- The start of the new year is always excellent, since we have time to plan and look to unfinished tasks if they are necessary. As always, many new challenges to solve, and in February the American Academy of Forensic Sciences has it conference in Washington DC, where I am looking forward to meet the colleagues. Currently also finalizing the work on workshop 17 'Image Analysis — 3D Imaging and Virtopsies: Developments, Methods, and Reasoning About Images'.
- Teamwork remains important, where we have multidisciplinary teams that become more creative in finding new solutions. Currently working on implementing new methods how to improve this in R&D projects. There are also many new challenges, and of course budget constraints is one of them.
- We see that the CSI effect at universities appears to work for getting people interested in forensic science and that they are aware of the real issues.
- The opening of the European Cybercrime Center at Europol om 1 January 2013 is an important event for the fight against cybercrime.
Tuesday, January 01, 2013
January 2013
Wednesday, December 05, 2012
December 2012
The One Topic One Day symposium of ENFSI on accreditation in Digital Evidence in Tallinn, where I was invited for a talk on Quality Assurance in Digital Evidence both as chairman of the ENFSI and from the view of the NFI, was very nice. It very much depends on the size and the kind of procedures that are handled within the forensic lab. However it appeared that there are many solutions for the rate of change. In the Netherlands we are working with accreditation of R&D in casework within ISO 17025.
Currently the new guideline standard ISO 27032 is published on Information technology -- Security techniques -- Guidelines for identification, collection, acquisition and preservation of digital evidence. New standards are being developed and new standards in ISO are being developed. ISO/IEC 27037, 27041, 27042 and 27043 is to promote good practice methods and processes for forensic investigation of digital evidence.
Currently working on several papers and some presentations as well as reviewing and preparing for an ENFSI meeting in Berlin with the board, where we are looking into developments within forensic science, and of course one of the topics will be how to handle cuts of budgets with keeping the quality the same or better..
Currently the new guideline standard ISO 27032 is published on Information technology -- Security techniques -- Guidelines for identification, collection, acquisition and preservation of digital evidence. New standards are being developed and new standards in ISO are being developed. ISO/IEC 27037, 27041, 27042 and 27043 is to promote good practice methods and processes for forensic investigation of digital evidence.
Currently working on several papers and some presentations as well as reviewing and preparing for an ENFSI meeting in Berlin with the board, where we are looking into developments within forensic science, and of course one of the topics will be how to handle cuts of budgets with keeping the quality the same or better..
Friday, November 16, 2012
November 2012
November started with some nice events. I had to go to the Court of Appeal in The Hague and testify in a case on image comparison. It is always nice to answer the questions, and verify if the report that has been written is understood in a correct way by all parties.
In the second week we had a very well organized conference at the Carabinieri in Rome of the ENFSI Forensic IT working group meeting, where I was re-elected as chairman. Many new developments in digital evidence, and now also the discussion on error rate in digital evidence is more visible, as is also discussed at the Scientific Working group of Digital Evidence , where we have an excellent liaison with. Furthermore, three proficiency tests where carried out in the field, so that was very good. Also the ISO-standards on digital evidence are developing rapidly.
Also busy with some proposal on big data for the FP7 cyber security call. And I received the message from the American Academy of Forensic Science that the workshop that we proposed (which I am chairing) on (W17) Image Analysis - 3D Imaging and Virtopsies: Developments, Methods, and Reasoning is accepted.
Currently we are sending out a proficiency test on camera identification So enough work to do. And next week I am chairing the organisation of our conference for the digital investigators of the Dutch Police, where we have 350 people that will participate. Six parallel workshops and many nice developments, the second day is with companies and universities.
Also we have to cope with some budget cuts, so keeping the work more efficient and finding new ways of doing the forensic work is a challenge, and of course applications of funding, working with R&D and new developments remain important. And finally, I had to give an live interview (in Dutch) on Anne Frank and some photograph comparison for the radio in the Netherlands, which was also interesting to do.
In the second week we had a very well organized conference at the Carabinieri in Rome of the ENFSI Forensic IT working group meeting, where I was re-elected as chairman. Many new developments in digital evidence, and now also the discussion on error rate in digital evidence is more visible, as is also discussed at the Scientific Working group of Digital Evidence , where we have an excellent liaison with. Furthermore, three proficiency tests where carried out in the field, so that was very good. Also the ISO-standards on digital evidence are developing rapidly.
