Preview

Forensics

Powerful Essays
Open Document
Open Document
3335 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Forensics
How Computer Forensics Works by Jonathan Strickland

Computer Image Gallery

Paul Howell/Getty Images Imagine how many files were retrieved from these computers on Enron 's trading floor. See more computer pictures.
When the company Enron declared bankruptcy in December 2001, hundreds of employees were left jobless while some executives seemed to benefit from the company 's collapse. The United States Congress decided to investigate after hearing allegations of corporate misconduct. Much of Congress ' investigation relied on computer files as evidence. A specialized detective force began to search through hundreds of Enron employee computers using computer forensics.
The purpose of computer forensics techniques is to search, preserve and analyze information on computer systems to find potential evidence for a trial. Many of the techniques detectives use in crime scene investigations have digital counterparts, but there are also some unique aspects to computer investigations.
For example, just opening a computer file changes the file -- the computer records the time and date it was accessed on the file itself. If detectives seize a computer and then start opening files, there 's no way to tell for sure that they didn 't change anything. Lawyers can contest the validity of the evidence when the case goes to court.
Some people say that using digital information as evidence is a bad idea. If it 's easy to change computer data, how can it be used as reliable evidence? Many countries allow computer evidence in trials, but that could change if digital evidence proves untrustworthy in future cases.
­Computers are getting more powerful, so the field of computer forensics must constantly evolve. In the early days of computers, it was possible for a single detective to sort through files because storage capacity was so low. Today, with hard drives capable of holding gigabytes and even terabytes of data, that 's a daunting task. Detectives must discover new ways to



Links: Fitzgerald, Thomas J. "Deleted But Not Gone." The New York Times. November 3, 2005. http://www.nytimes.com/2005/11/03/technology/circuits/03basics.htmlex=1288674000&en=52520fd64c31403f&ei=5090&partner=rssuserland&emc=rss Kerr, Orin S Harris, Ryan. "Arriving at an anti-forensics consensus." Digital Investigation. 2006. http://dfrws.org/2006/proceedings/6-Harris.pdf "How the FBI Investigates Computer Crime." CERT Witter, Franklin. "Legal Aspects of Collecting and Preserving Computer Forensic Evidence." Global Information Assurance Certification. April 20, 2001. http://www.giac.org/certified_professionals/practicals/gsec/0636.php

You May Also Find These Documents Helpful

  • Powerful Essays

    272. Newman, R. (2007). Computer Forensics: Evidence Collection and Managment. Boca Raton FL: Taylor & Francis Group. LLC.…

    • 4846 Words
    • 17 Pages
    Powerful Essays
  • Satisfactory Essays

    MGS 351 FINAL TIPS

    • 313 Words
    • 2 Pages

    digital forensics: acquire the evidence without changing) authenticate your recovered evidence is the same as original…

    • 313 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Some kinds of evidence rely on honesty and trust. Direct evidence and testimonies both require help of people in the case you are in. Those people can twist the story, make the situation seem better for them, or sometimes they completely lie without a speck of truth. Forensic evidence doesn’t have to rely on truth. The evidence you gain from it has no argument. If you ask them if they committed the crime, they could lie and tell you no.…

    • 276 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Assignment5

    • 285 Words
    • 1 Page

    The three phases of computer forensic investigations are; acquire the evidence, authenticate the evidence, and analyze the evidence. In acquiring the evidence the data is collected. Authenticating the evidence a chain of custody is used for the evidence to ensure its trustworthiness. Finally in analyzing the evidence the data is viewed and if need be a copy of the evidence can be created.…

    • 285 Words
    • 1 Page
    Satisfactory Essays
  • Satisfactory Essays

    Many times, computer forensics practitioners work with traditional forensics experts in criminal investigations to reveal evidence. With frequent work experiences with forensics experts and lawyers, having a general knowledge of relevant laws and ethics is a nice complement to any computer forensics practitioner’s skill set. Furthermore, as many audits are conducted on businesses and illegal organizations are done electronically, computer forensics experts may want to have working knowledge in accounting and/or finance in order to prepare for such jobs.…

