Skip to main content

Digital Evidence Bag Selection for P2P Network Investigation

  • Conference paper
Future Information Technology

Part of the book series: Lecture Notes in Electrical Engineering ((LNEE,volume 276))

Abstract

The collection and handling of court admissible evidence is a fundamental component of any digital forensic investigation. While the procedures for handling digital evidence take much of their influence from the established policies for the collection of physical evidence, due to the obvious differences in dealing with non-physical evidence, a number of extra policies and procedures are required. This paper compares and contrasts some of the existing digital evidence formats or “bags” and analyses them for their compatibility with evidence gathered from a network source. A new digital extended evidence bag is proposed to specifically deal with evidence gathered from P2P networks, incorporating the network byte stream and on-the-fly metadata generation to aid in expedited identification and analysis.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 169.00
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 219.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info
Hardcover Book
USD 219.99
Price excludes VAT (USA)
  • Durable hardcover edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Turner, P.: Unification of digital evidence from disparate sources (digital evidence bags). Digital Investigation 2(3), 223–228 (2005)

    Article  Google Scholar 

  2. Casey, E.: What does for ensically sound really mean. Digital Investigation 4(2), 49–50 (2007)

    Google Scholar 

  3. Common Digital Evidence Storage Format (CDESF): Survey of existing disk image storage formats. In: Proc. Digital Forensic Research Workshop 2006 (September 2006)

    Google Scholar 

  4. Group, D.F.R.W.D.C.D.E.S.F.C.W (September 2006), http://www.dfrws.org/CDESF/index.shtml

  5. The Common Digital Evidence Storage Format Working Group: Standardizing digital evidence storage. Communications of the ACM 49(2), 67–68 (2006)

    Google Scholar 

  6. Garfinkel, S.: Aff: a new format for storing hard drive images (2006)

    Google Scholar 

  7. Richard, G., Roussev, V., Marziale, L.: Forensic discovery auditing of digital evidence containers. Digital Investigation 4(2), 88–97 (2007)

    Google Scholar 

  8. Zip, G.F.: (April 2009), http://www.nongnu.org/gfzip/

  9. Hosmer, C.: Digital evidence bag. Commun. ACM 49(2), 69–70 (2006)

    Article  MathSciNet  Google Scholar 

  10. Features, E.F.: (August 2009), http://www.guidancesoftware.com/WorkArea/DownloadAs-set.aspx?id=671.GuidanceSoftware

  11. Science and Technology Committee: Forensic Science on Trial, 75–76 (2005)

    Google Scholar 

  12. Carrier, B.: Open source digital forensics tools: Thelegal argument. @stakeResearch Report (2002)

    Google Scholar 

  13. Supreme Court of the United States, Daubert v. Merrell Dow Pharmaceuticals: (June 1993), http://supct.law.cornell.edu/supct/html/92-102.ZS.html/

  14. Computer Forensic Tool Testingpro-gram, U.S.N.I.o.S., Technology (August 2009), http://www.cftt.nist.gov/

  15. National Institute of Standards and Technology: NIST Special Publication 800-86 Guide to Integrating Forensic Techniques into Incident Response. Create Space, Paramount, CA (2012)

    Google Scholar 

  16. Karyda, M., Mitrou, L.: Internet forensics: Legal and technical issues. In: IEEE Second International Workshop on Digital Forensics and Incident Analysis, WDFIA 2007, pp. 3–12 (2007)

    Google Scholar 

  17. McCanne, S., Leres, C., Jacobson, V.: Libpcap (June 2012)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Mark Scanlon .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2014 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Scanlon, M., Kechadi, T. (2014). Digital Evidence Bag Selection for P2P Network Investigation. In: Park, J., Stojmenovic, I., Choi, M., Xhafa, F. (eds) Future Information Technology. Lecture Notes in Electrical Engineering, vol 276. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-40861-8_44

Download citation

  • DOI: https://doi.org/10.1007/978-3-642-40861-8_44

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-642-40860-1

  • Online ISBN: 978-3-642-40861-8

  • eBook Packages: EngineeringEngineering (R0)

Publish with us

Policies and ethics