Skip to main content

Standard for the Electronic Evidence Exchange

  • Chapter
  • First Online:
  • 846 Accesses

Part of the book series: Law, Governance and Technology Series ((LGTS,volume 39))

Abstract

Within the activities of the Evidence Project, it has been proposed a standard for the representation of the data and metadata involved in the electronic evidence exchange process. The main aim is to consider the widest range of forensic information and processing results including legal requirements. The standard consists of a set of data and metadata for describing all actions (i.e., tasks), actors (e.g., subjects, victims, authorities, examiners, etc.), tools (i.e., digital tools for carrying out different forensic processes), digital and physical objects involved in the investigative case (e.g., hard disk, smartphone, memory dump, etc.) and objects relationships (e.g., contains, extracted from, etc.); formal languages for representing in a standard way all the elements above cited; a platform for implementing the exchange process in terms of functionalities along with a recommendation for an integration with existing platforms already in place and run by European/international public bodies.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   119.00
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   159.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD   159.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

Notes

  1. 1.

    Evidence Project—“European Informatics Data Exchange Framework for Courts and Evidence”, www.evidenceproject.eu.

  2. 2.

    In the forensics community there is no a general agreement on the exact meaning of the evidence provenance, although all experts unanimously consider the great importance of the provenance in digital forensics investigation. Some experts see the provenance as chain of custody documentation (Turner, 2005a), other interpret the provenance as the “the set of tools and transformations that led from acquired raw data to the final findings” (Levine and Liberatore, 2009).

  3. 3.

    Public Prosecutor speech during a 2 days meeting held in Florence, on 8–9 April 2015.

  4. 4.

    The main important system in the evidence exchange is SIENA, that stands for Secure Information Exchange Network Application. It is a secure communication system managed by EUROPOL and dedicated to the EU law enforcement community. The storage and exchange of information through SIENA is properly governed by legal framework, observing strong data protection regime. SIENA is used for exchanging personal information related to the crime areas within the mandate of EUROPOL, including EU restricted information. Basically, the SIENA application is a tool used for exchanging case relevant information (operational information).

  5. 5.

    See section Forensic Toolkit in the Digital Forensic Tools Catalogue at http://wp4.evidenceproject.eu.

  6. 6.

    See, for example, the File Carving or Application Forensics categories in the Digital Forensic Tools Catalogue.

  7. 7.

    MAC times are pieces of file system metadata that record when certain events pertaining to a computer file occurred most recently. M stands for Modify, A for Access and C for Change or Create.

  8. 8.

    The MITRE Corporation is a not-for-profit company that operates multiple federally funded research and development centers (FFRDCs), https://www.mitre.org.

  9. 9.

    http://capec.mitre.org.

  10. 10.

    http://maec.mitre.org.

  11. 11.

    http://stix.mitre.org.

  12. 12.

    http://taxii.mitre.org.

  13. 13.

    https://www.enisa.europa.eu.

  14. 14.

    https://www.enisa.europa.eu/activities/cert/support/actionable-information/actionable-information-for-security.

  15. 15.

    https://www.enisa.europa.eu/activities/cert/support/actionable-information/standards-and-tools-for-exchange-and-processing-of-actionable-information.

  16. 16.

    For the current list of objects, see https://cyboxproject.github.io/documentation/objects.

  17. 17.

    For a complete list see https://cyboxproject.github.io/documentation/object-relationships.

  18. 18.

    The UCO element ucoCommon:InformationSourceType that details the source of a given data entry.

  19. 19.

    A basic example, called basic_example.xml has been provided, by the DFAX developers, on the Github site—the well-known a web-based Git repository hosting service—via the http://github.com/DFAX/dfax/tree/master/examples.

  20. 20.

    Plaso is a Python-based backend engine for the tool log2timeline, developed and maintained by Google. log2timeline is a tool designed to extract timestamps from various files found on a typical computer system(s) and aggregate them.

  21. 21.

    psort is a command line tool to post-process plaso storage files. It allows you to filter, sort and run automatic analysis on the contents of plaso storage files.

  22. 22.

    A format similar to the Comma Separated Value.

References

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Fabrizio Turchi .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2018 Springer International Publishing AG, part of Springer Nature

About this chapter

Check for updates. Verify currency and authenticity via CrossMark

Cite this chapter

Epifani, M., Turchi, F. (2018). Standard for the Electronic Evidence Exchange. In: Biasiotti, M., Mifsud Bonnici, J., Cannataci, J., Turchi, F. (eds) Handling and Exchanging Electronic Evidence Across Europe. Law, Governance and Technology Series, vol 39. Springer, Cham. https://doi.org/10.1007/978-3-319-74872-6_15

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-74872-6_15

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-74871-9

  • Online ISBN: 978-3-319-74872-6

  • eBook Packages: Law and CriminologyLaw and Criminology (R0)

Publish with us

Policies and ethics