Showing posts with label digital forensics. Show all posts
Showing posts with label digital forensics. Show all posts

Sunday, May 17, 2020

EXAMINING THE CHALLENGES OF POLICING ECONOMIC CYBERCRIME IN THE UK

When preparing this review use was made of trialling numerous AI (artificial intelligence) tools to assist in the collection of standard definition terms and the article's reference sources. The purpose in using AI tools is determine if the tools produce inaccuracies and, if it is found, such tools can accurately produce validated results this could assist Digital Forensics, Incident Response, Cyber Security, Law Enforcement and the Criminal Justice System etc.

EXAMINING THE CHALLENGES OF POLICING ECONOMIC CYBERCRIME IN THE UK
Güvenlik Bilimleri Dergisi, Şubat 2020,UGK Özel Sayısı, 113-134

DOI:10.28956/ gbd.695956


  • Introduction:

     The advent of the Internet and its commercial applications have significantly changed the way the authors socialise, shop or communicate.
  • It is argued that the commercial application of the Internet has provided new opportunities for the commission of the traditional crime, but it has given rise to new forms of crimes (Wall, 2007b; Lee, Holt, Burruss, and Bossler, 2019).
  • Action Fraud reported that Internet users lost £34.6m as a result of cybercrime between April and September 2018, which indicates a %24 rise when compared to the previous 6 months (BBC, 2019)
  • Objectives:

     The aims of this research were two-fold: documenting the problems experienced by police officers working in cybercrime departments and discerning police officers’ perceptions related to the role of police in the wider policing assemblage.
  • Methods:

     In order to address this knowledge gap in the literature, ten semi-structured interviews were conducted with police officers working in cybercrime departments in the UK and three semi-structured interviews were done with experts working on IT departments of the local governments.
  • The research was conducted according to the Declaration of Helsinki (World Medical Association, 2001).
  • Interviewees were provided participant information sheets explaining interview and transcription processes prior to interviews.
  • Participants were asked to sign consent forms before the interviews.
  • Interviews were conducted face-to-face at police departments.
  • Interviews were recorded and transcribed verbatim by authors after the interviews
  • Results:

     Analysis of interviews conducted with police officers and cybercrime experts suggests that policing economic cybercrime is a multidimensional complex issue involving both national and international actors together with police forces.
  • Interviews with police officers revealed the lack of international cooperation as the key challenge to policing economic cybercrime.
  • Participants acknowledged that non-European countries were reluctant to share information related to online perpetrators.
  • “The companies sit in Luxemburg, Panama or Gibraltar are reluctant to share information.
  • It is difficult to catch them and bring to the jurisdiction crime happened.” (Participant 4)
  • Conclusion:

     Despite the growing cyber threat and cybersecurity concerns among the public, there is a lack of empirical research on discerning the challenges of policing economic cybercrime.
  • This result which confirms the previous studies indicates that governments or international and transnational actors have failed to collaborate to combat cybercrime globally.National and international initiatives such as UK Cybercrime Strategy 2016/2021 place emphasis upon reducing disparities among national jurisdictions and creating strong coordination between policing bodies and other private and governmental actors of cybersecurity to alleviate policing problems of cybercrime (Ellis and Mohan, 2019)
  • Despite these efforts, there is lack of empirical studies on this issue.
  • ENISA or another agency should actively seek to collaborate with non-EU countries
 
