Presentation is loading. Please wait.

Presentation is loading. Please wait.

THE IMPACT OF USING NON- VALIDATED FORENSIC ACQUISITION TOOLS ON DIGITAL EVIDENCE Lex Informatica Conference 25 th September 2014.

Similar presentations


Presentation on theme: "THE IMPACT OF USING NON- VALIDATED FORENSIC ACQUISITION TOOLS ON DIGITAL EVIDENCE Lex Informatica Conference 25 th September 2014."— Presentation transcript:

1 THE IMPACT OF USING NON- VALIDATED FORENSIC ACQUISITION TOOLS ON DIGITAL EVIDENCE Lex Informatica Conference 25 th September 2014

2 DIGITAL EVIDENCE  Digital evidence is increasingly common in court proceedings  Digital evidence is a very fragile form of evidence and requires special methods to collect and preserve  Digital forensics is a crucial tool in the collection and preservation of digital evidence

3 THE FORENSIC ACQUISITION PROCESS ProtectCollectVerify

4 FORENSIC ACQUISITION TOOLS Forensic Acquisition Write Blocking Forensic Imaging

5 MINIMUM ACCEPTABLE FORENSIC SCIENCE STANDARD Forensic Acquisition Tools Validated Findings Verifiable Correct Processes

6 THE CURRENT SITUATION IN SOUTH AFRICA

7 TRAINING ON THE IMPORTANCE OF VALIDATION

8 TRAINING ON HOW TO CONDUCT VALIDATION TESTING

9 KNOWLEDGE OF VALIDATION STANDARDS

10 CLAIMED TO USE VALIDATED WRITE BLOCKERS

11 HOW WRITE BLOCKING VALIDITY WAS ENSURED

12 REASONS FOR NOT USING VALIDATED WRITE BLOCKERS

13 HOW VALIDATION WAS CONFIRMED WHEN NOT TESTED PERSONALLY

14 PERSONAL VALIDATION TESTING OF WRITE BLOCKERS

15 CLAIMED USE OF VALIDATED FORENSIC IMAGING HARDWARE OR SOFTWARE

16 HOW FORENSIC IMAGER VALIDATION WAS ASSURED

17 REASONS FOR NOT USING VALIDATED FORENSIC IMAGING HARDWARE OR SOFTWARE

18 HOW VALIDATION WAS CONFIRMED FOR FORENSIC IMAGERS

19 PERSONAL VALIDATION TESTING OF FORENSIC IMAGERS

20 SO WHAT DOES THIS ALL MEAN At least 81 percent of all digital evidence that finds it way into South African courts cannot be objectively verified as having any evidential integrity. In the 19 percent of other cases, the means of objectively verifying evidential integrity is so poor that it would be unlikely to survive robust cross-examination.

21 SECTION 15 OF THE ECT ACT  One of the key aspects that the courts must take into consideration when examining the weight of digital is the manner in which the integrity of the digital evidence was determined and maintained  If non-validated tools are used to preserve the evidence, there is no way to prove to the court that the integrity of the digital evidence was determined or maintained at all

22 THE WAY FORWARD  Insist on proof of all hardware and software tools used in the forensic acquisition process  Insist on detailed proof of how validation was determined  Don’t use any digital evidence that has not been obtained using validated forensic acquisition tools

23 THANK YOU Jason Jordaan CFCE, CFE, PMIITPSA, GCFE MSc, MTech, BComHons, BSc, BTech Principal Forensic Scientist jason@dfirlabs.com


Download ppt "THE IMPACT OF USING NON- VALIDATED FORENSIC ACQUISITION TOOLS ON DIGITAL EVIDENCE Lex Informatica Conference 25 th September 2014."

Similar presentations


Ads by Google