Digital Forensics Research is Investigator- Centric Robert J. - - PowerPoint PPT Presentation

digital forensics
SMART_READER_LITE
LIVE PREVIEW

Digital Forensics Research is Investigator- Centric Robert J. - - PowerPoint PPT Presentation

Effective Digital Forensics Research is Investigator- Centric Robert J. Walls Brian Neil Levine Marc Liberatore Clay Shields University of Massachusetts Amherst Georgetown University rjwalls@cs.umass.edu 1 forensics.umass.edu


slide-1
SLIDE 1 rjwalls@cs.umass.edu forensics.umass.edu 1

Effective

Digital Forensics

Research is

Investigator- Centric

Robert J. Walls Brian Neil Levine Marc Liberatore Clay Shields University of Massachusetts Amherst Georgetown University

slide-2
SLIDE 2 rjwalls@cs.umass.edu forensics.umass.edu 2
slide-3
SLIDE 3 rjwalls@cs.umass.edu forensics.umass.edu 2
slide-4
SLIDE 4 rjwalls@cs.umass.edu forensics.umass.edu 3
slide-5
SLIDE 5 rjwalls@cs.umass.edu forensics.umass.edu 3
slide-6
SLIDE 6 rjwalls@cs.umass.edu forensics.umass.edu 4

Digital forensics contends with

the CSI-effect.

slide-7
SLIDE 7 rjwalls@cs.umass.edu forensics.umass.edu 4

Digital forensics contends with

the CSI-effect.

and security

^

slide-8
SLIDE 8 rjwalls@cs.umass.edu forensics.umass.edu 5

Digital forensics lacks a solid

scientific foundation.

slide-9
SLIDE 9 rjwalls@cs.umass.edu forensics.umass.edu 6

Digital forensics struggles with

practical challenges.

slide-10
SLIDE 10 rjwalls@cs.umass.edu forensics.umass.edu 7

Digital forensics impacts

people directly.

slide-11
SLIDE 11 rjwalls@cs.umass.edu forensics.umass.edu 8
slide-12
SLIDE 12 rjwalls@cs.umass.edu forensics.umass.edu 9

Security, privacy,

& forensics?

slide-13
SLIDE 13 rjwalls@cs.umass.edu forensics.umass.edu 10
slide-14
SLIDE 14 rjwalls@cs.umass.edu forensics.umass.edu 11

principles for

researchers.

5

slide-15
SLIDE 15 rjwalls@cs.umass.edu forensics.umass.edu 12
slide-16
SLIDE 16 rjwalls@cs.umass.edu forensics.umass.edu 13
slide-17
SLIDE 17 rjwalls@cs.umass.edu forensics.umass.edu 14

Investigator-Centric

Digital Forensics is

1

slide-18
SLIDE 18 rjwalls@cs.umass.edu forensics.umass.edu 15

1: Forensics is Investigator-Centric

> Research is investigator driven.

slide-19
SLIDE 19 rjwalls@cs.umass.edu forensics.umass.edu 15

1: Forensics is Investigator-Centric

> Consider both goals and constraints. > Research is investigator driven.

slide-20
SLIDE 20 rjwalls@cs.umass.edu forensics.umass.edu 15

1: Forensics is Investigator-Centric

> Consider both goals and constraints. > Research is investigator driven. > Break the rules lose the case.

slide-21
SLIDE 21 rjwalls@cs.umass.edu forensics.umass.edu 15

1: Forensics is Investigator-Centric

> Consider both goals and constraints. > Research is investigator driven. > Break the rules lose the case. > The rules change.

slide-22
SLIDE 22 rjwalls@cs.umass.edu forensics.umass.edu 16

inseparable

Forensics and law are

2

slide-23
SLIDE 23 rjwalls@cs.umass.edu forensics.umass.edu 17

2: Forensics and law are inseparable

> Law is struggling to keep up.

slide-24
SLIDE 24 rjwalls@cs.umass.edu forensics.umass.edu 17

2: Forensics and law are inseparable

> How does seizure apply to data? > Law is struggling to keep up.

slide-25
SLIDE 25 rjwalls@cs.umass.edu forensics.umass.edu 17

2: Forensics and law are inseparable

> How does seizure apply to data? > Law is struggling to keep up. > Unproven techniques are risky.

slide-26
SLIDE 26 rjwalls@cs.umass.edu forensics.umass.edu 18

People

Investigations are about

3

slide-27
SLIDE 27 rjwalls@cs.umass.edu forensics.umass.edu 19

3: Investigations are about people

> Focus on the person, not the machine.

slide-28
SLIDE 28 rjwalls@cs.umass.edu forensics.umass.edu 19

3: Investigations are about people

> Intent is outside of security domain. > Focus on the person, not the machine.

slide-29
SLIDE 29 rjwalls@cs.umass.edu forensics.umass.edu 19

3: Investigations are about people

> Intent is outside of security domain. > Focus on the person, not the machine. > Crime may not violate security.

slide-30
SLIDE 30 rjwalls@cs.umass.edu forensics.umass.edu 20

4

Dumb Ones

Still useful to catch the

slide-31
SLIDE 31 rjwalls@cs.umass.edu forensics.umass.edu 21

4: Still useful to catch the dumb ones

> Doesn’t have to be foolproof to be useful.

slide-32
SLIDE 32 rjwalls@cs.umass.edu forensics.umass.edu 21

4: Still useful to catch the dumb ones

> Tech savvy criminals aren’t more dangerous. > Doesn’t have to be foolproof to be useful.

slide-33
SLIDE 33 rjwalls@cs.umass.edu forensics.umass.edu 21

4: Still useful to catch the dumb ones

> Tech savvy criminals aren’t more dangerous. > Doesn’t have to be foolproof to be useful. > 40% is still good.

slide-34
SLIDE 34 rjwalls@cs.umass.edu forensics.umass.edu 22

5 Simple

Keep it

slide-35
SLIDE 35 rjwalls@cs.umass.edu forensics.umass.edu 23

5: Keep it simple

> Make it simple for investigators to use it.

slide-36
SLIDE 36 rjwalls@cs.umass.edu forensics.umass.edu 23

5: Keep it simple

> Must be within Investigator capabilities. > Make it simple for investigators to use it.

slide-37
SLIDE 37 rjwalls@cs.umass.edu forensics.umass.edu 23

5: Keep it simple

> Must be within Investigator capabilities. > Make it simple for investigators to use it. > Often simpler non-computer solutions.

slide-38
SLIDE 38 rjwalls@cs.umass.edu forensics.umass.edu 24

Forensics research without

these principles is

not forensics.

slide-39
SLIDE 39 rjwalls@cs.umass.edu forensics.umass.edu 25

1: Forensics is Investigator-Centric. 2: Forensics and law are inseparable. 3: Investigations are about people. 4: Still useful to catch the dumb ones. 5: Keep it simple.

This work was supported in part by NSF awards CNS-1018615, CNS-0905349, and DUE-0830876, and in part by NIJ award 2008-CE-CX- K005.