ARTICLE REFERENCE SOURCES
 
  • Akhgar, B., Choras, M., Brewster, B., Bosco, F., Veermeersch, E., Luda, V., Puchalski, D., and Wells, D. (2016) 'Consolidated Taxonomy and Research Roadmap for Cybercrime and Cyberterrorism', pp. 295-322 in B. Akhgar and B. Brewster (eds) Combatting cybercrime and cyberterrorism: challenges, trends and priorities: Springer. 
  • Anderson, R., Barton, C., Böhme, R., Clayton, R., Van Eeten, M. J., Levi, M., Moore, T., and Savage, S. (2013) 'Measuring the Cost of Cybercrime', pp. 265300 in The economics of information security and privacy: Springer.
  • Barthelemy, J. (2003) 'The seven deadly sins of outsourcing', Academy of Management Perspectives 17(2): 87-98. 
  • Bayley, D. H., and Shearing, C. D. (1996) 'The future of policing', Law Society Review 30: 585. 
  • BBC (2019) UK cyber-crime victims lose £190,000 a day. Available at: https://www.bbc.co.uk/news/uk-47016671 (Accessed:14/09/2019.
  • Blanco Hache, A. C., and Ryder, N. (2011) '’Tis The Season to (be Jolly?) WiseUp to Online Fraudsters. Criminals on The Web Lurking to Scam Shoppers this Christmas: A Critical Analysis of the United Kingdom's Legislative Provisions and Policies to Tackle Online Fraud', Information & Communications Technology Law 20(1): 35-56.
  • Boes, S., and Leukfeldt, E. R. (2017) 'Fighting Cybercrime: A Joint Effort' in R. M. Clark and S. Hakim (eds) Cyber-physical security: protecting critical infrastructure at the state and local level: Springer. 
  • Bond, E., and Tyrrell, K. (2018) 'Understanding revenge pornography: A national survey of police officers and staff in England and Wales', Journal of interpersonal violence: 0886260518760011. 
  • Bossler, A. M., and Holt, T. J. (2012) 'Patrol officers' perceived role in responding to cybercrime', Policing: an international journal of police strategies & management 35(1): 165-181. 
  • Braun, V., and Clarke, V. (2006) 'Using thematic analysis in psychology', Qualitative research in psychology 3(2): 77-101. 
  • Brenner, S. W. (2001) 'Is There Such a Thing as' Virtual Crime'?'. 
  • ---. (2004) 'Cybercrime Metrics: Old Wine, New Bottles?', VA. JL & TECH. 9: 13. ---. (2007) 'The Council of Europe’s Convention on Cybercrime', pp. 207-221 in J. 
  • Balkin, J. Grimmelmann, E. Katz, N. Kozlovski, S. Wagman and T. Zarsky (eds) Cybercrime: digital cops in a networked environment: NYU Press.
  • Brenner, S. W. (2010) Cybercrime: Criminal Threats from Cyberspace: USA: Prager. 
  • Button, M. (2019) Private policing: Routledge. 
  • Casey, E. (2011) 'Language of Computer Crime Investigation', pp. 35-48 in E. Casey (ed.), Digital Evidence and Computer Crime: Forensic Science, Computers, and the Internet. London: Elsevier. 
  • Clough, J. (2014) 'A World of Difference: The Budapest Convention of Cybercrime and the Challenges of Harmonisation', Monash UL Rev. 40: 698. 
  • Dolliver, D. S., and Poorman, K. (2018) 'Understanding Cybercrime', pp. 139-160 in P. L. Reichel and R. Randa (eds) Transnational Crime and Global Security [2 volumes]: ABC-CLIO. Ellis, R., and Mohan, V. (2019) Rewired: Cybersecurity Governance: John Wiley & Sons. European Commission (2007) Towards a General Policy on the Fight Against Cyber Crime Available at: https://eur-lex.europa.eu/LexUriServ/ LexUriServ.do?uri= COM:2007:0267:FIN:EN:PDF.--- (2019) The EU cybersecurity certification framework. Available at:https://ec.europa.eu/digital-single-market/en/eu-cybersecurity-certificationframework (Accessed:17/08/2019. 
  • Finn, B. M. (2019) 'Recommendations for a hybridized public private law enforcement approach'. Garland, D. (1996) 'THE LIMITS OF THE SOVEREIGN STATEStrategies of Crime Control in Contemporary Society', The British journal of criminology 36(4): 445-471. 
  • Gercke, M. (2012) Understanding Cybercrimes: Phenomena, Challenges and Legal Response: International Telecommunication Union. 
