Suppr超能文献

当一无所获可能成为某种证据时:反取证与数字工具痕迹

When finding nothing may be evidence of something: Anti-forensics and digital tool marks.

作者信息

Horsman Graeme, Errickson David

机构信息

Teesside University, Campus Heart, Southfield Rd, Middlesbrough TS1 3BX, United Kingdom.

Cranfield Forensic Institute, Defence Academy of the United Kingdom, Cranfield University, Shrivenham, SN6 8LA, United Kingdom.

出版信息

Sci Justice. 2019 Sep;59(5):565-572. doi: 10.1016/j.scijus.2019.06.004. Epub 2019 Jun 3.

Abstract

There are an abundance of measures available to the standard digital device users which provide the opportunity to act in an anti-forensic manner and conceal any potential digital evidence denoting a criminal act. Whilst there is a lack of empirical evidence which evaluates the scale of this threat to digital forensic investigations leaving the true extent of engagement with such tools unknown, arguably the field should take proactive steps to examine and record the capabilities of these measures. Whilst forensic science has long accepted the concept of toolmark analysis as part of criminal investigations, 'digital tool marks' (DTMs) are a notion rarely acknowledged and considered in digital investigations. DTMs are the traces left behind by a tool or process on a suspect system which can help to determine what malicious behaviour has occurred on a device. This article discusses and champions the need for DTM research in digital forensics highlighting the benefits of doing so.

摘要

对于标准数字设备用户而言,有大量措施可供他们以反取证方式行事,并隐藏任何表明犯罪行为的潜在数字证据。虽然缺乏实证证据来评估这种对数字取证调查的威胁规模,使得使用此类工具的真实程度尚不清楚,但可以说该领域应采取积极措施来检查和记录这些措施的能力。虽然法医学长期以来一直接受工具痕迹分析作为刑事调查的一部分概念,但“数字工具痕迹”(DTMs)在数字调查中很少被承认和考虑。数字工具痕迹是工具或过程在嫌疑系统上留下的痕迹,有助于确定设备上发生了何种恶意行为。本文讨论并倡导在数字取证中开展数字工具痕迹研究的必要性,并强调这样做的好处。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验