    • 524 Words
    • 3 Pages
    Satisfactory Essays
  • Satisfactory Essays

    Lab 1

    • 414 Words
    • 2 Pages

    2. Which items within WinAudit’s initial report would you consider to be of critical importance in a computer forensic investigation?…

    • 414 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    When investigator Peter L. Lockhart Jr., follows the basic steps in a cybercrime investigation, the evidence will be admissible in a court of law. Obtaining the evidence…

    • 664 Words
    • 3 Pages
    Good Essays
  • Satisfactory Essays

    Forensic Science 1.06

    • 658 Words
    • 2 Pages

    Forensic science, is the application of science to the criminal justice system. Forensic science is any science that is used for the purposes of the criminal justice system. Forensic scientists use forensics to help determine who committed a crime. For example, forensic scientists are able to compare fingerprints from a crime scene with databases of fingerprints in order to find who was at the scene of a crime.…

    • 658 Words
    • 2 Pages
    Satisfactory Essays
  • Good Essays

    Csi Essay Example

    • 3977 Words
    • 16 Pages

    When prosecutors present evidence to a court, they must be ready to show that the thing they offer is the same thing the police officers, crime scene investigators, and agents seized. When that evidence is not distinctive but fungible (whether little bags of cocaine, bullet shell casings, or electronic data), the "process or system" which authenticates the item is a hand-to-hand chain of accountability.…

    • 3977 Words
    • 16 Pages
    Good Essays
  • Better Essays

    CCJS321 Project 1

    • 1347 Words
    • 4 Pages

    K-Mart Corp. v. Trotti, 677 S.W.2d 632 (Court of Appeals of Texas, Houston First District 1984).…

    • 1347 Words
    • 4 Pages
    Better Essays
  • Satisfactory Essays

    After the preservation phase, forensics are required to locate and identify any evidence that can be used to aid the crime case. There are several locations where evidence are usually found such as in the hard drive on the user’s personal computer, laptop, smart phone or tablet (ACPO, 2012). It is also critical that forensics are aware of the intention of the particular investigation. This aids in the forensics' efforts of locating digital evidences that are relevant to the case. For example, in the case of a server intrusion, forensics should look out for signs such as a rootkit installation, analyze configuration files, logs files and etc. These are possible locations and processes where traces of evidence can be picked out from (Carrier and Spafford, 2003).…

    • 257 Words
    • 2 Pages
    Satisfactory Essays
  • Better Essays

    Respect, observant, self-deprecating, judgments and honesty. These are the words that come to mind when reflecting back on the novel The Great Gatsby. The narrator, Nick, is a quiet, reflective 30 year old man who moves to New York to learn about the bonding business. Now, it is probably easy to think of many differences between myself, a 17 year old girl living in the 21st century, and Nick a 30 year old man alive during the 1920’s but perhaps the similarities aren't quite as clear. Well if you look below the surface it is found that there are many traits that Nick and I share. The American Dream is defined as how a person would achieve the perfect life. I believe that Nick and I share the same ideas of attaining this “perfect life”. By becoming successful, focusing on individualism, and holding genuine happiness. Although Nick and I may…

    • 1514 Words
    • 7 Pages
    Better Essays
  • Good Essays

    Forensic evidence is a type or forensic science, which is a science applied to answering legal questions. This evidence can draw together knowledge from a single field, or it could be a combination of fields. Whatever the field may be, the evidence is applied and used to help reconstruct a crime case. There is also a branch called Criminalistics, which deals with the examination…

    • 226 Words
    • 1 Page
    Good Essays
  • Satisfactory Essays

    forensic

    • 266 Words
    • 1 Page

    Information technology knowledge and skills are necessary tools of the forensic accountant in a world filled which paperless crimes. At minimum, forensic accountants must know the point at which they should contact an expert in computer hardware or software. Examples of ways that forensic accountants use information technology skills to quarantine data, extract data through data mining, design and implement controls over data manipulation, accumulate baseline information for comparison purpose, and analyze data.…

    • 266 Words
    • 1 Page
    Satisfactory Essays
  • Satisfactory Essays

    Forensic Science is the examination of criminal evidence for the criminal justice system in order to successfully prosecute a criminal.…

    • 479 Words
    • 2 Pages
    Satisfactory Essays

Related Topics