Komosny Dan
Department of Telecommunications, FEEC, Brno University of Technology, Brno, Czech Republic.
PeerJ Comput Sci. 2023 Mar 30;9:e1305. doi: 10.7717/peerj-cs.1305. eCollection 2023.
Knowledge of the previous location of an Internet device is valuable information in forensics. The previous device location can be obtained via the IP address that the device used to access Internet services, such as email, banking, and online shopping. However, the problem with the device location using its IP address is the unknown evidential value, which is used to admit the evidence in the case. This work introduces a method to process free and constantly updated data to assess the evidential value of the IP country location. The evidential value is assessed for several countries by analyzing historical data over 8 years. Tampering with the location evidence is discussed, as well as its detection. The source code to replicate the results and to apply the updated data to future evidence is available.
了解互联网设备的先前位置在法医学中是有价值的信息。可以通过设备用于访问互联网服务(如电子邮件、银行和网上购物)的IP地址来获取设备的先前位置。然而,使用IP地址确定设备位置的问题在于其证据价值未知,而这一证据价值在案件中用于采信证据。这项工作引入了一种处理免费且不断更新的数据的方法,以评估IP国家位置的证据价值。通过分析8年多的历史数据,对多个国家的证据价值进行了评估。文中讨论了篡改位置证据的情况及其检测方法。用于复制结果并将更新后的数据应用于未来证据的源代码是可用的。