Nalazite se na CroRIS probnoj okolini. Ovdje evidentirani podaci neće biti pohranjeni u Informacijskom sustavu znanosti RH. Ako je ovo greška, CroRIS produkcijskoj okolini moguće je pristupi putem poveznice www.croris.hr
izvor podataka: crosbi !

Search and seizure data in cyber space : mechanism to preserve and reproduce data in non-volatile format (CROSBI ID 596023)

Prilog sa skupa u zborniku | izvorni znanstveni rad | međunarodna recenzija

Škrtić, Dražen ; Kralj, Damir ; Švegar, Mirna Search and seizure data in cyber space : mechanism to preserve and reproduce data in non-volatile format // Contemporary Criminal Justice Practice and Research: conference proceeding (proceedings of the Biennial International Conference Criminal Justice - Contemporary Criminal Justice and Research / Meško, Gorazd ; Sotlar, Andrej and Jack R. Greene (ur.). Ljubljana: Faculty of Criminal Justice and Security, 2013. str. 509-521

Podaci o odgovornosti

Škrtić, Dražen ; Kralj, Damir ; Švegar, Mirna

engleski

Search and seizure data in cyber space : mechanism to preserve and reproduce data in non-volatile format

The purpose of the article is to present the origins, developments and trends in criminal investigation science /criminalistics in order to preserve digital evidence obtained by search and seizure data in cases of the remote computer, cyberspace and cloud search. The article is based on a review and analysis of professional literature on criminal investigation, published in books and periodicals. Electronic data held on computer hard disks and other rewritable physical digital media can be considered as very volatile form of evidence. This evidence can be easily altered or destroyed if left unprotected or without proper handling. As in the case of traditional evidence, the proponent of evidence normally carries the burden of offering sufficient support to authenticate electronic evidence. Therefore, a mechanism to preserve or reproduce the data in a non-volatile format is required. Physical acquisition (disk imaging) allows an entire hard disk drive to be reproduced or analyzed without the need to access the original hard disk. This process provides safe mechanism to analyze, test and interact with data, while still providing the most accurate reproduction of the original. In this case the data copied can be said to be an exact duplication of the original, a more exact duplication than, for example, a photocopy of a page, as disk image allows you to recover deleted and ambient data. In cases where data were obtained by searching in cyberspace, e.g. remote searching and browsing in the cloud, it is necessary to ensure the authenticity of the information searched and seized. Computer forensic examiners frequently use a number of methods to ensure the validity of the data copied including creating a digital signature (called a mathematical hash) of the data as it is read from the hard disk drive or similar physical media, so that the signature can be compared to the copied data. The mathematical hashing algorithm allows the examiner to detect if data have been altered or an error has occurred during the copy process. A number of commercial forensic acquisition products even embed the mathematical hash into the electronic container that holds the forensic image. The authors give an overview of standard procedures of ensuring the authenticity of digital evidence by using a specific write-protection devices, either hardware or software that will eliminate the inadvertent or deliberate alteration of data in the case where only file or files are copied (logical acquisition), and when there does not exist a copy of the entire hard disk or similar physical media (physical acquisition). This process is essential if the original evidence needs to be interacted in some way, such as producing a forensic copy or performing a preview of the data to determine reasonable grounds to believe a thing (computer) will afford evidence in investigation. The paper is the systematic overview of history and development of procedures ensuring the authenticity of digital evidence obtained by remote searching, searching in cyberspace and cloud.

cyberspace ; cloud ; remote search ; search and seizure data ; criminal investigation ; criminalistics ; forensics ; investigative

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

nije evidentirano

Podaci o prilogu

509-521.

2013.

objavljeno

Podaci o matičnoj publikaciji

Contemporary Criminal Justice Practice and Research: conference proceeding (proceedings of the Biennial International Conference Criminal Justice - Contemporary Criminal Justice and Research

Meško, Gorazd ; Sotlar, Andrej and Jack R. Greene

Ljubljana: Faculty of Criminal Justice and Security

978-961-6821-39-1

Podaci o skupu

Nepoznat skup

predavanje

29.02.1904-29.02.2096

Povezanost rada

Elektrotehnika, Računarstvo, Pravo

Poveznice