Lecture 6 - Digital Forensics Analysis and Validation

Digital Forensics Investigation Overview

  • Digital forensics involves examining electronic devices to recover and analyze data relevant to an investigation.

Key Objectives

  • Determine what data to analyze in a digital forensics investigation.

  • Explain tools used to validate data.

  • Explain common data-hiding techniques.

Importance of Data Analysis

  • Nature of investigation and amount of data process determines examination methods.

  • Scope creep: Expansion of investigation scope due to unexpected evidence leads to increased resources and time.

    • Common in criminal investigations before a trial.

    • Prosecution must ensure comprehensive evidence analysis.

Investigation Planning

  • Create an investigation plan that includes:

    • Goals and scope of the investigation.

    • Required materials and tasks.

    • Approach based on case type: corporate, civil, or criminal.

Steps in Digital Forensics Investigations

  1. Utilize recently wiped media for target drives after virus check.

  2. Inventory hardware and note the condition of the seized computer.

  3. For static acquisitions:

    • Remove original drive and check CMOS date and time.

  4. Document data acquisition process.

  5. Process drive contents methodically.

  6. Create a list of all folders and files.

  7. Examine all data file contents in folders.

  8. Recover contents of password-protected files.

  9. Identify executables not matching hash values.

  10. Maintain control of all evidence and findings.

Tools for Data Analysis

  • Autopsy supports analysis of various file systems:

    • Microsoft FAT, NTFS, ExFAT, UFS, ISO 9660, HFS+, Ext2fs, Ext3fs, Ext4fs.

  • Offers multi-user keyword search, hash databases, and file type identification.

Using Autopsy: Process Steps
  1. Select data source.

  2. Configure ingest modules:

    • Hash lookup.

    • File type identification.

Data Integrity Validation - Forensic Data

  • Ensuring collected data integrity is vital for court presentation:

    • Forensic tools typically hash image files for validation.

    • Advanced hexadecimal editors allow for specific file hashing.

    • Example: WinHex offers MD5 and SHA-1 algorithms.

Validating with Hexadecimal Editors

  • advanced hexadecimal editors offer more features including:

    • hashing specific files or sectors

  • with the hash value in hand

    • you can use the forensic tool to search for a suspicious file that might have had its name changed to look like an innocuous file

Data Hiding Techniques

  • Data hiding aims to conceal file information:

    • Techniques include:

    • Hiding partitions and changing file extensions.

    • Setting file attributes to hidden.

    • Bit-shifting and encryption.

    • Password protection.

Common Hiding Techniques
  • Changing file extensions obscures true file types:

    • Digital forensics check file headers against extensions.

  • Using OS hidden attributes conceals files.

  • Low-level encryption changes data order, making it unreadable.

Understanding Steganography and Steganalysis

  • Steganography: Hiding messages so only intended recipients can detect them.

  • Steganalysis: Techniques to detect steganography.

    • Includes various attack methods like known cover attack and chosen message attack.

  • Steganalysis methods

    • stego-only method

    • known cover attack

    • known message attack

    • chosen stego attack

    • chosen message attack

Encrypted Files and Password Recovery

  • Passwords and encryption methods secure files:

    • Key escrow technology helps recover encrypted data.

    • Key sizes from 128 to 4096 bits increase resilience.

  • Tools for password recovery:

    • Integrated or standalone crack tools like Last Bit, AccessData PRTK, John the Ripper, ophcrack, passware

  • Password recovery methods:

    • Brute-force: Tests all combinations.

    • Dictionary: Uses common words.

    • Rainbow tables: Fast hash lookup without conversion., faster than a brute force or dictionary attack.


    • salting passwords: alters hash values and makes cracking passwords more difficult

  • Building profiles helps of the user, helps recover / cracking passwords

Summary of Digital Forensics

  • Analysis practices depend on investigation type and data amount:

    • Wiping drives, documenting hardware and timestamps, and systematic data collection are the crux of investigations.

  • Advanced tools enhance efficiency and ensure the integrity of digital evidence.

  • Important to understand data-hiding techniques for thorough investigations.

  • Password recovery techniques are vital for accessing protected data successfully.