A new triage model conforming to the needs of selective search and seizure of electronic evidence

被引:10
作者
Hong, Ilyoung [1 ,2 ]
Yu, Hyeon [1 ,3 ]
Lee, Sangjin [1 ]
Lee, Kyungho [1 ]
机构
[1] Korea Univ, CIST, Seoul 136713, South Korea
[2] Supreme Prosecutors Off, Seoul, South Korea
[3] Korea Police Invest Acad, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
Digital forensics; Electronic evidence; Search and seizure; Triage; Privacy;
D O I
10.1016/j.diin.2013.01.003
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, digital evidence has been playing an increasingly important role in criminal cases. The seizure of Hard Disk Drives (HDDs) and creation of images of entire disk drives have become a best practice by law enforcement agencies. In most criminal cases, however, the incriminatory information found on an HDD is only a small portion of the entire HDD and the remaining information is not relevant to the case. For this reason, demands for the regulation of excessive search and seizure of defendants' innocuous information have been increasing and gaining strength. Some courts have even ruled out inadmissible digital evidence gathered from sites where the scope of a warrant has been exceeded, considering it to be a violation of due process. In order to protect the privacy of suspects, a standard should be made restricting excessive search and seizure. There are, however, many difficulties in selectively identifying and collecting digital evidence at a crime scene, and it is not realistic to expect law enforcement officers to search and collect completely only case-relevant evidence. Too much restriction can cause severe problems in investigations and may result in law enforcement authorities missing crucial evidence. Therefore, a model needs to be established that can assess and regulate excessive search and seizure of digital evidence in accordance with a reasonable standard that considers practical limitations. Consequently, we propose a new approach that balances two conflicting values: human rights protection versus the achievement of effective investigations. In this new approach, a triage model is derived from an assessment of the limiting factors of on-site search and seizure. For the assessment, a survey that provides information about the level of law enforcement, such as the available labor, equipment supply, technical limitations, and time constraints, was conducted using current field officers. A triage model that can meet the legal system's demand for privacy protection and which supports decision making by field officers that can have legal effects was implemented. Since the demands of each legal system and situation of law enforcement vary from country to country, the triage model should be established individually for each legal system. Along with experiment of our proposed approach, this paper presents a new triage model that is designed to meet the recent requirements of the Korean legal system for privacy protection from, specifically, a Korean perspective. (C) 2013 Elsevier Ltd. All rights reserved.
引用
收藏
页码:175 / 192
页数:18
相关论文
共 22 条
[1]   Requiring protocols in computer search warrants [J].
Brenner, SW .
DIGITAL INVESTIGATION, 2005, 2 (03) :180-188
[2]  
Gary Cantrell, 2012, COMPUTER INFORM SCI, V5, P29
[3]   An automated timeline reconstruction approach for digital forensic investigations [J].
Hargreaves, Christopher ;
Patterson, Jonathan .
DIGITAL INVESTIGATION, 2012, 9 :S69-S79
[4]  
Jackson Jacob T, 2003, INT J DIGITAL EVIDEN, V4
[5]  
James Migletz, 2008, THESIS NAVAL POSTGRA
[6]   Risk sensitive digital evidence collection [J].
Kenneally, Erin E. ;
Brown, Christopher L. T. .
DIGITAL INVESTIGATION, 2005, 2 (02) :101-119
[7]  
Kerr Orin S, 2006, HARVARD LAW REV, V119
[8]  
Mark R., 2002, International Journal of Digital Evidence, V1
[9]   The growing need for on-scene triage of mobile devices [J].
Mislan, Richard P. ;
Casey, Eoghan ;
Kessler, Gary C. .
DIGITAL INVESTIGATION, 2010, 6 (3-4) :112-124
[10]  
Pajek P, 2009, COMM COM INF SC, V45, P145