  • Gordon, S., and Ford, R. (2006) 'On the Definition and Classification of Cybercrime', Journal in Computer Virology 2(1): 13-20. 
  • Grabosky, P., and Smith, R. (2001) 'Telecommunications Fraud in the Digital Age: the Convergence of Technologies', pp. 23-43 in D. Wall (ed.), Crime and the Internet. London: Routledge. 
  • Grabosky, P. N. (2001) 'Virtual criminality: Old wine in new bottles?', Social & Legal Studies 10(2): 243-249. 
  • Graham, L. (2017) Cybercrime costs the global economy $450 billion: CEO. Available at: https://www.cnbc.com/2017/02/07/cybercrime-costs-the-globaleconomy-450-billion-ceo.html (Accessed:06/08/2019 2019). 
  • Hadlington, L., Lumsden, K., Black, A., and Ferra, F. (2018) 'A qualitative exploration of police officers’ experiences, challenges, and perceptions of cybercrime', Policing: A Journal of Policy and Practice. 
  • Hayes, N. (1997) 'Theory-led thematic analysis: Social identification in small companies'. 
  • Holt, T. J., Bossler, A. M., and Fitzgerald, S. (2010) 'Examining state and local law enforcement perceptions of computer crime', Crime on-line: Correlates, causes, and context: 221-246. 
  • Holt, T. J., Burruss, G. W., and Bossler, A. M. (2018) 'An examination of English and Welsh constables’ perceptions of the seriousness and frequency of online incidents', Policing and Society: 1-16. 
  • Holt, T. J., Lee, J. R., Liggett, R., Holt, K. M., and Bossler, A. (2019) 'Examining perceptions of online harassment among constables in England and Wales', International Journal of Cybersecurity Intelligence & Cybercrime 2(1): 24-39. 
  • Home Office (2014) The Serious and Organised Crime Strategy, London. 
  • --- (2018) CONTEST: The United Kingdom’s Strategy for Countering Terrorism, London. 
  • James, J. I., and Gladyshev, P. (2015) A Survey of International Cooperation in Digital Investigations, International Conference on Digital Forensics and Cyber Crime (pp. 103-114): Springer. 
  • Joh, E. E. (2019) 'Policing the smart city', International Journal of Law in Context 15(2): 177-182. 
  • Koops, B.-J. (2010) 'The internet and its opportunities for cybercrime'. 
  • Kshetri, N. (2010a) 'The Global Cybercrime Industry and Its Structure: Relevant Actors, Motivations, Threats, and Countermeasures', pp. 1-34 in The Global Cybercrime Industry: Springer. 
  • ---. (2010b) 'Structure of Cybercrime in Developing Economies', pp. 165-188 in The Global Cybercrime Industry: Springer. 
  • ---. (2013) 'Cybercrime and cyber-security issues associated with China: some economic and institutional considerations', Electronic Commerce Research 13(1): 41-69.
  • Lam, P. T. (2019) 'Public–Private Partnerships for Fire, Police, and Ambulance Services', pp. 153-165 in Public Private Partnerships: Springer. 
  • Lee, J. R., Holt, T. J., Burruss, G. W., and Bossler, A. M. (2019) 'Examining English and Welsh Detectives’ Views of Online Crime', International Criminal Justice Review: 1057567719846224. 
  • Levi, M., Doig, A., Gundur, R., Wall, D., and Williams, M. L. (2015) The Implications of Economic Cybercrime for Policing: City of London Corporation. Available at: https://www.cityoflondon.gov.uk/business/economicresearch-and-information/research-publications/Documents/Research2015/Economic-Cybercrime-FullReport.pdf. (Accessed:11 June 2017). 
  • Maguire, M., and Delahunt, B. (2017) 'Doing a thematic analysis: A practical, stepby-step guide for learning and teaching scholars', AISHE-J: The All Ireland Journal of Teaching and Learning in Higher Education 9(3). 
  • Malby, S., Mace, R., Holterhof, A., Brown, C., Kascherus, S., and Ignatuschtschenko, E. (2013) 'Comprehensive Study on Cybercrime', United Nations Office on Drugs and Crime, Tech. Rep. 
  • Nouh, M., Nurse, J. R., Webb, H., and Goldsmith, M. (2019) 'Cybercrime Investigators are Users Too! Understanding the Socio-Technical Challenges Faced by Law Enforcement', arXiv preprint arXiv:1902.06961. 
