The Field Of Computer Forensics

By Shirley Hayes


Computers are being adopted at a very high rate in government, corporate, and personal processes worldwide, something that is leading to a new form of crime called cybercrime. For a crime to qualify as cybercrime, it must have been facilitated by the use of a computing device. To counter cybercrime, a new field of study called computer forensics has been formulated. This field is growing at a fast rate worldwide as cases of cybercrime continue to grow.

Computer forensic science is the other name that is used to refer to this field. This science makes one of several other subfields that comprised in digital forensic science. In Albemarle, NC, there are several professionals whose area of expertise is CF. CF is a separate field of study that specializes in the analysis, reporting, and collection of data stored on digital media. The entire profession revolves around computers and digital storage media. Experts prevent and detect criminal activities by using data kept on digital media.

Computer forensic science continues to find more use in new professions. Almost every profession finds CF useful in one way or another. Law enforcement agencies are some examples of bodies that pioneered this field. These agencies make heavy use of this field in various operations. They also stand at the forefront in the major breakthroughs that have been made in CF.

The actions of law enforcement officers and criminals are increasingly making computers active crime scenes. Computers are made active crime scenes when cyber-attacks are directed at them. Criminal investigations also find computers to be useful sources of information. Information such as emails, browsing history, and documents can be used to solve criminal cases like a kidnapping.

The scope of CF exceeds finding documents, files, and emails on computing devices. It involves the examination of metadata on documents to reveal more information about them, which could prove to be useful in solving a crime. For example, through the use of metadata, it is possible to identify the first date a document appeared or was created on computers. It is also possible to determine the last date the document was printed, edited, and saved beside identifying the user of who undertook all these operations.

Commercial organizations have in the recent past used CF in a number of cases to their own benefit. Some of the areas in which this science has been used by commercial organizations include intellectual property theft, industrial espionage, employment disputes, fraud investigations, and forgeries. Additional cases include bankruptcy investigations, regulatory compliance, and internet use and inappropriate emails in workplaces.

Investigation in this field employs several different techniques. These techniques include cross-drive analysis, stochastic forensics, steganography, live analysis, and deleted files. The correlation of information gathered from multiple hard drives is done under cross-drive analysis.

CF examination is a single process that is comprised of six separate steps. These steps include readiness, presentation, review, collection, evaluation, and analysis. The list above is not in a chronological order. Although very crucial, the readiness step is often overlooked. Legal, administrative, and technical are the three broad categories of issues that prevail in this field.




About the Author:



ليست هناك تعليقات: