Remember Me
forgot your password?

Top 10 Ways People Damage Evidence

Turning on the computer
The biggest no-no. It writes large amounts of data to the hard disk, potentially wiping all traces of a deleted file forever. Data is automatically updated and therefore altered. Turning the computer on affects the swap file and registry as well as the list of most recently used documents. Dates when a file was created, last modified, last accessed and updated can all be unwittingly altered.

Investigating email with email
Investigating emails with an email client carries a host of potential dangers. Going into a suspect’s inbox in Outlook and reading an email which has not been opened before may create a read receipt, leaving a clear trace of the activity. Although often done to try and confirm suspicions, it can be considered tampering with the evidence.

Losing evidence
Failing to either make a forensic image of the hard drives of staff when they leave, or replace the hard drive and store the original, runs the risk of losing important data and therefore being unable to substantiate claims made at a later date.
Creating a copy of a person’s computer as it was when last used is key to preserving data.

DIY data recovery
Unskilled staff attempting to recover data from machines they suspect contain evidence is a big problem. Often, people can’t resist the urge to ‘have a quick look’ when an incident occurs. And although in many cases technical support will be called in, unfortunately, they will generally not have the specialist skills needed to investigate in an evidentially-sound manner. Correctly recovering data is expert work and should only be carried out by suitably qualified professionals.

Following evidential URLs
This is really dangerous territory. Apart from the risk of incriminating yourself — in the case of child abuse images you are essentially committing the same ‘offence’ as the suspect — there is also the possibility of compromising confidential data. You should never click on links in emails, even when they are from a supposedly trusted source.

Preserving digital evidence - Shutting down the PC
Simply, DON’T! Computers like to be very orderly, so when you shut down they will do a lot of ‘housekeeping’ — tidying up files, overwriting deleted information and changing times and dates which are vital to any investigation. If you have to turn the computer off, simply pull the plug. This freezes it and creates a ‘snapshot’ in time which can be forensically examined using a whole range of tools.

Jumping to conclusions
A common mistake when a computer crime is committed is to assume guilt and embark on a witch hunt for the culprit.
But is vital not to jump to conclusions. Just because there is incriminating material on somebody’s computer does not mean they put it there. Somebody else may have hacked their password, or it could have been a Trojan horse or other virus of which they had no knowledge, and therefore no control over.

Ignoring the evidence
Many ‘first responders’ will miss vital evidence by failing to follow correct procedures. Simply pulling the plug on the
computer will wipe the contents of RAM, which may contain useful information, particularly in cases of hacking or server damage. CDs, DVDs, digital cameras and personal organisers on a person’s desk are also often overlooked.

Incorrectly marked tapes
This is the bane of the life of a forensic analyst. It is extremely frustrating when investigating an incident to find that he data on a back-up tape is different from what is stated on the label. It is vital to have a data back-up and retention policy and be consistent in the implementation of it. Everyone involved in security must be aware of what their organisation’s back-up procedures are.

Being careless with evidence
Badly-handled evidence can stop a criminal investigation in its tracks. Evidence should always be carefully secured and then packaged with care. If not, fragile date can be damaged or even lost while stored or being transported. The evidence collection process should always begin with the creation of an incident log, in which the times and dates of any action taken are recorded.

Elizabeth Sheldo

Elizabeth Sheldon is a director of Evidence Talks, One of the most highly regarded computer forensics consultancies in the UK, Evidence Talks lead the way with unique solutions to some of the problems faced by industry today. More information visit- evidencetalks.com

Rate this Article: 0 / 5 stars - 0 vote(s)
Print Email Re-Publish

Add new Comment



Captcha

  • Latest Security Articles
  • More from Elizabeth Sheldo

DSi Download Center: A SCAM?

By: Sarah Brown | 29/12/2009
If you've been looking for DSi games online, you've probably seen something about a site called the DSi Download Center. And you, like me, probably wondered if DSi Download Center is a scam or a legitimate deal ? Not too long ago I was online and doing a Google search for DSi games to download from some place other than the Nintendo store. Through my searches I came across a couple places that talked about the DSi Download Center.