  • Pathak, P. (2016) 'The Review of Terms and Concepts Used to Understand Cybercrime to Safeguard Ourselves from Cybercriminals', International Journal of Advanced Research in Computer Science 7(1). 
  • Petee, T. A., Corzine, J., Huff-Corzine, L., Clifford, J., and Weaver, G. (2010) 'Defining” Cyber-crime”: Issues in Determining the Nature and Scope of Computer-related Offenses,”', Futures Working Group 5: 6-11. 
  • Reinhart, R. J. (2018) One in Four Americans Have Experienced Cybercrime. Available at: https://news.gallup.com/poll/245336/one-four-americansexperienced-cybercrime.aspx (Accessed:08/09/2019. 
  • Ruddell, R., Thomas, M. O., and Patten, R. (2011) 'Examining the roles of the police and private security officers in urban social control', International Journal of Police Science & Management 13(1): 54-69. 
  • Sandywell, B. (2013) 'On the Globalisation of Crime: the Internet and New Criminality', pp. 56-84 in Handbook of internet crime: Willan. 
  • Summerville, A. (2017) Protect against the fastest-growing crime: cyber attacks. Available at: https://www.cnbc.com/2017/07/25/stay-protected-from-the-ussfastest-growing-crime-cyber-attacks.html (Accessed:06/08/2019 2019). ↩
  • Taylor, G. (2002) 'The Council of Europe Cybercrime Convention a Civil Liberties Perspective', Retrieved June 13: 2006. 
  • The Council of Europe Convention on Cybercrime. (2001) Convention on Cybercrime. In T. C. o. Europe (Ed.). Budapest: European Treaty Series - No. 185.
  • Thomas, D., and Loader, B. (2000) 'Cybercrime: Law Enforcement, Security and Surveillance in the Information Age' in D. Thomas and B. Loader (eds) Cybercrime: Law enforcement, security and surveillance in the information age. London: Routledge. 
  • UN Congress. (2000) Crimes Related to Computer Networks, 10th United Nations Congress on the Prevention of Crime and the Treatment of Offenders. Vienna: United Nations.
  • UN Manual (1994) United Nations Manual on the Prevention and Control of Computer-Related Crime. Available at: http://216.55.97.163/wpcontent/themes/bcb/bdf/int_regulations/un/CompCrims_UN_Guide.pdf (Accessed:21/03/2017).
  • Wall, D. S. (2005) 'Digital Realism and the Governance of Spam as Cybercrime', European journal on criminal policy and research 10(4): 309-335. 
  • ---. (2007a) Cybercrime: The transformation of crime in the information age: Polity.
  • ---. (2007b) Cybercrime: The Transformation of Crime in the Information Age: Cambridge: Polity Press.
  • ---. (2008) 'Cybercrime, Media and Insecurity: The Shaping of Public Perceptions of Cybercrime', International Review of Law, Computers & Technology 22(12): 45-63.
  • ---. (2010) 'Policing Cybercrimes: Situating the Public Police in Networks of Security Within Cyberspace (Revised May 2010)', Police Practice and Research 8(2): 183-205.
  • ---. (2013a) 'Criminalising Cyberspace: The Rise of the Internet as a ‘Crime Problem’', pp. 106-121 in Handbook of Internet Crime: Willan.
  • ---. (2013b) 'Policing Identity Crimes', pp. 29-52 in D. S. Wall and M. L. Williams (eds) Policing cybercrime: networked and social media technologies and the challenges for policing: Taylor & Francis. 
  • Wall, D. S., and Williams, M. (2014) Policing cybercrime: networked and social media technologies and the challenges for policing: Routledge. 
  • Williams, M., and Levi, M. (2015) 'Perceptions of the ecrime Controllers: Modelling the Influence of Cooperation and Data Source Factors', Security Journal 28(3): 252-271. 
  • World Medical Association. (2001) 'World Medical Association Declaration of Helsinki. Ethical principles for medical research involving human subjects', Bulletin of the World Health Organization 79(4): 373.
  • Yar, M. (2005) 'The Novelty of 'Cybercrime’ an Assessment in Light of Routine Activity Theory', European Journal of Criminology 2(4): 407-427. 
  • ---. (2013a) Cybercrime and Society: Sage. ---. (2013b) 'The Private Policing of Internet Crime' in Y. Jewkes and M. Yar (eds) ↩
 

