Risk sensitive digital evidence collection

被引:30
作者
Kenneally, Erin E.
Brown, Christopher L. T.
机构
[1] Univ Calif San Diego, San Diego Supercomp Ctr, Pacific Inst Comp Secur, La Jolla, CA 92093 USA
[2] Technol Pathways LLC, San Diego, CA 92118 USA
关键词
computer forensics; digital evidence collection; evidence acquisition; digital evidence admissibility;
D O I
10.1016/j.diin.2005.02.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the past decade or so, well-understood procedures and methodologies have evolved within computer forensics digital evidence collection. Correspondingly, many organizations such as the HTCIA (High Technology Criminal Investigators Association) and IACIS (International Association of Computer Investigative Specialists) have emphasized disk imaging procedures which ensure reliability, completeness, accuracy, and verifiability of computer disk evidence. The rapidly increasing and changing volume of data within corporate network information systems and personal computers are driving the need to revisit current evidence collection methodologies. These methodologies must evolve to maintain the balance between electronic environmental pressures and legal standards. This paper posits that the current methodology which focuses on collecting entire bit-stream images of original evidence disk is increasing legal and financial risks.' The first section frames the debate and change drivers for a Risk Sensitive approach to digital evidence collection, which is followed by the current methods of evidence collection along with a cost-benefit analysis. Then the methodology components of the Risk Sensitive approach to collection, and then concludes with a legal and resource risk assessment of this approach. Anticipated legal arguments are explored and countered, as well. The authors suggest an evolved evidence collection methodology which is more responsive to voluminous data cases while balancing the legal requirements for reliability, completeness, accuracy, and verifiability of evidence. (c) 2005 Published by Elsevier Ltd.
引用
收藏
页码:101 / 119
页数:19
相关论文
共 12 条
[1]  
[Anonymous], 2000, American Heritage dictionary of the English language, V4th
[2]  
CARROLL JL, 2004, OBSERVATIONS SEDONA, P4
[3]  
*INTERPOL, 2001, 13 INTERPOL FOR SCI
[4]  
*IOCE, 1 RESP GUID TEMPL
[5]  
*JOINT COUNC INF A, LEIM C
[6]  
Kenneally E. E., 2001, VIRGINIA J LAW TECHN, V6, P13
[7]  
*LEX NEX, 2004, LEX NEX APPL DISC FA
[8]  
MCGOUGH LS, 2002, LAW CONTEMP PROBL, V65, P179
[9]  
*NAT I JUST COMP C, 2002, SEARCH SEIZ COMP OBT
[10]  
*PRINC U, WORDN 2 0