FORZA - Digital forensics investigation framework that incorporate legal issues

FORZA - Digital forensics investigation framework that incorporate legal issues
复制标题

DOI:
10.1016/j.diin.2006.06.004
复制
发表时间:
2006-09-01
影响因子:
--
通讯作者:
Leong, Ricci S. C.
Leong, Ricci S. C.
中科院分区:
工程技术4区
文献类型:
--
作者:
Leong, Ricci S. C.

文献摘要

被引文献

相似文献

什么是数字取证?Mark Pollitt在DFRWS 2004中强调[Politt MM. Six blind men from Indostan.数字取证研究研讨会(DFRWS); 2004]数字取证不是大象,它是一个过程,而不仅仅是一个过程,而是一组调查任务和过程。事实上,许多数字取证调查过程和任务都是根据技术实现细节定义的,传统取证科学家开发的调查程序侧重于处理证据的程序,而技术专家开发的调查程序则侧重于捕获证据的技术细节。因此,许多数字取证从业人员只是简单地遵循技术程序,而忘记了数字取证调查的实际目的和核心概念。由于所有这些技术细节和复杂的程序,法律的从业人员可能难以应用甚至理解他们在数字取证调查中的流程和任务。为了打破信息技术人员、法律的从业人员和调查人员之间的技术障碍,在本文中,我们首先强调了数字取证调查的基本原则(侦察,可靠性和相关性)。基于这一原则,我们重新审视了数字取证调查的任务,概括了数字取证调查中的8个不同角色及其职责,并为每个角色定义了6个关键问题集。它们是什么(数据属性),为什么(动机),如何(程序),谁(人),哪里(位置)和何时(时间)问题。事实上,在所有的调查过程中,有六个主要的问题是每个从业者经常会问的,通过将这六个问题集纳入Zachman的框架中,组成了一个数字取证调查框架-FORZA。我们将进一步解释这个新框架如何将法律的顾问和检察官纳入数字取证调查框架的更大范围。这个框架的可用性将在一个网络黑客的例子中说明。最后,将简要描述将框架与自动零知识数据采集工具互连的路线图。(c)2006年DFRWS。由爱思唯尔有限公司出版。保留所有权利。
What is Digital Forensics? Mark Pollitt highlighted in DFRWS 2004 [Politt MM. Six blind men from Indostan. Digital forensics research workshop (DFRWS); 2004] that digital forensics is not an elephant, it is a process and not just one process, but a group of tasks and processes in investigation. In fact, many digital forensics investigation processes and tasks were defined on technical implementation details Investigation procedures developed by traditional forensics scientist focused on the procedures in handling the evidence, while those developed by the technologist focused on the technical details in capturing evidence. As a result, many digital forensics practitioners simply followed technical procedures and forget about the actual purpose and core concept of digital forensics investigation.With all these technical details and complicated procedures, legal practitioners may have difficulties in applying or even understanding their processes and tasks in digital forensics investigations.In order to break the technical barrier between information technologists, legal practitioners and investigators, and their corresponding tasks together, a technical-independent framework would be required.In this paper, we first highlighted the fundamental principle of digital forensics investigations (Reconnaissance, Reliability and Relevancy). Based on this principle, we re-visit the investigation tasks and outlined eight different roles and their responsibilities in a digital forensics investigation.For each role, we defined the sets of six key questions. They are the What (the data attributes), Why (the motivation), How (the procedures), Who (the people), Where (the location) and When (the time) questions. In fact, among all the investigation processes, there are six main questions that each practitioner would always ask.By incorporating these sets of six questions into the Zachman's framework, a digital forensics investigation framework - FORZA is composed. We will further explain how this new framework can incorporate legal advisors and prosecutors into a bigger picture of digital forensics investigation framework.Usability of this framework will be illustrated in a web hacking example. Finally, the road map that interconnects the framework to automatically zero-knowledge data acquisition tools will be briefly described. (c) 2006 DFRWS. Published by Elsevier Ltd. All rights reserved.