Could ISO/IEC 27037:2012 be the better option for handling and obtaining digital forensic evidence?
ISO/IEC 27037:2012-10 (E)
Information technology - Security techniques - Guidelines for identification,
collection, acquisition and preservation of digital evidence
Contents
Foreword .......................................................................................................................................................... v
Introduction ..................................................................................................................................................... vi
1 Scope ............................................................................................................................................... 1
2 Normative reference ....................................................................................................................... 1
3 Terms and definitions .................................................................................................................... 2
4 Abbreviated terms .......................................................................................................................... 4
5 Overview ......................................................................................................................................... 6
5.1 Context for collecting digital evidence ........................................................................................ 6
5.2 Principles of digital evidence........................................................................................................ 6
5.3 Requirements for digital evidence handling ............................................................................... 6
5.3.1 General ............................................................................................................................................ 6
5.3.2 Auditability ...................................................................................................................................... 7
5.3.3 Repeatability ................................................................................................................................... 7
5.3.4 Reproducibility ............................................................................................................................... 7
5.3.5 Justifiability .................................................................................................................................... 7
5.4 Digital evidence handling processes ........................................................................................... 8
5.4.1 Overview ......................................................................................................................................... 8
5.4.2 Identification ................................................................................................................................... 8
5.4.3 Collection ........................................................................................................................................ 9
5.4.4 Acquisition ...................................................................................................................................... 9
5.4.5 Preservation.................................................................................................................................. 10
6 Key components of identification, collection, acquisition and preservation of digital
evidence ........................................................................................................................................ 10
6.1 Chain of custody .......................................................................................................................... 10
6.2 Precautions at the site of incident.............................................................................................. 11
6.2.1 General .......................................................................................................................................... 11
6.2.2 Personnel ...................................................................................................................................... 11
6.2.3 Potential digital evidence ............................................................................................................ 12
6.3 Roles and responsibilities ........................................................................................................... 12
6.4 Competency .................................................................................................................................. 13
6.5 Use reasonable care .................................................................................................................... 13
6.6 Documentation ............................................................................................................................. 14
6.7 Briefing .......................................................................................................................................... 14
6.7.1 General .......................................................................................................................................... 14
6.7.2 Digital evidence specific ............................................................................................................. 14
6.7.3 Personnel specific ........................................................................................................................ 15
6.7.4 Real-time incidents ...................................................................................................................... 15
6.7.5 Other briefing information ........................................................................................................... 15
6.8 Prioritizing collection and acquisition ....................................................................................... 16
6.9 Preservation of potential digital evidence ................................................................................. 17
6.9.1 Overview ....................................................................................................................................... 17
6.9.2 Preserving potential digital evidence ......................................................................................... 17
6.9.3 Packaging digital devices and potential digital evidence ........................................................ 17
6.9.4 Transporting potential digital evidence ..................................................................................... 18
7 Instances of identification, collection, acquisition and preservation .................................... 19
7.1 Computers, peripheral devices and digital storage media ..................................................... 19
7.1.1 Identification ................................................................................................................................ 19
7.1.2 Collection ..................................................................................................................................... 21
7.1.3 Acquisition ................................................................................................................................... 25
7.1.4 Preservation ................................................................................................................................. 29
7.2 Networked devices ...................................................................................................................... 29
7.2.1 Identification ................................................................................................................................ 29
7.2.2 Collection, acquisition and preservation .................................................................................. 31
7.3 CCTV collection, acquisition and preservation ........................................................................ 33
Annex A (informative) DEFR core skills and competency description ................................................... 35
Annex B (informative) Minimum documentation requirements for evidence transfer .......................... 37
Bibliography .................................................................................................................................................. 38
Investigations, Practices and Procedures: Seizure-Forensic Examination-Evidence. Cellular and Satellite Telephones, Call Records-Billing Data, Cell Site Analysis. Telecomms. Computer and Network Analysis. GPS devices & Jammers, Cyber, IoT forensics.
