{"id":858,"date":"2010-08-12T06:47:00","date_gmt":"2010-08-12T06:47:00","guid":{"rendered":"http:\/\/digitalfire.ucd.ie\/?p=858"},"modified":"2013-05-14T12:48:03","modified_gmt":"2013-05-14T12:48:03","slug":"survey-of-evidence-and-forensic-tool-usage-in-digital-investigations","status":"publish","type":"post","link":"https:\/\/dfire.ucd.ie\/?p=858","title":{"rendered":"Survey of Evidence and Forensic Tool Usage in Digital Investigations"},"content":{"rendered":"<p>This work is in regards to a 2009 project about research into real-world digital forensic practices for the development of highly automated tools to increase speed and efficiency of forensic investigations. A survey was conducted of 30 Law Enforcement officers from different countries in Europe (with 10\u00a0respondents). The key findings of the survey are given, with a link to the full document provided.<\/p>\n<p>Key observations:<\/p>\n<ul>\n<li>Every country has a different\u00a0<i>definition<\/i>\u00a0of digital crime<\/li>\n<li>Every country has different\u00a0<i>laws<\/i>\u00a0relating to digital crime<\/li>\n<li>INTERPOL fights international crime by managing resources between countries<\/li>\n<li>INTERPOL provides facilitation rather than direct operational capabilities\n<ul>\n<li>\u2018Outsource\u2019 operational needs from member countries<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><b>Requirements for Digital Forensic Tools<\/b><\/p>\n<p>Out of 30 surveys submitted, 10 were returned. Along with these surveys, informal discussions with practitioners were conducted.<\/p>\n<p>Through the survey and discussions it was found that three primary factors investigators are taken into account when purchasing forensic software:<\/p>\n<ol start=\"1\">\n<li>Feature set<\/li>\n<li>Cost<\/li>\n<li>Ease of use<\/li>\n<\/ol>\n<p>Cost was found to be a common complaint, and a major concern for almost every practitioner spoken to. However, the most expensive forensic software, Encase, was the primary software chosen by 80% of the organizations. FTK, X-Ways Forensic, and miscellaneous tools were also used, but not nearly as often.<\/p>\n<p>The average percentage of cases in which\u00a0<i>only<\/i>\u00a0the chosen primary software was used is 77.9%. Which suggests that the cost of more expensive software is justified if it can handle the majority of needs the investigator may have. It appears that Encase does, in fact, meet the majority of requirements of the investigator, however, there is still approximately 20% of the cases in which an investigator would need additional features.<\/p>\n<p>This 20% is covered by various secondary software, with FTK being the secondary software of choice. WinHex, Password Recovery\/Decryption, Automated Analysis tools, and various Linux-based tools were also used.<\/p>\n<p>The majority of the time an investigator is looking at user documents. Internet traces, passwords and log analysis are a close second.<\/p>\n<p>The group also indicated that they would be more likely to buy a plug-in to their current software-set than to buy a third-party stand alone software. Fitting into their current workflow is a topic of importance.<\/p>\n<p>Timelines of user actions are important to investigators. Some investigators indicated that a timeline of user activities would be useful in up to 70% of their cases.<\/p>\n<p>Also interesting is that currently only 31% of cases involve Windows Registry Analysis. This low number was\u00a0<b>not<\/b>\u00a0shown to correlate with knowledge of the Windows Registry. Responders who claimed to be \u201cvery familiar\u201d or \u201cexpert\u201d in Windows Registry analysis, employed it just as often as those who were only \u201csomewhat familiar\u201d.<\/p>\n<p>Finally the types of evidence investigators are seeing still consist primarily of Windows computers (87%) with Linux a far second (7%) and Mac last (6%). Of the Windows machines, Windows XP is still the most common OS (58%) with Vista (28%) and Windows 7 (4%) growing, but still not the majority.<\/p>\n<p>For more information and the raw data, please see:<br \/>\nJames, J.I. (2009) &#8220;Survey of Evidence and Forensic Tool Usage in Digital Investigations&#8221;. University College Dublin. [<a href=\"http:\/\/digitalfire.ucd.ie\/?attachment_id=860\">PDF<\/a>]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This work is in regards to a 2009 project about research into real-world digital forensic practices for the development of highly automated tools to increase speed and efficiency of forensic investigations. A survey was conducted of 30 Law Enforcement officers from different countries in Europe (with 10\u00a0respondents). The key findings of the survey are given, [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[30],"tags":[26,36,65],"class_list":["post-858","post","type-post","status-publish","format-standard","hentry","category-windows-forensics","tag-digital-forensics","tag-law-enforcement","tag-survey"],"_links":{"self":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts\/858"}],"collection":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=858"}],"version-history":[{"count":8,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts\/858\/revisions"}],"predecessor-version":[{"id":1114,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=\/wp\/v2\/posts\/858\/revisions\/1114"}],"wp:attachment":[{"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dfire.ucd.ie\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}