Digital Forensics: The Branches
Joe Abraham
IT SECURITY PROFESSIONAL
@joeabrah www.joestechinsights.com
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Digital Evidence
Overview
The Five Branches
- Network Forensics
- Computer Forensics
- Mobile Forensics
- Database Forensics
- Forensic Data Analysis
Network Forensics
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Network
Digital Evidence
Digital evidence includes information on computers,
audio files, video recordings, and digital images.
-Nist.gov
Examples of Digital Evidence in the Network
Captured network Network device logs Email
traffic
Files Web traffic Any other traffic
“transmitted”
What Is Network Forensics Used For?
Analyze attack methods and Discover and understand
their durations attack vectors
Verify regulatory and Troubleshoot network
organizational policy performance and optimize
compliance services
Logging Within a Network
Network Visibility
Network Devices
Collector
Log
Information
SIEM
IDS/IPS
Identity Services
“I think you can have a ridiculously
enormous and complex data set, but if
you have the right tools and
methodology then it’s not a problem.”
Aaron Koblin
Computer Forensics
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Network Computer
Examples of Digital Evidence in Computers
Logs, registry, Documents, The operating Hard drive data
application pictures, videos, system or the and RAM data
data, and web and other files entire computer
history
Analyzing attacks
Verifying compliance
Troubleshooting
What Is Computer
Who, what, where,
when, why? Forensics Used For?
Develop remediation
How?
Painting the Picture
Use commercial and open-source
applications
Be thorough and put the facts together
Handle the evidence properly
Prove what happened
- Make it readable
- Make it understandable
- Eliminate doubt
Mobile Forensics
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Network Computer Mobile
Examples of Digital Evidence in Mobile Devices
Phonebook and call information
Messaging application data and SMS messages
Location data
Application data
Sample Use Cases for Mobile Forensics
Analyzing attacks via mobile Tracking movement of
devices suspects
Using call and message
Supplementing evidence from
records to prove wrongful
acts other branches
Prevention of data manipulation
Remote wipe
Data/evidence - Only needs power and connectivity
Preservation Helps ensure availability and integrity
Necessary in all branches of digital
forensics
Database Forensics
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Network Computer Mobile Database
Examples of Digital Evidence in Databases
Security/access logs Transaction logs
Files System logs
Pattern Analysis
One file or many?
Specific files?
Specific order?
Find the pattern to figure out why
Help paint the picture
Version Control
In computing, the management and maintenance of a
software system running different versions of various
programs.
–Dictionary.com
Forensic Data Analysis
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Data
Network Computer Mobile Database Analysis
Structured Data
Structured data is a standardized format for providing
information.
-Google Developers
Unstructured Data
Non-traditional data or data format; data that may not
fit into a structured database.
Pattern Analysis
Structured Data Unstructured Data
Queries, easier to accomplish, Scripts and software, more
can pinpoint key words and difficult to properly analyze,
phrases business intelligence and big
data
Make at least one
forensic image
Investigator works on
this image
Prevents Creating a Forensic Image
compromising of
evidence
Regulatory and legal
considerations
What is digital evidence?
Five branches of digital forensics
Summary
The importance of each branch
Key aspects surrounding digital forensics
- Logging
- Evidence preservation
- Painting the picture
- Data backups
- Forensic imaging
Forensic Science
Forensic Science
Other
Forensic Digital Forensics
Subdivisions
Data
Network Computer Mobile Database Analysis
How Much Data Is Created Every Day?
*April 5, 2017, Ben Walker, vouchercloud
2,500,000,000 GB
Average Number of Connected Devices
*Per U.S. Household, Pew Research Center, 2016
5
“We keep moving forward, opening
new doors, and doing new things,
because we’re curious and curiosity
keeps leading us down new paths.”
Walt Disney