Skip to main content

Computer Forensics – What is Computer Forensics?



Defining What is Computer Forensics

A document distributed by the United States government in 2008 outlines the meaning as this, “Forensics is a process of using scientific knowledge of collecting, analyzing, and presenting evidence to the legal systems” (US-Cert, 2008). Furthermore, the document also adds that computer forensics is a newer process to the court systems, and policies are still being adapted in how to implement them. Although the collection of forensics is not new, the process of computer data collection is currently evolving as we progress through the digital times we now live in. This brings us to the meaning of forensics and how it relates to computers. Referring back to the same article, we extract the meaning of computer forensics as, “A discipline that combines the elements of law and computer science to collect and analyze data from computer systems, networks, wireless communications, and storage devices in a way that is admissible as evidence in a court of law” (US-Cert, 2008). Some definitions may vary slightly from this, but in general computer forensics is a technique used for identification, collection, examination, and protection of information which may be electronically or magnetically stored. To add more depth to this meaning, computer forensics is not just collection and examination of data off the hard drive “persistent data” but also “volatile data” which is data stored in memory that could be lost once the system is powered off. (Nolan, 2005). Now that we have placed meaning on what computer forensics is, when is this process used?

Computer Forensics Usage

Companies and organizations must pay close attention to their infrastructure to protect their assets. According to a free open source Website based around a community of computer forensics professionals, some common circumstances that involve computer forensics at work include: “employee internet abuse, unauthorized disclosures of information, industrial espionage, damage assessment following a breach, criminal fraud or deception, simple storage of information intentionally or unwillingly along with other aspects” (FAQ, 2010). This leads to some examples coming to mind such as child pornography cases in which predators download and store harmful and unlawful pictures. In identity theft cases where personal information is accidently leaked or has been comprised, computer forensics is used to examine the full potential of breaches. The Computer Forensics World website is full of information for those seeking careers in this field and/or training-related resources. It’s a good place to start for questions and answers. I will be returning to the site.

We have a meaning of forensics, and an understanding of some of the crimes that can be solved or prosecuted using computer forensics, but why the focus? The focus is because computer forensics is very meaningful. As technology continues to rapidly evolve, companies and organizations continue to adopt systems for collecting forensics data to better position themselves in their perspective markets. Information technology professionals must stay abreast of these changes and adapt accordingly. To be effective at doing this, we must examine risks and opportunities so our clients and the companies we work for remain sustainable. According to Specker and Janson, “effective network security includes protocols to detect, to investigate, and to preclude the recurrence of any breach in the stalled security system” (Specker & Janson, 2010). That quote comes from an interesting article titled, “Forensic Resources for Network Professionals”. In the article they outline a number of resources pertaining to security, dealing with the breaches, and how to effectively deal with a possible comprised network. As the article outlines that a company’s bottom line will often trump security concerns when the firm decides to position themselves and their systems online, so information technology professionals will be faced with threats from the expanding businesses.

Keeping the meaning and the goals of what is computer forensics in mind, there are a few other things of which upcoming professionals should be made aware. One, we have to obtain authorization before monitoring and starting to collect data related to the intrusion, as pointed out in the article from US-Cert, as legal criteria does exist in using monitoring tools similar to police needing a search warrant signed by a judge of a jurisdiction to execute a search. Laws are in place to protect the privacy of users and personal data, so policies and documentation protocols must be followed. Again as an example, for evidence to be submitted into a court hearing it must be collected by legal means.

Forensics Summary

In conclusion, computer forensics exists to help keep our computer data infrastructure secure and sustainable. Computer forensics collection and examination is much like a crime scene where collecting, analyzing, and protecting the evidence is done so it can be submitted in the courts, only instead of taking blood and carpet fiber samples, we are pulling the evidence from computer systems, wireless networks, and computer data storage devices. One must abide by the laws so the evidence collection is admissible in court in cases where criminal prosecution exists. If the IT professional is skilled and is able to carry out these tasks, one becomes a great asset to their respective employer. I hope this gives you a better idea what is in the world ofcomputer forensics.

Comments

Popular posts from this blog

CIA Triad for- Base of Information security

The essential security principles of confidentiality, integrity, and availability are often  referred to as the  CIA Triad. All security controls must address these principles. These three  security principles serve as common threads throughout the CISSP CBK. Each domain  addresses these principles in unique ways, so it is important to understand them both in  general terms and within each specific domain: Confidentiality is the principle that objects are not disclosed to unauthorized subjects. Integrity is the principle that objects retain their veracity and are intentionally modified by  authorized subjects only. Availability is the principle that authorized subjects are granted timely access to objects  with sufficient bandwidth to perform the desired interaction. Different security mechanisms address these three principles in different ways and offer varying  degrees of support or application of these principl...

10 Steps to Become a Top Information Security Professional: A Comprehensive Guide

In 2024, the demand for skilled information security professionals is higher than ever. As cyber threats continue to evolve, organizations around the globe are in desperate need of experts who can safeguard their critical data and systems. If you're aspiring to become one of the best in the field, you're in the right place. This comprehensive guide outlines ten essential steps to help you build a successful career in information security. From foundational education to advanced certifications, hands-on experience, and continuous learning, we'll cover everything you need to know to excel and stand out in this dynamic industry. Let's embark on your journey to becoming a top-tier information security professional. 1. Foundation in Computer Science Degree : Obtain a degree in computer science, information technology, or a related field. This will provide you with a strong foundational knowledge. Programming : Learn multiple programming languages such as Python, C++, Java, a...

My Article :- હેકર બનવું છે? કઈ રીતે?

મારી ૨ વર્ષ ની કારકિર્દી માં મને કેટલાય  લોકોએ, ખાસ કરીને કોલેજ ના વિદ્યાર્થીઓએ ઘણી વાર પૂછ્યું છે કે "મારે હેકર બનવું છે. તો હું શું કરું? " અને મારા બ્લોગ્સ માં પણ પૂછવામાં આવે છે કે એક સારો હેકર કઈ રીતે બની શકાય? એવું હું શું કરું અથવા તો મારા માં કઈ લાયકત હોવી જોઈએ એક હેકર બનવા માટે? આ પ્રશ્ન નો સંતોષકારક જવાબ આપવા માટે મેં internet પર શોધખોળ કર્યા પછી મને જે કઈ માહિતી મળી તેને હું આજે અહી રજુ કરું છું. મિત્રો, સૌપ્રથમ હેકર કઈ રીતે બનવું એ જાણવા પહેલા એ જાણવું જરૂરી છે કે ખરેખર હેકિંગ શું છે ? અને હેકર કોને કહેવાય. હેકિંગ ની સીધી અને સરળ વ્યાખ્યા નીચે મુજબ છે.  "તમારા કમ્પ્યુટર,નેટવર્ક(ઈન્ટરનેટ કે LAN દ્વારા) કે કોઈ ડીવાઈસ માં (ફોન, ટેબ્લેટ) માં કરવામાં આવતા ગેરકાયદેસર પ્રવેશ અને ઉપયોગ એ હેકિંગ કહેવાય છે."અને હેકિંગ કરતા લોકોને હેકર કહેવાય છે. હવે તમને થશે કે આવું શું કામ કરવું જોઈએ? આ તો ક્રાઈમ છે. તો તમને જણાવી દઉં કે હેકર મુખ્યત્વે ૨ પ્રકારના હોય છે.    વાઈટ હેટ હેકર્સ (એથીકલ હેકર્સ) : ધારો કે તમે તમારો ફેસબુક નો પાસવર્ડ ભૂલી ગયા(ખરેખર ના ભૂલતા ક્યારેય..)કે ત...