0% found this document useful (0 votes)
65 views

Digital Forensics: The Branches: Joe Abraham

Digital forensics has five main branches: network forensics, computer forensics, mobile forensics, database forensics, and forensic data analysis. Each branch analyzes specific types of digital evidence like network traffic, files on computers and mobile devices, and database transaction logs. Key aspects of digital forensics include logging information, preserving evidence, analyzing patterns in the data, creating forensic images of evidence, and "painting the picture" to understand what happened. Large amounts of structured and unstructured data are created every day that require different forensic analysis techniques.

Uploaded by

EDu Jose
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
65 views

Digital Forensics: The Branches: Joe Abraham

Digital forensics has five main branches: network forensics, computer forensics, mobile forensics, database forensics, and forensic data analysis. Each branch analyzes specific types of digital evidence like network traffic, files on computers and mobile devices, and database transaction logs. Key aspects of digital forensics include logging information, preserving evidence, analyzing patterns in the data, creating forensic images of evidence, and "painting the picture" to understand what happened. Large amounts of structured and unstructured data are created every day that require different forensic analysis techniques.

Uploaded by

EDu Jose
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 35

Digital Forensics: The Branches

Joe Abraham
IT SECURITY PROFESSIONAL

@joeabrah www.joestechinsights.com
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions
Digital Evidence
Overview
The Five Branches
- Network Forensics
- Computer Forensics
- Mobile Forensics
- Database Forensics
- Forensic Data Analysis
Network Forensics
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions

Network
Digital Evidence
Digital evidence includes information on computers,
audio files, video recordings, and digital images.
-Nist.gov
Examples of Digital Evidence in the Network

Captured network Network device logs Email


traffic

Files Web traffic Any other traffic


“transmitted”
What Is Network Forensics Used For?

Analyze attack methods and Discover and understand


their durations attack vectors

Verify regulatory and Troubleshoot network


organizational policy performance and optimize
compliance services
Logging Within a Network
Network Visibility
Network Devices
Collector
Log
Information

SIEM
IDS/IPS

Identity Services
“I think you can have a ridiculously
enormous and complex data set, but if
you have the right tools and
methodology then it’s not a problem.”
Aaron Koblin
Computer Forensics
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions

Network Computer
Examples of Digital Evidence in Computers

Logs, registry, Documents, The operating Hard drive data


application pictures, videos, system or the and RAM data
data, and web and other files entire computer
history
Analyzing attacks
Verifying compliance
Troubleshooting
What Is Computer
Who, what, where,
when, why? Forensics Used For?
Develop remediation
How?
Painting the Picture

Use commercial and open-source


applications
Be thorough and put the facts together
Handle the evidence properly
Prove what happened
- Make it readable
- Make it understandable
- Eliminate doubt
Mobile Forensics
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions

Network Computer Mobile


Examples of Digital Evidence in Mobile Devices

Phonebook and call information

Messaging application data and SMS messages

Location data

Application data
Sample Use Cases for Mobile Forensics

Analyzing attacks via mobile Tracking movement of


devices suspects

Using call and message


Supplementing evidence from
records to prove wrongful
acts other branches
Prevention of data manipulation
Remote wipe
Data/evidence - Only needs power and connectivity

Preservation Helps ensure availability and integrity


Necessary in all branches of digital
forensics
Database Forensics
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions

Network Computer Mobile Database


Examples of Digital Evidence in Databases

Security/access logs Transaction logs

Files System logs


Pattern Analysis

One file or many?


Specific files?
Specific order?
Find the pattern to figure out why
Help paint the picture
Version Control
In computing, the management and maintenance of a
software system running different versions of various
programs.
–Dictionary.com
Forensic Data Analysis
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions

Data
Network Computer Mobile Database Analysis
Structured Data
Structured data is a standardized format for providing
information.
-Google Developers
Unstructured Data
Non-traditional data or data format; data that may not
fit into a structured database.
Pattern Analysis

Structured Data Unstructured Data


Queries, easier to accomplish, Scripts and software, more
can pinpoint key words and difficult to properly analyze,
phrases business intelligence and big
data
Make at least one
forensic image
Investigator works on
this image
Prevents Creating a Forensic Image
compromising of
evidence
Regulatory and legal
considerations
What is digital evidence?
Five branches of digital forensics
Summary
The importance of each branch
Key aspects surrounding digital forensics
- Logging
- Evidence preservation
- Painting the picture
- Data backups
- Forensic imaging
Forensic Science

Forensic Science

Other
Forensic Digital Forensics
Subdivisions

Data
Network Computer Mobile Database Analysis
How Much Data Is Created Every Day?

*April 5, 2017, Ben Walker, vouchercloud

2,500,000,000 GB

Average Number of Connected Devices

*Per U.S. Household, Pew Research Center, 2016

5
“We keep moving forward, opening
new doors, and doing new things,
because we’re curious and curiosity
keeps leading us down new paths.”
Walt Disney

You might also like