verktøy tilgjengelig på markedet, men slik programvare kan være svært kostbart noe som gjør at etterforskingsavsnittene må prioritere hvilke verktøy de skal kjøpe inn. Freetool er et prosjekt som utvikler digitale etterforskingsverktøy gratis for politienheter. Ett av verktøyene utviklet som en del av Freetool-prosjektet er Deepthought. Deepthought er et triage verktøy som brukes til å utføre initiell analyse av beslaglagte digitale enheter. Som en del av oppgaven har vi gjennomført eksperimenter på Deepthought-programvaren ved bruk av metodikken vi beskriver. Vår avhandling konkluderer med at Deepthought har stort potensial som triage verktøy, men at dagens versjon ikke oppfyller kravene for digitale etterforskingsverktøy. Som en del av avhandlingen har vi utviklet datasett for funksjonstesting av digitale etterforskingsverktøy. Vi er i ferd med å gjøre disse datasettene offentlig tilgjengelige slik at andre kan gjennomføre lignende funksjonstester. Gjennom vårt arbeid har vi identifisert testkriterier for funksjoner benyttet av digitale etterforskingsverktøy rettet mot barneovergrepssaker. Disse testkriteriene kan sammenstilles og kombineres med testkriterier identifisert gjennom andre eksperimenter på digitale etterforskingsverktøy. En slik samling testkriterier kan da benyttes når lignende programvare skal testes i fremtiden.Digital evidence is playing an increasingly critical role in investigations. Trusting the forensic tools to retrieve and analyze files accurately, without affecting the integrity of the evidence, is imperative for the investigators to be able to use the evidence in court. In this thesis, we identify requirements for digital forensic tools, and review existing scientific methods for validating digital forensic tools. As part of this thesis we have combined ISO standards for software testing with established standards in the field of digital forensic tool testing. The result of our combined method provides a structured method for establishing test criteria in a versatile framework for testing digital forensic tools. With increasing amounts of digital evidence in criminal cases, there is a growing need for automated digital forensic tools to process seized devices. There are many commercial tools available on the market, but with the cost of licensing commercial software, law enforcement is forced to prioritize what tools to buy. The Freetool project seeks to develop free digital forensic tools for law enforcement, and one of these tools is Deepthought. Deepthought is a triaging tool used for performing preliminary analysis of the seized devices. By applying our test methodology, we have conducted experiments on the Deepthought software to verify if the tool meets the requirements for digital forensic tools. Our thesis concludes that Deepthought has great potential as a triaging tool, but that the current version does not meet the requirements. As part of the thesis we have developed datasets for specific function testing of digital forensic tools. We are in the process of making these datasets available to the community for similar functionality tests. Through our work, we have identified test assertions for digital forensic tools aimed at child exploitation cases. In future research, this work can be further extended to include more functions, and ultimately ending in a comprehensive list of test assertions to be used when testing any digital forensic tool functionality

    Deepthought - A Case Study in Digital Forensic Tool Validation

    No full text
    Bevis fra digitale enheter spiller en stadig større rolle i etterforskning av kriminalsaker. Spesialverktøyene som brukes til å sikre og hente ut bevis må være nøyaktige og påvirke de beslaglagte enhetene så lite som mulig. I denne masteroppgaven identifiserer vi hvilke krav som stilles til digitale etterforskingsverktøy, samt drøfter eksisterende metodikk for å validere at slike verktøy er pålitelige. Som en del av oppgaven har vi kombinert ISO standarder for programvaretesting med etablerte metoder for validering av digitale etterforskingsverktøy. Denne metodikken gir en strukturert måte å bryte ned verktøyets funksjoner til test kriterier, i et fleksibelt rammeverk som egner seg for testing av alle digitale etterforskingsverktøy. Med økende mengder digitale beslag i straffesaker er det et økende behov for automatiserte digitale etterforskingsverktøy for å behandle og analysere beslag. Det finnes mange kommersielle verktøy tilgjengelig på markedet, men slik programvare kan være svært kostbart noe som gjør at etterforskingsavsnittene må prioritere hvilke verktøy de skal kjøpe inn. Freetool er et prosjekt som utvikler digitale etterforskingsverktøy gratis for politienheter. Ett av verktøyene utviklet som en del av Freetool-prosjektet er Deepthought. Deepthought er et triage verktøy som brukes til å utføre initiell analyse av beslaglagte digitale enheter. Som en del av oppgaven har vi gjennomført eksperimenter på Deepthought-programvaren ved bruk av metodikken vi beskriver. Vår avhandling konkluderer med at Deepthought har stort potensial som triage verktøy, men at dagens versjon ikke oppfyller kravene for digitale etterforskingsverktøy. Som en del av avhandlingen har vi utviklet datasett for funksjonstesting av digitale etterforskingsverktøy. Vi er i ferd med å gjøre disse datasettene offentlig tilgjengelige slik at andre kan gjennomføre lignende funksjonstester. Gjennom vårt arbeid har vi identifisert testkriterier for funksjoner benyttet av digitale etterforskingsverktøy rettet mot barneovergrepssaker. Disse testkriteriene kan sammenstilles og kombineres med testkriterier identifisert gjennom andre eksperimenter på digitale etterforskingsverktøy. En slik samling testkriterier kan da benyttes når lignende programvare skal testes i fremtiden

    Strategies for Improving Retention in Online Learning.

    No full text
    This research seeks to determine if methods exist to identify students in online education who are a retention risk and to develop solutions to help prevent said students from exiting the course prematurely. In order to do this effectively, this study addresses three specific questions: • What data is provided by VLEs that might help educators to measure student engagement? • To what extent are educators able to identify those students who are in danger of exiting a course prematurely in the online learning environment? • What preventative measures are being used by educators to attempt to improve student retention in the online learning environment? A qualitative approach is used to answer the above questions. Initially the documentation for the most popular VLEs is analysed to identify the information present that would allow educators measure student engagement. Following this online educators are interviewed in order to harness their thoughts and experiences in the identification of students who are a retention risk. The participants are also asked about their preferred strategies for preventing the early drop out of students in online learning. The result of this primary research is to develop a set of recommendations, both for higher education institutions, and also for educators which aid in the identification of at-risk students. Additionally recommendations are provided for strategies that can be used, both proactively and reactively, in online learning to improve student retention

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis

    Dispelling the Myths Behind First-author Citation Counts

    Get PDF
    We conducted a full-scale evaluative citation analysis study of scholars in the XML research field to explore just how different from each other author rankings resulting from different citation counting methods actually are, and to demonstrate the capability of emerging data and tools on the Web in supporting more realistic citation counting methods. Our results contest some common arguments for the continued use of first-author citation counts in the evaluation of scholars, such as high correlations between author rankings by first-author citation counts and other citation counting methods, and high costs of using more realistic citation counting methods that are not well-supported by the ISI databases. It is argued that increasingly available digital full text research papers make it possible for citation analysis studies to go beyond what the ISI databases have directly supported and to employ more sophisticated methods
    corecore