官术网_书友最值得收藏!

  • Practical Mobile Forensics
  • Rohit Tamma Oleg Skulkin Heather Mahalik Satish Bommisetty
  • 188字
  • 2021-06-24 16:39:02

Preserving the evidence

As evidence is collected, it must be preserved in a state that is acceptable in court. Working directly on the original copies of evidence might alter it. So, as soon as you recover a raw disk image or files, create a read-only master copy and duplicate it. In order for evidence to be admissible, there must be a scientific method to validate that the evidence submitted is exactly the same as the original collected. This can be accomplished by creating a forensic hash value of the image.

A forensic hash is used to ensure the integrity of an acquisition by calculating a cryptographically strong and non-reversible value of the image/data.

After duplicating the raw disk image or files, compute and verify the hash values for the original and the copy to ensure that the integrity of the evidence is maintained. Any changes in hash values should be documented and explicable. All further processing or examination should be performed on copies of the evidence. Any use of the device might alter the information stored on the handset. So, only perform the tasks that are absolutely necessary.

主站蜘蛛池模板: 泾源县| 罗城| 白银市| 兴和县| 石狮市| 崇文区| 罗城| 平谷区| 河北区| 阳曲县| 杂多县| 留坝县| 济宁市| 离岛区| 兴安县| 罗山县| 略阳县| 寻乌县| 徐州市| 马尔康县| 陆河县| 寻甸| 响水县| 克山县| 建始县| 新昌县| 琼结县| 启东市| 玉山县| 龙井市| 海兴县| 浠水县| 平乡县| 如皋市| 麻栗坡县| 宁蒗| 五华县| 大同市| 洛浦县| 凌源市| 东城区|