Wednesday, February 14, 2018

Important principles in digital forensics


At a time when digital forensics is under the spotlight and taking salvos of criticism for poor performance and lack of knowledge about its own scientific subject matter (http://parliamentlive.tv/Event/Index/7767e1b9-0e44-4de3-8627-baf9d091f487 and https://www.theguardian.com/uk-news/2018/feb/12/police-outsource-digital-forensic-work-to-unaccredited-labs) there is no better time than to refresh on principles to signpost the way to go or leave a breadcrumb trail to find the way back to safe ground.

I posted comments back in November 2006 (http://trewmte.blogspot.co.uk/2006/11/cell-site-analysis.html) identifying principles to remember, recall and apply, when conducting Cell Site Analysis (CSA) - but they apply to examinations also -  that are still relevant to today (2G/3G/4G/5G/etc....) as they were since the inception of digital cellular radio services back in the late 1980s/1990s.

The requirements identified in standards as "mandatory", "conditional", "recommendations" and so on are not written for fun;  nor to be wilfully disregarded just because they appear complex, complicated or difficult e.g. cannot be bothered to learn them, my device/machine does the thinking for me; both render the human-being to be no more than a perfunctory-goffer (human obsolescence) for the processes generated by software and algorithms in a device or machine.

The four principles to easily remember, recall and apply:

- There are mandatory requirements with mandatory outcomes
- There are mandatory requirements with optional outcomes
- There are optional requirements with mandatory outcomes
- There are optional requirements with optional outcomes


Moreover, and a fundamental (and one might suggest absolute) requirement, is the importance to understanding 'Modal verbs terminology' adopted in the standards.

Modal verbs terminology

In the present document "shall", "shall not", "should", "should not", "may", "may not", "need", "need not", "will", "will not", "can" and "cannot" are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions)

"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.

Sunday, April 09, 2017

Digital Evidence ISO/IEC 27037 -v- ISO/IEC 17025

Could ISO/IEC 27037:2012 be the better option for handling and obtaining digital forensic evidence?




ISO/IEC 27037:2012-10 (E)
Information technology - Security techniques - Guidelines for identification,
collection, acquisition and preservation of digital evidence