Showing posts with label digital investigations. Show all posts
Showing posts with label digital investigations. Show all posts
Sunday, April 09, 2017
Sunday, December 27, 2015
SDD: TRIM, GC and Greedy Garbage etc
SDD: TRIM, GC and Greedy Garbage etc
It is amazing how we can all look at the same subject but still have a wide range of views. If the discussion is about TRIM and GC then the two should not be confused. That is fair warning, but isn't there something quite obvious in the two different titles? If we extend confusion further what Write Amplification or hot and cold data or SSDs with no TRIM feature at all? The diversity in opinions may well be put down to has:
(a) conducted tests and
(b) which tests were they
(c) any standard involved
(d) any manufacturer spec involved and
(e) any research material read influencing the thought processes?
Who knows the answers as many of the discussions read rarely identify the sources of knowledge.
I cannot guarantee you that this thread will provide all the answers but here are some sources of information that may help. Perhaps you can contribute, too? The materials are not arranged in any particular order.
why-ssd-destroy-court-evidence - http://belkasoft.com/download/info/SSD%20Forensics%202012.pdf
ssd-2014 - http://belkasoft.com/download/info/SSD%20Forensics%202014.pdf
Mac OSx enabling TRIM - http://arstechnica.com/apple/2015/06/latest-os-x-update-allows-you-to-enable-trim-for-third-party-ssds/
Kingston on Garbage Collection - http://media.kingston.com/images/ssd/technicalbrief/MKF_608_%20SSDGarbagecollectionTechBrief.pdf
On the Optimality of Greedy Garbage Collection for SSDs - https://www.dropbox.com/s/62743amgz9yu9nd/YYang.pdf?dl=0
Write Amplification - https://www.dropbox.com/s/ty0e4hs9aou5mux/WriteAmplification.pdf?dl=0
A Mean Field Model for a Class of Garbage Collection
Algorithms in Flash-based Solid State Drives - https://www.dropbox.com/s/xailw5tb702dsfe/VanHoudt_QUESTA.pdf?dl=0
Establishing Professional Guidelines for SSD Forensics: A Case Study - https://www.dropbox.com/s/y1eqlqhtd7q0e69/UchiyamaJJ.pdf?dl=0
Model and Analysis of Trim Commands in Solid State Drives - https://www.dropbox.com/s/z7b5u7s0flvywa8/TRIM%20eScholarship%20UC%20item%208gn63800.pdf?dl=0
To TRIM or Not to TRIM: Judicious TRIMing for Solid State Drives - https://www.dropbox.com/s/nfce2k3h3j2jc89/sosp11-final16.pdf?dl=0
DELL Solid State Drive (SSD) FAQ - https://www.dropbox.com/s/tushqjeow02ds0n/Solid-State-Drive-FAQ-us.pdf?dl=0
SATA-IO Releases Revision 3.1 Specification - https://www.dropbox.com/s/5buxd4qtvnhpfvu/SATA-IORevision31_PRfinal.pdf?dl=0
The Fundamental Limit of Flash Random Write Performance: Understanding, Analysis and Performance Modelling - https://www.dropbox.com/s/me322d1e4xoz2md/rz3771.pdf?dl=0
Performance of garbage collection algorithms for flash-based solid state drives with hot/cold data - https://www.dropbox.com/s/8a66duhnc2b5w09/hot_cold.pdf?dl=0
Extending the Lifetime of Flash-based Storage through Reducing Write Amplification from File Systems - https://www.dropbox.com/s/c7vdp3011icue68/fast13-final110.pdf?dl=0
Data Set Management Commands Proposal for ATA8-ACS2 2007 - https://www.dropbox.com/s/vkm0er1804swk2z/e07154r6-Data_Set_Management_Proposal_for_ATA-ACS2.pdf?dl=0
Information technology -ATA/ATAPI Command Set - 2 (ACS-2) 2009 - https://www.dropbox.com/s/6tm8pbu41tefcm3/d2015r1-ATAATAPI_Command_Set_-_2_ACS-2.pdf?dl=0
Information technology -ATA/ATAPI Command Set - 2 (ACS-2) 2011 - https://www.dropbox.com/s/l4onbxkeeuqa4is/d2015r6-ATAATAPI_Command_Set_-_2_ACS-2.pdf?dl=0
Modelling and Managing SSD Write-amplification - https://www.dropbox.com/s/r59p76n5oa7nzhe/1504.00229.pdf?dl=0
It is amazing how we can all look at the same subject but still have a wide range of views. If the discussion is about TRIM and GC then the two should not be confused. That is fair warning, but isn't there something quite obvious in the two different titles? If we extend confusion further what Write Amplification or hot and cold data or SSDs with no TRIM feature at all? The diversity in opinions may well be put down to has:
(a) conducted tests and
(b) which tests were they
(c) any standard involved
(d) any manufacturer spec involved and
(e) any research material read influencing the thought processes?
