Advances in Forensic Data Acquisition

Abstract

You all know this from watching CSI: When a crime is committed, usually some form of digital evidence is left on devices such as computers, mobile phones, or the navigation system of a car a suspect has used. Indeed, law enforcement agencies are regularly interested in data from personal devices to find evidence, guide investigations, or even act as proof in a court of law. This tutorial article by Felix Freiling et al. mentions the San Bernadino case as a prominent example. But how do police investigators go about accessing this evidence? Is what is shown on TV realistic? Whereas, in times of classical hard disks, accessing data was quite easy due to the non- volatility of the memory device. However, this is getting increasingly difficult because of developing technologies like SSDs, other forms of flash storage, and, in particular, for volatile memory such as RAM, with the major problem being to read out data while guarding “authenticity.” In the past ten years, there has been some substantial development in the area of forensic data acquisition, which is summarized by the article. It gives clear indications of what currently can be technically done and what cannot be done by police investigators. So, if you watch CSI again and the cops need to access some digital evidence, you can tell truth from fiction. —Jürgen Teich, Friedrich-Alexander-Universität Erlangen-Nürnberg

Mehr zum Titel

Titel Advances in Forensic Data Acquisition
Medien IEEE Design & Test
Verlag IEEE
Heft 5
Band 35
Verfasser Felix Freiling, Tobias Groß, Tobias Latzo, Prof. Dr. Tilo Müller, Ralph Palutke
Seiten S. 63-74
Veröffentlichungsdatum 01.08.2018
Zitation Freiling, Felix; Groß, Tobias; Latzo, Tobias; Müller, Tilo; Palutke, Ralph (2018): Advances in Forensic Data Acquisition. IEEE Design & Test 35 (5), S. 63-74.