digital forensics forensic toolkit: a tool to process born digital records emma jolley curator of...

32
DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Upload: meryl-stone

Post on 31-Dec-2015

231 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

DIGITAL FORENSICSForensic Toolkit: a tool to process born digital records

Emma Jolley Curator of Digital Archives

Page 2: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Why Digital Forensics?The process of identifying, preserving, analysing and presenting digital evidence in a manner that is legally

acceptable.

ProvenanceOriginal Order

Chain of CustodyIdentifying

Authenticity

Page 3: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Forensic Toolkit

Page 4: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Case Summary

Page 5: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Overview of FTK Screen

Page 6: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Explore View

Page 7: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Explore View – Additional Technical Metadata

Page 8: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Explore View – Additional Technical Metadata (part – 2)

Page 9: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Overview View

Page 10: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Overview View

Page 11: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Viewing Content

Page 12: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Email View - 1

Page 13: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Email View 1 – Deleted Items

Page 14: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Email View 1 – Calendar view

Page 15: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Email View 2

Page 16: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Email View 2

Page 17: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Graphics View

Page 18: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Graphics View – Properties view (metadata)

Page 19: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Video View

Page 20: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Audio Player

Page 21: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Bookmarks (Serialisation – Arrangement and Description)

Page 22: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Bookmarks (Serialisation – Arrangement and Description)

Page 23: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Labels (Analysis)

Page 24: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Searching (Index)

Page 25: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Searching (Index) – Copyright and IP statements

Page 26: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Visualisation – Time Series (Email)

Page 27: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Visualisation – social analyser (email)

Page 28: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Reporting

Page 29: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Reporting – Finding-aid

Page 30: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Reporting – Donors List (Finding-aid)

Page 31: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Issues and Challenges• Professional interactions (vocabulary)• Donors metadata• Description• Hybrid collections• Perceptions of the challenge• No two collections are the same• Getting the Description into CMS

Page 32: DIGITAL FORENSICS Forensic Toolkit: a tool to process born digital records Emma Jolley Curator of Digital Archives

Lessons Learnt• Plan, Plan, Plan, visit and plan some more• Expect the unexpected• Digital Transfer is very resource hungry• Appraisal must be at CDP level (and Functions)• A single person isn’t going to do it (need a

village)• Theory is the same regardless of format