Presentation is loading. Please wait.

Presentation is loading. Please wait.

Digital Forensics. Hardware components Motherboard Motherboard System bus System bus CPU CPU ROM ROM RAM RAM HDD HDD Input devices Input devices Output.

Similar presentations


Presentation on theme: "Digital Forensics. Hardware components Motherboard Motherboard System bus System bus CPU CPU ROM ROM RAM RAM HDD HDD Input devices Input devices Output."— Presentation transcript:

1 Digital Forensics

2 Hardware components Motherboard Motherboard System bus System bus CPU CPU ROM ROM RAM RAM HDD HDD Input devices Input devices Output devices Output devices

3 Storing and Retrieving Data OS OS Formatting and Partitioning the HDD Formatting and Partitioning the HDD Mapping the HDD Mapping the HDD Sectors Sectors Clusters Clusters Tracks Tracks Cylinders Cylinders

4 Documenting the Electronic Crime Scene Document the scene Document the scene Photograph overall layout Photograph overall layout Photograph all connections Photograph all connections Decide on data acquisition method Decide on data acquisition method Forensic Image Acquisition Forensic Image Acquisition Must not alter data in anyway Must not alter data in anyway Can’t just boot up or will alter HDD Can’t just boot up or will alter HDD Remove HDD and place in forensic computer Remove HDD and place in forensic computer Use MD5 or SHA algorithms to fingerprint disk Use MD5 or SHA algorithms to fingerprint disk

5 Analysis of Electronic Data Visible data Visible data Data/Work product files Data/Work product files Swap file data Swap file data Temporary files Temporary files Latent Data Latent Data Slack space Slack space RAM slack RAM slack File slack File slack Unallocated space Unallocated space Defragmenting Defragmenting Swap files/swap space Swap files/swap space Deleted files Deleted files

6 The Internet Browsers Browsers URL URL Hypertext Hypertext Bookmark Bookmark Search engines Search engines Email Email Mailing lists Mailing lists Newsgroups Newsgroups

7 The World-Wide Web Internet cache Internet cache Cookies Cookies Internet history Internet history Bookmarks/Favorites Bookmarks/Favorites

8 Forensic Analysis of Internet Data IP addresses IP addresses Email, Chat and IM Email, Chat and IM Hacking Hacking Firewall Firewall

9 Forensic Investigation of Internet Communications Connections Connections Modem Modem Broadband Broadband DSL DSL Wi-Fi Wi-Fi Routers Routers VoIP VoIP ISPs ISPs IP IP Domains Domains

10 Forensic Psychiatry/Psychology Psychological testing Psychological testing Rorschach Rorschach Thematic-Apperception Test Thematic-Apperception Test Personality Inventories Personality Inventories Intellectual and Cognitive Assessment Intellectual and Cognitive Assessment Altered State Interviews Altered State Interviews


Download ppt "Digital Forensics. Hardware components Motherboard Motherboard System bus System bus CPU CPU ROM ROM RAM RAM HDD HDD Input devices Input devices Output."

Similar presentations


Ads by Google