Sunday, February 14, 2010

February 2010

A cold month with lots of snow. However also nice developments are going on. The American Academy of Forensic Sciences with the Annual meeting in Seattle will be a very nice event. I will chair the revised workshop on Multimedia Analysis, where we will also have a hands on training on camera identification. Also analysis of video files will be a part of this, and since I am chairman of the Section Digital and Multimedia Sciences, it is nice to see that the field is expanding further. And this week I am also working on many new students that start with projects and developing software for the open source sourceforge.net that we have for forensic software.

We have several students that work in house, however also many have projects that will be run from the universities / hogescholen in the Netherlands themselves. The students Informatics with a minor on Forensics of the Hogeschool Amsterdam will also start with several projects. Sometimes we had extremely good results. Most often this happens if the project is small, well defined, and ofen development in Java or .NET will give good results. Working on existing projects remains a challenge, since often documentation remains an issue.

In the meantime, we are preparing the conference for our Working Group of Forensic IT of ENFSI in Moscow, Russia. It will be in September, more information is available soon. And in the meantime, I have also some casework and other work to do. However good planning is always half of the work.

Tuesday, January 19, 2010

January 2010

It seems January gives lots of changes and opportunities. I first had to clean my website from a trojan which appeared only to be detected with one virus scanner. So I cleaned many html-files manually and check all changes in order to have the best effort. I do not think many users have noticed it, however malware is getting more anoying to fix, and it is always a balance between options on a website and freedom on developing and security.

This month I had some interesting discussions also in courses that I gave in digital evidence in a course on Forensic Economics at the University of Leiden. How do we combine evidence, especially in the fields where no numbers are given, however a subjective conclusion. How do we combine conclusions if there is no calibration between the different fields of expertise ? I worked in different fields of expertise and I know that there are differences between experts and between groups of experts and the conclusions that are drawn. The Bayesian rules might help, however still we need calibration.

Last week I went to inaugural lecture of Prof. dr. Ate Kloosterman, Special Chair of Forensic Biology of the Institute for Biodiversity and Ecosystem Dynamics (IBED). It was an excellent overview he gave of the development of DNA analysis of the years. After that there was a reception, and it was very nice to meet also my many of the past colleagues that I did not see for a long time. After a while I was not feeling well, and went out of the reception, and I fell down, since I was very dizzy. I could not stand anymore, since I was sick. In no time there was an ambulance available and checked my heart and I went rapidly to the hospital OLVG nearby. After many examinations in the hospital (MRI, CT-scans, blood, ECG etc) it appeared that I had very probably an infection of the organ of balance, and had to stay in the hospital for two days. For me it was very difficult, since I could not do anything, I could not stand, or send email or send sms messages anymore. I felt very bad that this happened during this party.

However now I am recovering, and total recovery is expected in two weeks (I still use some anti-nausea medicine Primperan), and walking and going on the bicycle should be more easy. It is also a good period to think, so I had to be at home for a week.

Of course also busy with emailing and organizing. The AAFS conference is also soon, so I am preparing. I also have some time to do some reviews, and we are now solliciting for new students for projects. We are also happy that the proficiency test on PRNU is working well, and currently my colleague Wiger and I submitted a new article on a new and faster algorithm for computing PRNU.

Monday, December 28, 2009

December 2009 (2)

As always the last days of the year are very good to finish deadlines, and finish casework and preparing courses for next year. The ideal situation to finish all work since there are no meetings and it is more quiet at the laboratory since many people have vacation.

From January 1st we have a new law on Forensic evidence active in the Netherlands, with an official register of experts at http://www.nrgd.nl . So it is interesting how this will work, since there are no experts in this register yet. However it is expected to be a good approach for the quality of forensic expertise in the Netherlands.

Currently we send out a proficiency test for camera identification and also organized the CAMCOM competition, where more people are interested to participate. It is interesting what will happen here.

Also I am working on a workshop on forensic multimedia analysis for the AAFS and looking on how to improve the training we give on digital evidence in general, with more interactive learning.

The good thing is now that I do not have any backlog in casework anymore, since we have better caseload management procedures in place, and this approach seems to work. So for the first time since 1991 I see an approach that works in practice, which also makes visible what are capacity is for casework, and also takes into account the more complicated cases.

Finally also my health improved, since I had issues with some of the medicines for asthma, that worked on coronary spasms with the betamimetics and also with ipratropiumbromide inhalers (which is a complication that is not very common). After good interaction between the cardiologist and the lung doctor, finally since this month I have a treatment that appears to work without all the complications I had before. So it appears after all a good start for 2010.