Who knows the answers as many of the discussions read rarely identify the sources of knowledge.
I cannot guarantee you that this thread will provide all the answers but here are some sources of information that may help. Perhaps you can contribute, too? The materials are not arranged in any particular order.
why-ssd-destroy-court-evidence - http://belkasoft.com/download/info/SSD%20Forensics%202012.pdf
ssd-2014 - http://belkasoft.com/download/info/SSD%20Forensics%202014.pdf
Mac OSx enabling TRIM - http://arstechnica.com/apple/2015/06/latest-os-x-update-allows-you-to-enable-trim-for-third-party-ssds/
Kingston on Garbage Collection - http://media.kingston.com/images/ssd/technicalbrief/MKF_608_%20SSDGarbagecollectionTechBrief.pdf
On the Optimality of Greedy Garbage Collection for SSDs - https://www.dropbox.com/s/62743amgz9yu9nd/YYang.pdf?dl=0
Write Amplification - https://www.dropbox.com/s/ty0e4hs9aou5mux/WriteAmplification.pdf?dl=0
A Mean Field Model for a Class of Garbage Collection
Algorithms in Flash-based Solid State Drives - https://www.dropbox.com/s/xailw5tb702dsfe/VanHoudt_QUESTA.pdf?dl=0
Establishing Professional Guidelines for SSD Forensics: A Case Study - https://www.dropbox.com/s/y1eqlqhtd7q0e69/UchiyamaJJ.pdf?dl=0
Model and Analysis of Trim Commands in Solid State Drives - https://www.dropbox.com/s/z7b5u7s0flvywa8/TRIM%20eScholarship%20UC%20item%208gn63800.pdf?dl=0
To TRIM or Not to TRIM: Judicious TRIMing for Solid State Drives - https://www.dropbox.com/s/nfce2k3h3j2jc89/sosp11-final16.pdf?dl=0
DELL Solid State Drive (SSD) FAQ - https://www.dropbox.com/s/tushqjeow02ds0n/Solid-State-Drive-FAQ-us.pdf?dl=0
SATA-IO Releases Revision 3.1 Specification - https://www.dropbox.com/s/5buxd4qtvnhpfvu/SATA-IORevision31_PRfinal.pdf?dl=0
The Fundamental Limit of Flash Random Write Performance: Understanding, Analysis and Performance Modelling - https://www.dropbox.com/s/me322d1e4xoz2md/rz3771.pdf?dl=0
Performance of garbage collection algorithms for flash-based solid state drives with hot/cold data - https://www.dropbox.com/s/8a66duhnc2b5w09/hot_cold.pdf?dl=0
Extending the Lifetime of Flash-based Storage through Reducing Write Amplification from File Systems - https://www.dropbox.com/s/c7vdp3011icue68/fast13-final110.pdf?dl=0
Data Set Management Commands Proposal for ATA8-ACS2 2007 - https://www.dropbox.com/s/vkm0er1804swk2z/e07154r6-Data_Set_Management_Proposal_for_ATA-ACS2.pdf?dl=0
Information technology -ATA/ATAPI Command Set - 2 (ACS-2) 2009 - https://www.dropbox.com/s/6tm8pbu41tefcm3/d2015r1-ATAATAPI_Command_Set_-_2_ACS-2.pdf?dl=0
Information technology -ATA/ATAPI Command Set - 2 (ACS-2) 2011 - https://www.dropbox.com/s/l4onbxkeeuqa4is/d2015r6-ATAATAPI_Command_Set_-_2_ACS-2.pdf?dl=0
Modelling and Managing SSD Write-amplification - https://www.dropbox.com/s/r59p76n5oa7nzhe/1504.00229.pdf?dl=0
Subscribe to:
Posts (Atom)
