Sunday, October 2, 2016

Understanding The Basics Of Computer Forensics

By Shirley Hayes


The adoption of various kinds of computers in personal, corporate, and government processes is leading to a new form of crime referred to as cybercrime. Cybercrime is any kind of crime facilitated by computers. Cybercrime is growing at a very fast rate, something that is making it necessary to formulate strategies for combating this new threat. In a bid to combat cybercrime, a new field of study known as computer forensics (CF) has emerged worldwide.

Computer forensic science is the other name that is used to refer to this field. This science makes one of several other subfields that comprised in digital forensic science. In Albemarle, NC, there are several professionals whose area of expertise is CF. CF is a separate field of study that specializes in the analysis, reporting, and collection of data stored on digital media. The entire profession revolves around computers and digital storage media. Experts prevent and detect criminal activities by using data kept on digital media.

Computer forensic science continues to find more use in new professions. Almost every profession finds CF useful in one way or another. Law enforcement agencies are some examples of bodies that pioneered this field. These agencies make heavy use of this field in various operations. They also stand at the forefront in the major breakthroughs that have been made in CF.

There are several different scenarios in which computers can be crime scenes. For instance, during a hacking or denial of service attack, the computer in question often becomes the crime scene. Computers can also be sources of useful evidence in the form of internet history, documents, and emails, which may be relevant in crimes such as drug trafficking, kidnapping, and murder.

The scope of CF exceeds finding documents, files, and emails on computing devices. It involves the examination of metadata on documents to reveal more information about them, which could prove to be useful in solving a crime. For example, through the use of metadata, it is possible to identify the first date a document appeared or was created on computers. It is also possible to determine the last date the document was printed, edited, and saved beside identifying the user of who undertook all these operations.

CF has been employed by commercial organizations in the recent past for meet organizational goals. Commercial organizations use this field in various cases, including intellectual property theft, fraud investigations, forgeries, industrial espionage, and employment disputes. Some additional cases that are handled using CF are bankruptcy investigations, internet use in workplaces, inappropriate emails in workplaces, and regulatory compliance.

Investigators in this field employ a wide range of techniques in their investigations. Some of these techniques include cross-drive analysis, live analysis, deleted files, stochastic forensics, and steganography. Cross-drive analysis is a technique that correlates information derived from several hard drives.

CF examination is a single process that is comprised of six separate steps. These steps include readiness, presentation, review, collection, evaluation, and analysis. The list above is not in a chronological order. Although very crucial, the readiness step is often overlooked. Legal, administrative, and technical are the three broad categories of issues that prevail in this field.




About the Author:



No comments: