官术网_书友最值得收藏!

Preserving the evidence

As evidence is collected, it must be preserved in a state that is acceptable in court. Working directly on the original copies of evidence might alter it. So, as soon as you recover a raw disk image or files, create a read-only master copy and duplicate it. In order for evidence to be admissible, there must be a method to verify that the evidence presented is exactly the same as the original collected. This can be accomplished by creating a forensic hash value of the image. A forensic hash is used to ensure the integrity of an acquisition by calculating a cryptographically strong and non-reversible value of the image/data. After duplicating the raw disk image or files, compute and verify the hash values for the original and the copy to ensure that the integrity of the evidence is maintained. Any changes in hash values should be documented and explainable. All further processing or examination should be performed on copies of the evidence. Any use of the device might alter the information stored on the handset. So, only perform the tasks that are absolutely necessary.

主站蜘蛛池模板: 前郭尔| 崇礼县| 平舆县| 奉贤区| 资兴市| 马边| 饶平县| 晋宁县| 黑山县| 寻甸| 海安县| 三台县| 乌拉特前旗| 鹤庆县| 伊通| 长顺县| 灵宝市| 鞍山市| 华阴市| 蒲城县| 滦南县| 鄂伦春自治旗| 固镇县| 威远县| 谢通门县| 应用必备| 读书| 琼中| 东乡| 天峨县| 双鸭山市| 合川市| 搜索| 平利县| 齐齐哈尔市| 怀宁县| 施秉县| 临海市| 临猗县| 吉木萨尔县| 岐山县|