03 Applicable SWGDE Glossary Definitions

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/48

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

49 Terms

1
New cards

Wear Leveling

Mechanisms aided by algorithms tracking use and wear on flash memory ensure all memory blocks experience a similar number of write/erase cycles, extending the life of the device.

2
New cards

Artifact

Data created as a result of the use of a n electronic device that shows past activity.

3
New cards

Carve

the extraction of a portion of data for the purpose of analysis.

4
New cards

Archive

Data placed on media for long-term storage / A bit-stream duplicate of the original data placed on media for long-term storage.

5
New cards

Algorithm

Step-by-step (mathematical) procedure for solving a problem or accomplishing some end.

6
New cards

Chain of Custody

Chronological documentation of the movement, location, and possession of evidence.

7
New cards

Codec

(Compressor/Decompressor)… a device or program capable of encoding and decoding digital data. They encode a stream or signal for transmission, storage, or encryption.

8
New cards

Competency Test

Evaluation of a person’s knowledge and ability to perform independent work in forensic casework, prior to performance. (vs Proficiency)

9
New cards

Compression

Process of reducing the size of a data file… a reduction in the number of bits needed to represent data. Concerns: storage capacity, speed, cost, bandwidth.

10
New cards

Compression Ratio

Size of data file before compression divided by the file size after compression.

11
New cards

Computer Evidence

Subsection of digital multimedia forensics that involves the examination, comparison, and/or evaluation of digital evidence in legal matters.

12
New cards

Data

Information in analog or digital form that can be transmitted or processed.

13
New cards

Data Analysis

The assessment of the information contained within the media.

14
New cards

Data Extraction

Process that identifies and recovers information that may be latent, or not immediately apparent.

15
New cards

Digital Evidence

Information of probative value that is stored or transmitted in binary form.

16
New cards

Duplicate

An accurate and complete reproduction of all data objects independent of the physical media.

17
New cards

Extraction

A method of exporting data(obtaining and recovering) from a source. Extraction carving is a technique used in computer forensics and data recovery to extract files and information from storage devices. We use the definition specifically for obtaining data from mobile devices… “Recovery” for computer devices.

18
New cards

File Format

The structure by which data is organized in a file.

19
New cards

File Slack

The data between the logical end of a file and end of the last storage unit for that file.

20
New cards

Forensic

The use or application of science, scientific knowledge to a point of law, especially as it applies to the investigation of crime.

21
New cards

Forensic Clone

A comprehensive duplicate of electronic media. Artifacts can be discovered in its slack and unallocated space. A bit stream image (an exact bit-for-bit copy) duplicate of the available data from one physical media to another. Usually used as a working copy.

22
New cards

Forensic Image

A comprehensive duplicate, a bit stream copy of available data, often encapsulated in a proprietary form (E01, AD1,). Usually used for analysis and evidence preservation. Artifacts such as deleted files, fragments, hidden data may be found in slack (end-of-file marker and end of cluster) and unallocated space. An exact duplicate of the data, also considered a bit by bit copy.

23
New cards

Hash Value or Hash

Numerical values generated by hashing tools, used to substantiate the integrity of digital evidence and/or for inclusion/exclusion comparisons against know value sets.

24
New cards

Hashing or Hashing Function

Application of… an established mathematical calculation that generates a numerical value (the hash) based on input data.

25
New cards

Integrity Verification

The process of confirming that the data presented is complete and unaltered since time of acquisition.

26
New cards

Log File

A record of actions, events, and related data.

27
New cards

Logical Acquisition

Accurate reproduction of information contained within a logical volume (e.g. mounted volume, logical drive assignment, etc.)

28
New cards

Logical Volume (LV)

A group of information on a physical volume (PV) that can span multiple disks. LVs are virtual storage volumes that can be used for a variety of system, such as paging.

29
New cards

Memory Smear

The modification of data by a running system during the memory acquisition process.

30
New cards

Metadata

Data frequently embedded within a file that describes a file or directory, which can include the locations where the content is stored, dates and times, app specific info, permissions.

31
New cards

Mobile Forensics

The utilization of scientific methodologies to recover data stored by a cellular device for legal purposes.

32
New cards

Physical Copy

An accurate reproduction of information contained on the physical device.

33
New cards

Physical Image

Bitstream duplicate of data contained on a device.

34
New cards

Proficiency Test

A test to evaluate analysts, tech personnel and quality performance of an agency.

35
New cards

Quality Assurance

Planned and systematic actions necessary to provide sufficient confidence that an agency/lab product or service will satisfy requirements for quality.

36
New cards

Quantitative Analysis

Process used to extract measurable data from a source.

37
New cards

Reliability

Extent to which info can be depended upon.

38
New cards

Reproducibility

The extent to which a process yields the same results on repeated trials.

39
New cards

Residue

Data contained in unallocated space or file slack.

40
New cards

Resolution

The act, process, or capability of distinguishing between two separate but adjacent parts or stimuli, such as elements of detail in an image or similar colors.

41
New cards

Restoration

Any process applied to partially or totally remove the effects of degradation.

42
New cards

Routing Switcher

A device &/or software used to direct the path of one or more signals into one or more devices.

43
New cards

Signature Wiped

Media securely wiped in accordance with acceptable standards such as those of NIST utilizing a unique sector character signature.

44
New cards

Technical Peer Review

An evaluation conducted by a second qualified individual of reports, notes, data, conclusions, and other documents.

45
New cards

Triage

Process by which items considered for collection or analysis are prioritized to determine the order in which they should be collected and analyzed if at all.

46
New cards

Validation

Process of performing a set of experiments which establishes the efficacy and reliability of a tool - An evaluation to determine if a tool, technique, or procedure functions correctly and as intended. Standardized testing / outcomes compared to standard expected results are known.

47
New cards

Verification

Process of confirming the accuracy of an item to its original / confirmation that a tool, technique, or procedure performs as expected.

48
New cards

WORM

Write Once Read Many

49
New cards

Write Block / Write Protect

Hardware/software methods of preventing modifications of media content.