Sunday, December 13, 2009

Visit Tokyo

At evening also went to Electric City Akihabara. In 1996 I have worked for 3 months in Tokyo, so I know this place well. The prices are the same as in the Netherlands, and even diner and hotel seems to be cheaper then in the Netherlands. I had a 11 hours direct flight with KLM, and after that I just did a short visit there. Public transportation in Tokyo is very clear and all signs are in English as well as there chipcard system which works very well.
Posted by Picasa

December 2009

In November I had a busy month, so not much time to update the ongoing work. Busy with casework as organizing a conference for digital evidence in the Netherlands for the Dutch police. Also a presentation on for European Security Round Table Working Group ESRT on forensic science, which also was a result from a meeting of FIDIS.

Currently we are also distributing a proficiency test for camera identification, where we send out a camera and ask to compare these with ten directories of images. Of course also some work for the AAFS in reviewing membership applications and preparing the handouts for the totally revised workshop on Forensic Multimedia. Another challenge we organize is the CAMCOM-challenge for camera identification for ICPR.

Last week I also attended a meeting in Tokyo of the IOCE, where I gave two presentations : one on 17025 in digital evidence and one on the ENFSI Forensic IT Working group. We also discussed the ISO 27037 standard on Guidelines for identification, collection and/or acquisition and preservation of digital evidence where also from ENFSI Forensic IT there were 84 proposals for changes.

Next year we will have our working group meeting of ENFSI Forensic IT in Moscow in September 2010.

Sunday, October 18, 2009

October 2009

I had a short vacation in Helsink, Finlandi and Tallinn, Estonia. Also I went for two days to the Digital Imaging working group conference of ENFSI. I organized a workshop for identfication of cameras with PRNU , since I was planning to organize a collaborative exercise / proficiency test for this field, and furthermore would like to collaborate in a European project on this, however as always we need to find the time.

I was also maintaining my website, and it appeared that my forum had to be cleaned up, and was not used for a while. On line forums and mailing list are sometimes unpredicatable in their behavior, as I also experience with the FORENS-L list which I host. In the past it was not necessary to moderate, however nowadays it seems to be unavoidable, since flames occur.

This month I have my caseload to handle on the different cases, with also a reconstruction at the scene of crime. Also we are working on the WCIT 2010 on the cybersaftey and security track, which is a public private partnership.

Sunday, September 20, 2009

September (2) 2009

I enjoyed the EAFS conference very much. We organized the workshop on Digital Evidence, and it appeared that we had good attendance from experts within different fields. It remains an issue to make a good workshop were people also can do some hands on and it is not a plenary kind of thing. Of course working in smaller groups can solve this issue. I had also some time to relax in Glasgow, and discuss with colleagues on issues in forensic science.

On Friday morning I chaired a session on Digital Evidence, where Peter Sommer was the keynote speaker. He was giving an overview of the rate of change, and the issue that forensic peer reviewed articles can not follow this rate of change. So not all specific methods in digital evidence that are used in court are peer reviewed, since often one has to do research and reverse engineering to find the particular digital traces, and it is used in that specific case. So if someone would like to follow Daubert exactly, it appears that the exact method is not peer reviewed. Of course a general approach of using digital evidence is described however in digital evidence, also in guidelines of ENFSI www.enfsi.eu . A solution might be a peer review of the method during the case by other experts. Another issue is that most forensic scientist are often loaded with casework and do not have time to publish.

It was good to be at this conferences, and although the papers varied in quality, I had good discussions, and I always learn from these conferences, and see the different approaches within different law systems. The good thing that we also have within our working group is that there is a new standard being developed for collecting Digital Evidence, which should be ready in 2012. It is standard http://www.iso27001security.com/html/27037.html ISO 27037 which will be developed now. I think it is very good since very often digital evidence, such as emails and logfiles will cross borders and jurisdictions if cases are on internet.

After that I had a week to recover, and work on some casework and new Research and Development. Last Friday I went to Brussels and talked to several people of the European Commission concerning the developments in forensic IT within Europe. Also I was discussing on the program of WCIT 2010 http://www.wcit2010.com/ which also handles the rate of change, and the issues and solutions around it. The NFI is the organiser of a track within this conference, and we are looking further in this program.

Budgets are currently tighter within most forensic institutes and government agencies, so we always have to consider more efficient ways on processing forensic examination, and maintaining the high quality. It will give new solutions, and approaches, as long as long term investments are continued. Training and education is always necessary on all levels such that the law enforcement knows limitations and possibilities of forensic evidence, and of course it remains important to have good guidelines which are easy to use and easy to understand, such that important forensic evidence will not be destroyed by accident.