CSE 469: Computer and Network Forensics
CSE 469: Computer and Network Forensics
- Dr. Mike Mabey | Spring 2019
CSE 469: Computer and Network Forensics Topic 2: Evidence - - PowerPoint PPT Presentation
CSE 469: Computer and Network Forensics Topic 2: Evidence Acquisition Dr. Mike Mabey | Spring 2019 CSE 469: Computer and Network Forensics Acquisition First step in the forensic process: Copy the evidence/data without altering or
CSE 469: Computer and Network Forensics
CSE 469: Computer and Network Forensics
2
CSE 469: Computer and Network Forensics
3
CSE 469: Computer and Network Forensics
4
CSE 469: Computer and Network Forensics
5
CSE 469: Computer and Network Forensics
Called a “collision”
6
CSE 469: Computer and Network Forensics
(no size limit)
Message Digest 128-bit/160-bit
7
CSE 469: Computer and Network Forensics
8
CSE 469: Computer and Network Forensics
Relatively Small Output Space
9
CSE 469: Computer and Network Forensics
10
Relatively Small Output Space
CSE 469: Computer and Network Forensics
See https://en.wikipedia.org/wiki/Message_digest
11
CSE 469: Computer and Network Forensics
12
CSE 469: Computer and Network Forensics
13
CSE 469: Computer and Network Forensics
14
CSE 469: Computer and Network Forensics
15
NOTE: A logical or sparse acquisition may be more appropriate if time is limited
accessible, such as in web or cloud forensic cases.
CSE 469: Computer and Network Forensics
16
CSE 469: Computer and Network Forensics
010110010110111101110 101011010000110000101 110110011001010111010 001101111011011110110 110101110101011000110 110100001110100011010 010110110101100101011 011110110111001111001 011011110111010101110 010011010000110000101 101110011001000111001 100100001
17
CSE 469: Computer and Network Forensics
18
CSE 469: Computer and Network Forensics
19
010110010110111101110 101011010000110000101 110110011001010111010 001101111011011110110 110101110101011000110 110100001110100011010 010110110101100101011 011110110111001111001 011011110111010101110 010011010000110000101 101110011001000111001 100100001
CSE 469: Computer and Network Forensics
20
CSE 469: Computer and Network Forensics
21
CSE 469: Computer and Network Forensics
22
CSE 469: Computer and Network Forensics
23
CSE 469: Computer and Network Forensics
24
CSE 469: Computer and Network Forensics
25
CSE 469: Computer and Network Forensics
26