Contents
Foreword .......................................................................................................................................................... v
Introduction ..................................................................................................................................................... vi
1 Scope ............................................................................................................................................... 1
2 Normative reference ....................................................................................................................... 1
3 Terms and definitions .................................................................................................................... 2
4 Abbreviated terms .......................................................................................................................... 4
5 Overview ......................................................................................................................................... 6
5.1 Context for collecting digital evidence ........................................................................................ 6
5.2 Principles of digital evidence........................................................................................................ 6
5.3 Requirements for digital evidence handling ............................................................................... 6
5.3.1 General ............................................................................................................................................ 6
5.3.2 Auditability ...................................................................................................................................... 7
5.3.3 Repeatability ................................................................................................................................... 7
5.3.4 Reproducibility ............................................................................................................................... 7
5.3.5 Justifiability .................................................................................................................................... 7
5.4 Digital evidence handling processes ........................................................................................... 8
5.4.1 Overview ......................................................................................................................................... 8
5.4.2 Identification ................................................................................................................................... 8
5.4.3 Collection ........................................................................................................................................ 9
5.4.4 Acquisition ...................................................................................................................................... 9
5.4.5 Preservation.................................................................................................................................. 10
6 Key components of identification, collection, acquisition and preservation of digital
evidence ........................................................................................................................................ 10
6.1 Chain of custody .......................................................................................................................... 10
6.2 Precautions at the site of incident.............................................................................................. 11
6.2.1 General .......................................................................................................................................... 11
6.2.2 Personnel ...................................................................................................................................... 11
6.2.3 Potential digital evidence ............................................................................................................ 12
6.3 Roles and responsibilities ........................................................................................................... 12
6.4 Competency .................................................................................................................................. 13
6.5 Use reasonable care .................................................................................................................... 13
6.6 Documentation ............................................................................................................................. 14
6.7 Briefing .......................................................................................................................................... 14
6.7.1 General .......................................................................................................................................... 14
6.7.2 Digital evidence specific ............................................................................................................. 14
6.7.3 Personnel specific ........................................................................................................................ 15
6.7.4 Real-time incidents ...................................................................................................................... 15
6.7.5 Other briefing information ........................................................................................................... 15
6.8 Prioritizing collection and acquisition ....................................................................................... 16
6.9 Preservation of potential digital evidence ................................................................................. 17
6.9.1 Overview ....................................................................................................................................... 17
6.9.2 Preserving potential digital evidence ......................................................................................... 17
6.9.3 Packaging digital devices and potential digital evidence ........................................................ 17
6.9.4 Transporting potential digital evidence ..................................................................................... 18
7 Instances of identification, collection, acquisition and preservation .................................... 19
7.1 Computers, peripheral devices and digital storage media ..................................................... 19
7.1.1 Identification ................................................................................................................................ 19
7.1.2 Collection ..................................................................................................................................... 21
7.1.3 Acquisition ................................................................................................................................... 25
7.1.4 Preservation ................................................................................................................................. 29
7.2 Networked devices ...................................................................................................................... 29
7.2.1 Identification ................................................................................................................................ 29
7.2.2 Collection, acquisition and preservation .................................................................................. 31
7.3 CCTV collection, acquisition and preservation ........................................................................ 33
Annex A (informative) DEFR core skills and competency description ................................................... 35
Annex B (informative) Minimum documentation requirements for evidence transfer .......................... 37
Bibliography .................................................................................................................................................. 38

Sunday, December 27, 2015

SDD: TRIM, GC and Greedy Garbage etc

SDD: TRIM, GC and Greedy Garbage etc

It is amazing how we can all look at the same subject but still have a wide range of views. If the discussion is about TRIM and GC then the two should not be confused. That is fair warning, but isn't there something quite obvious in the two different titles? If we extend confusion further what Write Amplification or hot and cold data or SSDs with no TRIM feature at all? The diversity in opinions may well be put down to has:

(a) conducted tests and
(b) which tests were they
(c) any standard involved
(d) any manufacturer spec involved and
(e) any research material read influencing the thought processes?

Who knows the answers as many of the discussions read rarely identify the sources of knowledge.