Also busy with some proposal on big data for the FP7 cyber security call. And I received the message from the American Academy of Forensic Science that the workshop that we proposed (which I am chairing) on (W17) Image Analysis - 3D Imaging and Virtopsies: Developments, Methods, and Reasoning is accepted.
Currently we are sending out a proficiency test on camera identification So enough work to do. And next week I am chairing the organisation of our conference for the digital investigators of the Dutch Police, where we have 350 people that will participate. Six parallel workshops and many nice developments, the second day is with companies and universities.
Also we have to cope with some budget cuts, so keeping the work more efficient and finding new ways of doing the forensic work is a challenge, and of course applications of funding, working with R&D and new developments remain important. And finally, I had to give an live interview (in Dutch) on Anne Frank and some photograph comparison for the radio in the Netherlands, which was also interesting to do.
Friday, October 19, 2012
October 2012 : some challenges in digital evidence
This week we will have an ENFSI-meeting in Rome of the Forensic IT Working group, were the new developments in forensic IT are discussed as well as solutions.
In Forensic IT currently we have the next seven long term challenges :
With encryption methods getting more sophisticated and also implemented in hardware such as SSD-disks, live forensics methods are the choice instead of trying to break the keys. However live systems should be shielded from network communication, since it is possible to remotely wipe systems.
In Forensic IT currently we have the next seven long term challenges :
- big data
- malware
- number of students in ICT
- encryption
- different formats
- diversity
- presenting complicated evidence in court
- big data
The issue with big data is that cases are growing rapidly. If all data from a person is collected in a case, the amount grow rapidly, also due to multimedia and fast datalinks. Currently indexing over 100 Petabyte is not easy, also HADOOP has issues with it and new solutions are developed by social networks such as facebook. Indexing video data is also not easy. Filtering is important, and triage is one of the solutions. Cloud computing is an issue here, since often the data is available in other states with different jurisdictions.
2. malware
Issues with malware developers is that it is difficult to investigate. Zero day exploits can be seen more often, and botnets and other attacks of many systems such as SCADA, are an issue. Malware on mobile phones is so common that the FBI placed a warning. Lawyers might use it as defense. Even medical devices can be infected by malware. Also people claim that governments develop malware.
3. number of students in ICT
ICT and related studies are not very popular, so it is difficult to fill all vacancies. Software engineers are difficult to hire, and are needed for all developments.
4. encryption
With encryption methods getting more sophisticated and also implemented in hardware such as SSD-disks, live forensics methods are the choice instead of trying to break the keys. However live systems should be shielded from network communication, since it is possible to remotely wipe systems.
5. different formats
Many developers will make new file formats which deviate from the file format, and use coding which is not public. Analysing and repairing them is important. The golden age as Simon Garfinkel mentioned is over, and we will enter a digital forensic crisis.
6. diversity
There are many hardware manufacturers as well as software developments. It is hard to keep up with developments and have methods available for doing a forensic analysis. Mobile device forensics with chip extraction is an option, however remains time consuming and expensive.
7. presenting complicated evidence in court
Often digital evidence especially in hacking cases is difficult to interpret for juries and judges. The challenge for the forensic examiner is to present the evidence in court such that it is acceptable. Many times new methods have to be developed and validated for the court, and also privacy laws have to be taken care of.
Sunday, October 14, 2012
Guest post by Ken Myers
7 Ways Social Media is Used by Forensic Investigation
As the saying goes, "What is posted on the Internet, stays on the Internet". Investigations are including
social media sites during forensic investigations to strengthen or confirm information gathered about any
given case. Sometimes, the criminal themselves will post incriminating information without thinking
about how it could affect them. How is this information gathered?
1. Profile Activity - Many people like to update his or her Facebook or other community site's profile.
However, posting pictures and commenting on robbing a gas station probably isn't the best method of
gaining fame.
2. Video Can Hurt - Sites such as YouTube and Flikr are entertaining sites created by those who use
them. Recording your criminal behavior and then posting it for everyone to see will secure your room at
the Jail House Hotel.
3. Chirping Your Crime - Tweeting about how you got away with an illegal activity isn't proving to
anyone how smart you are. On the contrary, posting the information is essentially telling everyone who
did what and how to find you.
4. No Comment - Posting on forums about your activity could give you a sense of status. Posting on
forums could solidify a case against you in a court of law.
5. Website Content - Even if you think your website is small and unnoticed, it can be traced back to you.
Detailing your deeds on a website could easily gather the attention of law enforcement.