LOCATE YOUR LAPTOP

By: seema bansal | 29/12/2009
Laptop thefts are very common nowadays, spilling a lot of financial burden on not only the laptop owners, but also the insurance companies. With the increase in the laptop thefts, the increase in the piracy has also made the market injected with the curse of increase in the duplication of the products as well as the parts of the laptops. So to avoid all these not only to save your laptop, but also as a social cause, you need to take up something that will stop the laptop theft events.

Examsoon 000-296 practice test

By: Adela1987 | 29/12/2009
Examsoon offers you a comprehensive certification test solution to help you become IBM certified professional. This certification preparation guide comes with free study guide, sample questions and answers, pdf exam, braindumps and answers lab that give you the experience of actual Storage Sales for IBM Certified Solution Designer exam. This preparation kit also contains study notes, 000-296 pdf, 000-296 download, 000-296 practice test and 000-296 review.

Spyware, what is it and how to prevent it

By: Jarvis Edwards | 29/12/2009
This article will describe what spyware is and how to prevent it from appearing on your computer.

Avoiding Malware and Spyware Online

By: Bubba Vine | 27/12/2009
Avoiding malware and spyware online is getting harder, its becoming more and more common and a lot of the time people get infected without even knowing.

Warning Signal For Freeware - Are You Alert For The Pains That May Come Forth

By: Jose Sogiros | 27/12/2009
Computer Software security measures is not uniquely pertaining publishers. As Well, the user must be sensible of troubles that might originate when clicking done with the software permit agreements without properly interpreting them.

Network Security A practical guide

By: freepedia | 26/12/2009
Network Security: a practical guide provides a comprehensive review of network security issues, with relevance to corporate networks, from both an administrative and user perspective.

Pass4side 9L0-509 study questions

By: Adela1987 | 26/12/2009
Pass4side Practice Exams for Apple 9L0-509 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.Pass4side Apple 9L0-509 Preparation Diary is my own preparation guide, there is no guarantee you’ll pass the exam, just by reading the article. Keep the article as starting point, do more research, I put enough reference wherever required, so expand your reading with references mentioned. Good Luck.

Top 10 Ways People Damage Evidence

By: Elizabeth Sheldo | 03/08/2009 | Security
Turning the computer on affects the swap file and registry as well as the list of most recently used documents. Investigating emails with an email client carries a host of potential dangers. Failing to either make a forensic image of the hard drives of staff when they leave, or replace the hard drive.

Showing Your Hand

By: Elizabeth Sheldo | 10/06/2009 | Computer Forensics
Having imaged and analysed the suspects computer disks and found the evidence all that remains is the process of presenting that evidence for use in any criminal, civil or disciplinary hearings.

Protecting The Evidence

By: Elizabeth Sheldo | 10/06/2009 | Computer Forensics
In court cases, computer evidence can be dismissed if even the slightest doubt over it's veracity can be shown, making the process of adducing the evidence correctly vital to the success of otherwise of the case.

Evidentially Sound Advice

By: Elizabeth Sheldo | 10/06/2009 | Computer Forensics
The key role of computer forensics is the protection, adducing and presentation of evidence, in that order. In all abuse cases, protection of the evidence is both critical and central to the organisations ability to investigate and take action against the abuser.

Customize Your Own T-Shirt From Promopays.Ca

By: Elizabeth Sheldo | 10/06/2009 | Customer Service
The screen printed t-shirts available at this company are made using state of the art techniques and break through technologies to deliver the customers promotional t-shirts of their choice.

Submit Your Articles Free: Signup
Article Categories




Use of this web site constitutes acceptance of the Terms Of Use and Privacy Policy | User published content is licensed under a Creative Commons License.
Copyright © 2005-2008 Free Articles by ArticlesBase.com, All rights reserved. (0.48, 1, w3)