I cannot guarantee you that this thread will provide all the answers but here are some sources of information that may help. Perhaps you can contribute, too? The materials are not arranged in any particular order.

why-ssd-destroy-court-evidence - http://belkasoft.com/download/info/SSD%20Forensics%202012.pdf

ssd-2014 - http://belkasoft.com/download/info/SSD%20Forensics%202014.pdf

Mac OSx enabling TRIM - http://arstechnica.com/apple/2015/06/latest-os-x-update-allows-you-to-enable-trim-for-third-party-ssds/

Kingston on Garbage Collection - http://media.kingston.com/images/ssd/technicalbrief/MKF_608_%20SSDGarbagecollectionTechBrief.pdf

On the Optimality of Greedy Garbage Collection for SSDs - https://www.dropbox.com/s/62743amgz9yu9nd/YYang.pdf?dl=0

Write Amplification - https://www.dropbox.com/s/ty0e4hs9aou5mux/WriteAmplification.pdf?dl=0

A Mean Field Model for a Class of Garbage Collection
Algorithms in Flash-based Solid State Drives
- https://www.dropbox.com/s/xailw5tb702dsfe/VanHoudt_QUESTA.pdf?dl=0


Establishing Professional Guidelines for SSD Forensics: A Case Study - https://www.dropbox.com/s/y1eqlqhtd7q0e69/UchiyamaJJ.pdf?dl=0

 Model and Analysis of Trim Commands in Solid State Drives - https://www.dropbox.com/s/z7b5u7s0flvywa8/TRIM%20eScholarship%20UC%20item%208gn63800.pdf?dl=0

To TRIM or Not to TRIM: Judicious TRIMing for Solid State Drives - https://www.dropbox.com/s/nfce2k3h3j2jc89/sosp11-final16.pdf?dl=0

DELL Solid State Drive (SSD) FAQ - https://www.dropbox.com/s/tushqjeow02ds0n/Solid-State-Drive-FAQ-us.pdf?dl=0

SATA-IO Releases Revision 3.1 Specification - https://www.dropbox.com/s/5buxd4qtvnhpfvu/SATA-IORevision31_PRfinal.pdf?dl=0

The Fundamental Limit of Flash Random Write Performance: Understanding, Analysis and Performance Modelling - https://www.dropbox.com/s/me322d1e4xoz2md/rz3771.pdf?dl=0

Performance of garbage collection algorithms for flash-based solid state drives with hot/cold data - https://www.dropbox.com/s/8a66duhnc2b5w09/hot_cold.pdf?dl=0

Extending the Lifetime of Flash-based Storage through Reducing Write Amplification from File Systems - https://www.dropbox.com/s/c7vdp3011icue68/fast13-final110.pdf?dl=0

Data Set Management Commands Proposal for ATA8-ACS2 2007 - https://www.dropbox.com/s/vkm0er1804swk2z/e07154r6-Data_Set_Management_Proposal_for_ATA-ACS2.pdf?dl=0

Information technology -ATA/ATAPI Command Set - 2 (ACS-2) 2009 - https://www.dropbox.com/s/6tm8pbu41tefcm3/d2015r1-ATAATAPI_Command_Set_-_2_ACS-2.pdf?dl=0

Information technology -ATA/ATAPI Command Set - 2 (ACS-2) 2011 - https://www.dropbox.com/s/l4onbxkeeuqa4is/d2015r6-ATAATAPI_Command_Set_-_2_ACS-2.pdf?dl=0

Modelling and Managing SSD Write-amplification - https://www.dropbox.com/s/r59p76n5oa7nzhe/1504.00229.pdf?dl=0

Sunday, August 02, 2015

National Digital Science and Justice Office (NDSJO)

A recent forum discussion I read recently mentioned a Digital Forensics Capability Review. The discussion also identified the document that forms the basis of this review: http://www.researchgate.net/publication/269332581_Digital_Forensics__Capability_Review

There were some good responses from forum members. Those responses combined with the initial enquiry and the download reference document suggested to me that keep tinkering here and there with different elements in "digital forensics" is perhaps why there is no real substantive change consolidating "digital forensics". There is a desire to galvanise a unifying system but as digital forensics is made up of so many constituent elements it maybe quite difficult to know where to start.

