Simple clear advice in plain English

Computer forensics

PCs are increasingly becoming a vital source of clues for solving today’s high-tech crimes

Assuming acquisition goes smoothly, the next stage of forensic examination is identification.

This is largely about placing facts into context. For example, at a physical level, a note is made of how many hard disks are present in the computer and which was configured as the boot disk.

At the logical level, the partitioning arrangement on the disks and the file systems on them can perhaps reveal the level of knowledge possessed by the computer’s owner.

Identifying the file system is also important in interpreting the layout of the disk and the behaviour of files as they are created, moved and deleted.

The evaluation stage of the process is concerned with locating and evaluating evidence. Here, the strategy used by the forensic analyst will depend on a number of factors, including the alleged crime, the number of exhibits and whether the suspect is in custody, on bail or not yet arrested.

For a forensic computer analyst undertaking work for a criminal prosecution, the presentation stage of the work is ultimately destined for an audience of lay people in a court of law. Much of the data found on a computer is stored in a raw format, and interpreting the information will usually be beyond the technical knowledge and experience of the jury and other people in court.

A key task for the analyst, then, is to interpret the data and present it without opinion, using only facts and probabilities to add weight to any significant evidence. A forensic scientist must be prepared to be questioned and defend their findings in court, in addition to explaining them clearly.

Inside the criminal mind
To prove a person’s guilt under UK law, many offences require evidence to show that they both committed the act of which they are accused and intended to do so. In legal terminology, this distinction is known by the Latin terms actus reus meaning a guilty act and mens rea, a guilty mind. These are terms you may have come across if you’ve done jury service. Computer forensics can help prove both.

For example, imagine that a business has recently been hacked and the police have identified a suspect from the IP addresses in the firewall logs, tracing the IP address back, via the ISP, to a particular person.

Now, suppose confidential company files are found during an examination of the suspect’s computer. This provides evidence of actus reus. By investigating the suspect’s internet history on the computer, a forensic analyst discovers a number of Google searches that were carried out just prior to the offence, using the search phrase ‘hacking firewalls’.

The analysis also shows that the user went through a further four pages of results from Google, before visiting the site http://insecure.org and downloading the file nmap-4.11.setup.exe. This website and tool are network security related, so the activity is indicative of their thinking process, or mens rea.

Reader Comments

   

Add your comment

All fields must be completed. Your email address will not be displayed or used to send marketing messages.

All messages will be checked by moderators before appearing on the site.

See our Privacy Policy for more information.

Related articles

Security shield illustration

How to use the Command Prompt

Lurking under Windows is the little-known world of the command line. We explain how to use this to fix faults and make your PC much more secure

Move copy or delete files with Dropit step illustration

Take the repetition out of housekeeping chores on a hard disk

Free software makes it easier to copy, move and delete files by automating the task. We show you how to set up the program and make life simpler for yourself

Using Docshield to restore file revisions illustration

Save multiple versions of a document as you work on it

Save revisions of a file at different stages in its life with free software Docshield

Question & Answer

Q.Why are some of the keys on my keyboard doing strange...

> Read the answer

Q.Is my phone’s Bluetooth any use?

> Read the answer

Q.Can I switch boot drives so that I can work on older...

> Read the answer

Best deals on the web

img

Samsung RV520-A07

£359.98- Buy it now

img

Acer Aspire 5750G (LX.RXP02.019)

£399.99- Buy it now

img

Apple MacBook Pro (MD313B/A)

£904.37- Buy it now

Latest issue & subscription deals

Poll

Are you concerned about viruses that target mobile phones?

Jargon Buster

Computing terms explained in plain English

Virtual drive

A set of files seen by Windows as a separate hard disk.

Great shopping deals from Computeractive