6. Digital Information - During an Investigation, your computer could become evidence and all accounts
could be analyzed. The sites you once thought of as hang-outs, could be used against you to make legal
hang-ups.
7. Reputation - If you think something may be too incriminating to post on the Internet, don't post it. Not
everyone needs to know every secret, and information has a way of telling more than you want it to.
If you don't want someone to know something about yourself, don't post it on the Internet. Even
photographs have a way of staying in the system long after you deleted them from your account. Data is
collected on a regular basis and could come back to haunt you if you're not careful.
Ken Myers is the founder for http://www.longhornleads.com/. He frequently researches and
writes about a variety of topics like education, Technology, Health and many more. He welcomes your
comments.
Sunday, October 07, 2012
October 2012
September was as always a busy month, so not much time to write. Many reviews for articles, and rescheduling projects and making new project proposals. It is often not easy to explain technical issues or research projects to people that are not used to them, so the challenge is always to write clearly and receive as much feedback as possible, by directly asking non-technical people to explain what is written, and hear back if it is understood well. This is important in both forensic reports as well as project proposals.
At the start of October I enjoyed a week vacation in Bucharest. It was nice to see the different musea and buildings and some big shopping malls. I even saw some nice paintings of Rembrandt over there. In October I have to make preparations for a two days conference in the Netherlands on Digital Investigation which I am currently organizing together with a good team, so that should work well. Also I am looking forward to the ENFSI Forensic IT working group meeting in Rome later in October, where I am chairman of the working group. I visited in September during two days the ENFSI Digital Imaging Working group in Brussels, which was very well organized by NICC.
Of course, some casework, and currently also some students on different projects from several universities, on several topics, from camera identification, to forensic hand comparison and other body parts, super resolution and some research on iPhone forensics.
At the start of October I enjoyed a week vacation in Bucharest. It was nice to see the different musea and buildings and some big shopping malls. I even saw some nice paintings of Rembrandt over there. In October I have to make preparations for a two days conference in the Netherlands on Digital Investigation which I am currently organizing together with a good team, so that should work well. Also I am looking forward to the ENFSI Forensic IT working group meeting in Rome later in October, where I am chairman of the working group. I visited in September during two days the ENFSI Digital Imaging Working group in Brussels, which was very well organized by NICC.
Of course, some casework, and currently also some students on different projects from several universities, on several topics, from camera identification, to forensic hand comparison and other body parts, super resolution and some research on iPhone forensics.
Saturday, August 18, 2012
August 2012
This month starts busy, lots of cases often are submitted before the vacation starts. I also had several deadlines before August 1st, for example submission of abstracts for the AAFS conference in Washington DC next year.
Several students finished their thesis for their internship, unfortunately it is difficult to get a job in general forensic science now, however it van be easy in the field of forensic ICT, so currently I advise students to study informatics and forensics, since people are needed there at the moment.
I will present at two workshops at the European Academy of Forensic Science in the Hague in August, and one paper. I am looking forward to the conference, it is always nice to meet all colleagues. The ENFSI awards will also be granted at this meeting, where I am honored and thankful to receive the distinguished forensic scientist award. Also I had the honor to meet Queen Beatrix there.
Furthermore the ENFSI Forensic IT working group meeting in Rome in October seems to have many attendees registered. In September I am looking forward to be at the ENFSI Digital Imaging Working group in Brussels, however I will only be there for a part of the meeting. Also I am looking forward to the ICMedia conference in Brasilia where I will be one of the invited speakers in September.
Several students finished their thesis for their internship, unfortunately it is difficult to get a job in general forensic science now, however it van be easy in the field of forensic ICT, so currently I advise students to study informatics and forensics, since people are needed there at the moment.
I will present at two workshops at the European Academy of Forensic Science in the Hague in August, and one paper. I am looking forward to the conference, it is always nice to meet all colleagues. The ENFSI awards will also be granted at this meeting, where I am honored and thankful to receive the distinguished forensic scientist award. Also I had the honor to meet Queen Beatrix there.
Furthermore the ENFSI Forensic IT working group meeting in Rome in October seems to have many attendees registered. In September I am looking forward to be at the ENFSI Digital Imaging Working group in Brussels, however I will only be there for a part of the meeting. Also I am looking forward to the ICMedia conference in Brasilia where I will be one of the invited speakers in September.
Subscribe to:
Posts (Atom)