Some observations:

1) Industry specific foundation materials are need to make work ISO/IEC 17025; the latter document tries to be all things to all men - ISO/IEC 17025 is used by many industries from chemical production, metals, drugs, fertilisers through to food products etc. People may passionately argue it is the right standard to follow. ISO/IEC 17025 is a commercially orientated document for business. It outlines what is expected to get business but not how to go about achieving the results it defines should be met. Achieving the result requires specific i) competencies ii) knowledge iii) skillsets and iv) experiences which are not defined when simply applying over-arching generic principles.

2) A document that should be replaced is the "Association of Chief Police Officers (ACPO) Principles (ACPO, 2012)". There should be in its place an industry document for digital forensic principles similar to the US NIST documents. This document should be for all and created by all and not created by public servants. Just because a document is not 'authorised' as the de facto standard doesn't mean to say it isn't being used in that way to ensure public funds are misguidedly placed in only certain sectors. This means an industry document would apply to everyone following the same criteria set by a 'body' as opposed to "don't do what we do, do what we say" brigade.  

3) There needs to be a body such as National Digital Science and Justice Office (NDSJO) that is not run by public or private cronies or apparatchik but by an elected office with elections every five years and no employment-for-life positions. It is important that at least one Active or Retired Senior Judge should be elected to post responsible for safeguarding independence, objectivity and impartiality and with the legal authority to enforce that. 3.1) The NDSJO shall avoid discrimination of any sort and the NDSJO to publish lists of those engaged by the NDSJO measured against criterion such as "age", "sex", "ethnicity" etc. and identify and put deterrents in place to prevent favour to one particular group of persons or political pressures. 3.2) The NDSJO to feed knowledge into national schools, academies, and colleges science education system for the future development of our children. 3.3) The NDSJO shall also provide for a membership and membership fee to ensure wisdom, knowledge, skills and experience thrives within the NDSJO. 3.4) The NDSJO shall work with the Competition Commission etc. to detect and stop cartels or monopolies taking place on public sector contracts. The higher proportion of public sector contracts to go to small and medium sized businesses to help them grow and to avoid large organisations dumping high levels of staff that can undermine the British economy.  3.5) To prevent major contract holders (a) suppressing salaries, wages or self-employed payments and skimming off profits whilst forcing sub-contractors to constantly find savings causing significant detriment to work performance, salaries/wages/self employed payment that when unfettered influence upturn in the British economy. 3.6) The NDSJO shall be responsible for preparing and producing particular digital science industry documents.

4) All manufacturers providing purchased or free tools (software and hardware) to be used for acquiring evidence whether commercial or forensic tools shall be registered with the NDSJO. Manufacturers shall legally self-certify their product as fit for purpose and those who sell tools provide the necessary insurance for all claims. The NDSJO to identify insurance schemes for free tools that have been produced through goodwill but having an effective and affective role when used in acquiring evidence. The latter may equally involve the user of the free tool providing an insurance that might be encapsulated as part of the membership fee of the NDSJO.

...is it true that someone is smiling on the plans above? Well it could act as a needed fillip to the British economy.

Thursday, February 26, 2009

What is happening with Digital Forensics UK

What is happening with Digital Forensics UK
.
For those of you that did not know, which is probably most of the digital forensics community in the UK, as I didn't know, until today 26th February 2009, the Forensic Science Regulator is having a conference in Birmingham on the 31st March 2009 to be held at the International Convention Centre (ICC), Broad Street, Birmingham, B1 2EA. The aim of the conference is for the purpose "As part of the consultation process, the Regulator is to hold a conference for digital forensics practitioners as a group of experts to focus on the standards and to provide opportunities for detailed feedback."
.
Disappointingly, the closing date to submit applications to attend was the 23rd February 2009. Regrettably, there is no notification at the Forensic Science Regulator's website and no notification to the established expert bodies in the UK about the conference. Instead, the matter was left to a small, but interesting, digital forensic forum that does not represent, and nor is it the voice of, the digital forensics community as a whole in the UK, to circulate the conference notice but sent to those forum's members only.